mirror of
https://github.com/ryan4yin/nix-config.git
synced 2026-09-09 19:41:46 +02:00
fix(security): tighten desktop remote access
This commit is contained in:
@@ -11,7 +11,7 @@
|
||||
# in modules/nixos/desktop/ssh.nix (needed for GUI forwarding).
|
||||
X11Forwarding = lib.mkDefault false;
|
||||
# root user is used for remote deployment, so we need to allow it
|
||||
PermitRootLogin = "prohibit-password";
|
||||
PermitRootLogin = lib.mkDefault "prohibit-password";
|
||||
PasswordAuthentication = false; # disable password login
|
||||
};
|
||||
openFirewall = true;
|
||||
|
||||
@@ -1,7 +1,5 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
myvars,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
@@ -34,7 +32,7 @@
|
||||
services.sunshine = {
|
||||
enable = lib.mkDefault false; # default to false, for security reasons.
|
||||
autoStart = true;
|
||||
capSysAdmin = true; # only needed for Wayland -- omit this when using with Xorg
|
||||
capSysAdmin = false;
|
||||
openFirewall = true;
|
||||
settings = {
|
||||
# pc - Only localhost may access the web ui
|
||||
@@ -45,6 +43,4 @@
|
||||
wan_encryption_mode = 2;
|
||||
};
|
||||
};
|
||||
|
||||
users.users."${myvars.username}".extraGroups = lib.mkIf config.services.sunshine.enable [ "input" ];
|
||||
}
|
||||
|
||||
@@ -1,5 +1,8 @@
|
||||
{
|
||||
# Desktops keep X11 forwarding (current behavior, needed for GUI forwarding);
|
||||
# servers default to off (see modules/nixos/base/ssh.nix).
|
||||
services.openssh.settings.X11Forwarding = true;
|
||||
services.openssh.settings = {
|
||||
PermitRootLogin = "no";
|
||||
X11Forwarding = true;
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user