nixpkgs/nixos/modules
Felix Singer 3d30811d4e nixos/gerrit: Apply initial hardening using the systemd unit
These options are a good start for sandboxing the service. It's planned
to set `ProtectSystem` to `strict` instead of `full`, but that requires
specific directories to be configured as writable. It's also planned to
filter system calls. However, that requires more testing but it
shouldn't prevent us from applying these options for now and add others
later.

Signed-off-by: Felix Singer <felixsinger@posteo.net>
2024-10-10 07:12:28 +02:00
..
config Remove the revCount attribute from the generated flake registry (#316225) 2024-10-04 15:25:55 -07:00
hardware nixos/usbStorage: apply upstream (#284334) 2024-10-06 19:39:07 -04:00
i18n/input-method nixos/fcitx5: fix evaluation 2024-08-31 09:20:31 -04:00
image nixos/repart-verity-store: include original roothashes in repart-output.json 2024-09-30 22:45:05 +02:00
installer treewide: \xc2\xa0 -> 2024-10-02 15:33:06 +02:00
misc nixis/uinput: use a fixed GID for the uinput group 2024-10-05 10:21:26 +02:00
profiles macos-builder: readd Nix CLI for debugging (#347205) 2024-10-08 09:58:17 +02:00
programs nixos/nncp: refactor configuration merging 2024-10-09 09:07:11 +00:00
security nixos: improve systemd slice names (#345990) 2024-10-04 12:08:36 +02:00
services nixos/gerrit: Apply initial hardening using the systemd unit 2024-10-10 07:12:28 +02:00
system nixos/systemd: allow using writeShellApplication for systemd unit scripts 2024-10-08 12:01:48 +02:00
tasks nixos/networking: improve vlan service description 2024-10-04 22:09:01 +02:00
testing nixos/testing: Fix tty output 2024-09-05 10:54:55 +02:00
virtualisation nixos/libvirtd: add startDelay and shutdownTimeout option (#347023) 2024-10-09 16:58:16 +02:00
module-list.nix nixos/tailscale-derper: init (#306533) 2024-10-09 17:05:01 +02:00
rename.nix unifi-video: drop 2024-10-01 15:58:19 +01:00