Commit Graph

87 Commits

Author SHA1 Message Date
fddefdde61 Update nixpkgs to 25.11-beta 2025-11-25 21:07:42 +09:00
56ef2b09b2 common/udisks2: only enable on graphical machines 2025-11-05 09:54:32 +09:00
36c9a5affc common/wpa_supplicant: harden 2025-11-05 09:47:16 +09:00
5a7269f55d common/irqbalance: apply chroot 2025-11-05 09:38:54 +09:00
99fac5e5aa common/rtkit: harden 2025-11-05 09:38:53 +09:00
80d078739b common/udisks2: harden 2025-11-05 09:38:53 +09:00
4d516b7bab common/polkit: apply chroot 2025-11-05 09:38:53 +09:00
704be04e26 common/packages: add more manpages 2025-11-05 08:50:16 +09:00
664be83949 common/packages: split off file from default.nix 2025-11-05 08:49:47 +09:00
52607f7ee6 common/dbus: temporarily undo hardening, system broke :( 2025-11-05 08:41:07 +09:00
f2931da4ab common/dbus: harden dbus-broker units 2025-10-28 13:46:26 +09:00
a3542e6a6c common: use nsncd instead of nscd 2025-10-28 11:52:49 +09:00
5d866049a0 common: use nftables as firewall 2025-10-28 11:52:09 +09:00
bec478767f xps16: change timezone 2025-10-03 10:47:36 +09:00
57b1390e45 treewide: get rid of nordic related config 2025-08-22 14:25:51 +02:00
8f6c8bc338 common/gnome-keyring: move to session.slice 2025-05-27 12:23:15 +02:00
18e37aa599 common/dconf: move to session.slice 2025-05-27 12:12:18 +02:00
ef33e52880 common/docker: split file, fix auto-prune service 2025-05-21 10:03:35 +02:00
c71f91a87f common/display-manager: split file, fix sddm theme, fix default compositor choice 2025-05-21 09:55:39 +02:00
abac62b42b nixpkgs 25.05 🎉 2025-05-20 20:57:25 +02:00
9132b537fd common/uptimed: add settings, sd_notify 2025-05-08 16:19:50 +02:00
150089a583 {common,home}/nix: finegrained tokens 2025-05-06 13:05:21 +02:00
1f43c4a4ba common: add loopback addresses for fqdn 2025-04-25 22:48:47 +02:00
c941b24880 {common,dosei/home}: set uid to 1000 2025-04-02 12:49:33 +02:00
64b1be2a3c common: don't start docker on boot 2025-04-01 11:05:53 +02:00
9ae857fb74 common: disable kernel module locking 2025-04-01 10:53:21 +02:00
770fd05e26 common/docker: enable autopruning 2025-04-01 10:53:03 +02:00
e1e9e7a398 common/openssh: more config 2025-03-17 09:48:19 +01:00
433b8b46a8 common/userdbd: fix 2025-03-15 02:20:25 +01:00
cce75f872f common: enable more systemd stuff 2025-03-15 00:44:43 +01:00
00c97b8da1 common: protect kernel image 2025-03-15 00:44:42 +01:00
5197de939a common/nix: restrict users 2025-03-15 00:44:42 +01:00
1c71991f09 common/graphical-desktop: enable 2025-03-15 00:44:42 +01:00
824d964d61 common/udisks2: enable 2025-03-15 00:44:42 +01:00
33fb8a9209 common/locate: use root user (plocate does not support localuser) 2025-03-15 00:44:41 +01:00
ac657c4a82 common: lock kernel modules 2025-03-15 00:44:41 +01:00
21187f3fb8 common: more tpm2 stuff 2025-03-15 00:44:41 +01:00
6200f89ef7 common/bluetooth: powerOnBoot by default 2025-03-15 00:44:41 +01:00
cdefda67de common: use tmpfs for /tmp 2025-03-15 00:44:41 +01:00
5a50e7fd02 common/nix: use latest 2025-03-15 00:44:40 +01:00
80668c0fd3 common: enable sysrq 2025-03-15 00:44:40 +01:00
881c5f3633 common/nixseparatedebuginfod: init 2025-03-15 00:44:40 +01:00
c885d4f515 common/locate: init 2025-03-15 00:44:40 +01:00
bcf29eb442 {common,home}/nix: use sops templates for access tokens 2025-03-13 15:13:59 +01:00
f8a11ae4fb common/nix: upgrade CPU scheduling policy 2025-03-13 15:06:53 +01:00
583db61b3f common/nix: auto optimise, auto gc 2025-03-13 15:06:52 +01:00
a5c5350f80 common/bluetooth: enable A2DP sink 2025-03-04 13:39:33 +01:00
a1a98fc580 common/pipewire: fix 2025-03-04 13:39:04 +01:00
c1dcf35d63 common/pipewire: enable wireplumber, add bluetooth config 2025-03-04 13:05:51 +01:00
fba3b614bd common/blueman: init 2025-03-04 13:04:43 +01:00