ca4a0b23ab
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, ...); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys, inherit, bool-compare guards); add missing trailing newlines
40 lines
641 B
Nix
40 lines
641 B
Nix
{
|
|
config,
|
|
pkgs,
|
|
...
|
|
}: {
|
|
boot = {
|
|
bootspec.enable = true;
|
|
|
|
initrd.systemd.enable = true;
|
|
|
|
supportedFilesystems = ["ntfs"];
|
|
|
|
kernelPackages = pkgs.linuxPackages_latest;
|
|
|
|
consoleLogLevel = 3;
|
|
|
|
kernelParams = [
|
|
"quiet"
|
|
"systemd.show_status=auto"
|
|
"rd.udev.log_level=3"
|
|
"plymouth.use-simpledrm"
|
|
];
|
|
|
|
plymouth.enable = true;
|
|
|
|
tmp = {
|
|
useTmpfs = true;
|
|
cleanOnBoot = true;
|
|
};
|
|
};
|
|
|
|
systemd.services.nix-daemon.environment.TMPDIR = "/var/tmp";
|
|
|
|
environment.systemPackages = [
|
|
config.boot.kernelPackages.cpupower
|
|
pkgs.brightnessctl
|
|
pkgs.ddcutil
|
|
];
|
|
}
|