feat: enable hardened kernel
This commit is contained in:
parent
1f2a2a706d
commit
06df535e84
|
@ -10,14 +10,17 @@ let
|
||||||
};
|
};
|
||||||
|
|
||||||
in {
|
in {
|
||||||
imports = [ ./hardware-configuration.nix ];
|
imports = [
|
||||||
|
<nixpkgs/nixos/modules/profiles/hardened.nix>
|
||||||
|
./hardware-configuration.nix
|
||||||
|
];
|
||||||
|
|
||||||
# networking
|
# networking
|
||||||
networking.hostName = "neodymium";
|
networking.hostName = "neodymium";
|
||||||
networking.networkmanager.enable = true;
|
networking.networkmanager.enable = true;
|
||||||
networking.firewall.enable = true;
|
networking.firewall.enable = true;
|
||||||
networking.firewall.allowedTCPPorts = [];
|
networking.firewall.allowedTCPPorts = [ ];
|
||||||
networking.firewall.allowedUDPPorts = [];
|
networking.firewall.allowedUDPPorts = [ ];
|
||||||
|
|
||||||
# use systemd-boot EFI boot loader
|
# use systemd-boot EFI boot loader
|
||||||
boot.loader.systemd-boot.enable = true;
|
boot.loader.systemd-boot.enable = true;
|
||||||
|
|
Loading…
Reference in a new issue