security: make firewall secure-by-default, disable explicitly on servers

Flip the base firewall default to ON so new hosts are protected by default. Servers keep the firewall off (trusted internal LAN, WAN protected at the router) via explicit overrides in modules/nixos/server/{server,server-aarch64}.nix. Behavior-preserving for all 18 current hosts; adds a security-firewall eval test guarding the per-host state.
This commit is contained in:
Ryan Yin
2026-08-26 18:14:43 +08:00
parent 7364d5aa1b
commit 72a6e95cab
7 changed files with 39 additions and 2 deletions
+4
View File
@@ -17,6 +17,10 @@
../../base
];
# Servers run on the trusted internal LAN (NAT'd; WAN protected at the router).
# Keep the firewall off here; the secure default is ON (see modules/nixos/base/ssh.nix).
networking.firewall.enable = false;
# Fix: jasper is marked as broken, refusing to evaluate.
environment.enableAllTerminfo = lib.mkForce false;
}
+4
View File
@@ -4,4 +4,8 @@
../base
../../base
];
# Servers run on the trusted internal LAN (NAT'd; WAN protected at the router).
# Keep the firewall off here; the secure default is ON (see modules/nixos/base/ssh.nix).
networking.firewall.enable = false;
}