security/sudo: disable lecture and no longer persist /var/db
This commit is contained in:
parent
ee55e4a237
commit
2f202aac57
|
@ -17,6 +17,7 @@ let
|
||||||
# keep-sorted start
|
# keep-sorted start
|
||||||
programs.tools.common
|
programs.tools.common
|
||||||
security.polkit
|
security.polkit
|
||||||
|
security.sudo
|
||||||
services.dbus
|
services.dbus
|
||||||
services.journald
|
services.journald
|
||||||
services.openssh
|
services.openssh
|
||||||
|
|
10
nixos/profiles/security/sudo/default.nix
Normal file
10
nixos/profiles/security/sudo/default.nix
Normal file
|
@ -0,0 +1,10 @@
|
||||||
|
{ ... }:
|
||||||
|
{
|
||||||
|
security.sudo = {
|
||||||
|
execWheelOnly = true;
|
||||||
|
wheelNeedsPassword = true;
|
||||||
|
extraConfig = ''
|
||||||
|
Defaults lecture="never"
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
}
|
|
@ -2,7 +2,7 @@
|
||||||
{
|
{
|
||||||
environment.globalPersistence = {
|
environment.globalPersistence = {
|
||||||
directories = [
|
directories = [
|
||||||
"/var/db"
|
"/var/cache"
|
||||||
"/var/lib"
|
"/var/lib"
|
||||||
"/var/log"
|
"/var/log"
|
||||||
"/var/tmp"
|
"/var/tmp"
|
||||||
|
|
Loading…
Reference in a new issue