some systemd hardening #67
No reviewers
Labels
No Label
art
backup
big
blocked
bug
crash report
disputed
documentation
duplicate
enhancement
good first issue
logging
nixos
question
salt
security
servers n' hardware
wontfix
No Milestone
No Assignees
3 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Drift/pvv-nixos-config#67
Loading…
Reference in New Issue
No description provided.
Delete Branch "some-systemd-hardening"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Most of these should probably be upstreamed at some point, but let's dogfood a bit first. I'll create a new issue about upstreaming once this gets merged.
TODO:
- [ ] Is there anything more we can do with thermald? I'm unsure exactly what it does, so I've left out a bunch of options that I was unsure aboutThermald er en userspace greie som setter p-states og greier for å nå temperatur/performance mål. Det er siginifikant på nyere intel cpuer, men jeg tviler egentlig litt på at vi har noe hardware som drar spesielt nytte av det.
I'll drop the hardening for thermald here just to get the PR through, but maybe droppin the entire thing should be discussed in another issue (or I might just create a PR dropping thermald)
44b8c9d4a3
toef418bf125
WIP: some systemd hardeningto some systemd hardeningI would like a few internet-exposed services, such as postgresql, as well, but at least noone can rotate our logs with malice anymore.
Looks Glockenspiel To Me 🚀
hehe, rotates with ill intent