diff --git a/default.nix b/default.nix index 465ddb6..97e07dd 100755 --- a/default.nix +++ b/default.nix @@ -12,8 +12,6 @@ in { ]; i18n.defaultLocale = "en_US.UTF-8"; - - nix.settings.experimental-features = [ "nix-command" "flakes" ]; system.stateVersion = lib.mkDefault "23.11"; } diff --git a/hosts/server/default.nix b/hosts/server/default.nix index 8e05c59..a04b772 100755 --- a/hosts/server/default.nix +++ b/hosts/server/default.nix @@ -48,8 +48,6 @@ mosh.enable = true; }; - - security.enable = true; }; time.timeZone = "America/Los_Angeles"; diff --git a/modules/security.nix b/modules/security.nix deleted file mode 100755 index 4dc2268..0000000 --- a/modules/security.nix +++ /dev/null @@ -1,37 +0,0 @@ -{ config, lib, options, pkgs, ... }: - -with lib; -let - cfg = config.modules.security; -in { - options.modules.security = { - enable = mkOption { - type = types.bool; - default = true; - }; - }; - - config = mkIf cfg.enable { - security.rtkit.enable = true; - - boot.kernel.sysctl = { - "kernel.sysrq" = 0; - - "net.ipv4.conf.all.accept_source_code" = 0; - "net.ipv6.conf.all.accept_source_code" = 0; - "net.ipv4.conf.default.send_redirects" = 0; - "net.ipv4.conf.all.send_redirects" = 0; - "net.ipv4.conf.default.accept_redirects" = 0; - "net.ipv4.conf.all.accept_redirects" = 0; - "net.ipv6.conf.default.accept_redirects" = 0; - "net.ipv6.conf.all.accept_redirects" = 0; - "net.ipv4.conf.default.secure_redirects" = 0; - "net.ipv4.conf.all.secure_redirects" = 0; - "net.ipv4.tcp_syncookies" = 1; - "net.ipv4.tcp_rfc1337" = 1; - "net.ipv4.tcp_fastopen" = 3; - "net.ipv4.tcp_conjestion_control" = "bbr"; - "net.core.default_qdisc" = "cake"; - }; - }; -} diff --git a/readme.md b/readme.md index b36a2bf..595589b 100755 --- a/readme.md +++ b/readme.md @@ -14,15 +14,6 @@ _Commands here will assume you are currently in the directory of the dotfiles._ ```sh sudo nixos-rebuild switch --flake ".#server" ``` -- To update the system: - ```sh - sudo nixos-rebuild switch --upgrade --flake ".#server" - ``` -- To test the system: - ```sh - nix flake check - ``` - ## Permissions _Commands here will assume you are currently in the directory of the dotfiles._