sudo.nix: initial config
This commit is contained in:
parent
2862aa7aa9
commit
805d897927
6 changed files with 31 additions and 19 deletions
21
modules/system/os/security/sudo.nix
Normal file
21
modules/system/os/security/sudo.nix
Normal file
|
@ -0,0 +1,21 @@
|
|||
{
|
||||
lib,
|
||||
pkgs,
|
||||
}: let
|
||||
inherit (lib) mkForce mkDefault;
|
||||
in {
|
||||
security = {
|
||||
sudo-rs.enable = mkForce false;
|
||||
sudo = {
|
||||
enable = true;
|
||||
# We use the default sudo package
|
||||
package = pkgs.sudo;
|
||||
|
||||
# Wheel user should need the password to execute sudo commands
|
||||
wheelNeedsPassword = mkDefault true;
|
||||
|
||||
# BUT, only wheel users should be able to use sudo.
|
||||
execWheelOnly = mkForce true;
|
||||
};
|
||||
};
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue