#boot.kernelPackages = pkgs.linuxPackages_hardened;
#boot.kernelPackages = pkgs.linuxPackages_latest_hardened;
#environment.memoryAllocator.provider = "libc";
-nix.allowedUsers = [ "@users" ];
+nix.settings.allowed-users = [ "@users" ];
networking.firewall.pingLimit = "--limit 60/minute --limit-burst 5";
security.allowSimultaneousMultithreading = false;
security.apparmor.enable = lib.mkDefault true;
Storage=persistent
SystemMaxUse=100M
'';
+systemd.coredump = {
+ enable = lib.mkDefault false;
+ extraConfig = ''
+ Compress=true
+ MaxUse=1024M
+ Storage=external
+ '';
+};
services.openssh = {
openFirewall = lib.mkDefault false;
passwordAuthentication = false;