1 { inputs, pkgs, lib, config, ... }:
3 security.lockKernelModules = false;
4 security.virtualisation.flushL1DataCache = lib.mkForce null;
5 security.gnupg.agent = {
6 keyring."00B1DD47EA6B7BEF92FFEA66922C6249D6336C94" = {
7 passwordGpg = "gnupg/root.gpg";
10 services.openssh.extraConfig = ''
11 # This is for removing remote gpg-agent's socket
12 StreamLocalBindUnlink yes
15 environment.systemPackages = [