box,europa,faf,h,stan: use hardened kernel
This commit is contained in:
parent
470e3252bb
commit
78b56c7bf4
@ -96,7 +96,7 @@ in {
|
||||
boot.loader.systemd-boot.enable = true;
|
||||
boot.loader.efi.canTouchEfiVariables = true;
|
||||
|
||||
boot.kernelPackages = pkgs.linuxPackages;
|
||||
boot.kernelPackages = pkgs.linuxPackages_hardened;
|
||||
|
||||
doas.enable = true;
|
||||
|
||||
|
@ -57,7 +57,7 @@ in {
|
||||
efiSysMountPoint = "/boot/efi";
|
||||
};
|
||||
};
|
||||
kernelPackages = pkgs.linuxPackages;
|
||||
kernelPackages = pkgs.linuxPackages_hardened;
|
||||
kernelParams = [ "boot.shell_on_fail" "mem_sleep_default=deep" ];
|
||||
kernelModules = [ "kvm-intel" ];
|
||||
};
|
||||
|
@ -14,6 +14,8 @@ in {
|
||||
boot.loader.systemd-boot.enable = true;
|
||||
boot.loader.efi.canTouchEfiVariables = true;
|
||||
|
||||
boot.kernelPackages = pkgs.linuxPackages_hardened;
|
||||
|
||||
boot.supportedFilesystems = [ "zfs" ];
|
||||
boot.zfs.devNodes = "/dev/";
|
||||
|
||||
|
@ -33,6 +33,7 @@ in {
|
||||
boot.loader.grub.version = 2;
|
||||
boot.loader.grub.device = "/dev/sda";
|
||||
|
||||
boot.kernelPackages = pkgs.linuxPackages_hardened;
|
||||
boot.kernelParams = [ "net.ifnames=0" ];
|
||||
|
||||
tailscale.sshOnly = true;
|
||||
|
@ -29,7 +29,7 @@ in {
|
||||
"/crypto_keyfile.bin";
|
||||
secrets = { "/crypto_keyfile.bin" = null; };
|
||||
};
|
||||
kernelPackages = pkgs.linuxPackages;
|
||||
kernelPackages = pkgs.linuxPackages_hardened;
|
||||
kernelParams = [ "intel_idle.max_cstate=4" ];
|
||||
|
||||
};
|
||||
|
Loading…
Reference in New Issue
Block a user