blob: 9685d51bcead783f1fbb88ec1ee215f18cecb16a (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
|
{ ... }:
let
host = import ../hosts.nix;
in
{
imports = [
../modules/dns.nix
../modules/caddy.nix
../modules/gitsrv.nix
../modules/tailscale.nix
../modules/users.nix
];
nix.settings.trusted-users = [
"root"
"grace"
];
nix.settings.experimental-features = [
"nix-command"
"flakes"
];
boot.loader.grub = {
enable = true;
device = "/dev/vda";
};
networking.hostName = host.name;
services.openssh = {
enable = true;
openFirewall = true;
ports = [ 2222 ];
settings = {
PermitRootLogin = "no";
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
};
};
}
|