blob: aee4bf06f2f55963a5743775dd90335e8f7c756a (
plain)
1
2
3
4
5
6
7
8
9
10
11
|
{ pkgs, lib, ... }:
with lib;
{
security.chromiumSuidSandbox.enable = true;
security.lockKernelModules = false;
boot.kernel.sysctl."user.max_user_namespaces" = 63414;
imports = [
<nixpkgs/nixos/modules/profiles/hardened.nix>
];
}
|