From b9cb86c8e3d1414caab93af452b6a55ff77e4b4d Mon Sep 17 00:00:00 2001 From: Ryan Yin Date: Thu, 26 Sep 2024 16:19:37 +0800 Subject: [PATCH] docs: hardening --- hardening/README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/hardening/README.md b/hardening/README.md index 9f4cd73a..bc20aed9 100644 --- a/hardening/README.md +++ b/hardening/README.md @@ -68,6 +68,9 @@ provide a much higher level of security. - [Sandboxing all programs by default - NixOS Discourse](https://discourse.nixos.org/t/sandboxing-all-programs-by-default/7792) - [在 Firejail 中运行 Steam](https://imbearchild.cyou/archives/2021/11/steam-in-firejail/) - [Firejail - Arch Linux Wiki](https://wiki.archlinux.org/title/Firejail) +- [Paranoid NixOS Setup - xeiaso](https://xeiaso.net/blog/paranoid-nixos-2021-07-18/) +- [nix-mineral](https://github.com/cynicsketch/nix-mineral): NixOS module for convenient system + hardening. - nixpak configs: - https://github.com/pokon548/OysterOS/tree/b97604d89953373d6316286b96f6a964af2c398d/desktop/application - https://github.com/segment-tree/my-nixos/tree/ceb6041f73bd9edcb78a8818b27a28f7c629193b/hm/me/apps/nixpak