wip on new module system, copied secrets over

This commit is contained in:
RingOfStorms (Joshua Bell) 2024-12-23 23:43:19 -06:00
parent 25e9d06354
commit 7f5e4a0d93
126 changed files with 2722 additions and 30 deletions

28
modules/common/ssh.nix Normal file
View file

@ -0,0 +1,28 @@
{
config,
lib,
...
}:
with lib;
{
config = {
# Use fail2ban
services.fail2ban = {
enable = true;
};
# Open ports in the firewall if enabled.
networking.firewall.allowedTCPPorts = mkIf config.mods.common.sshPortOpen [
22 # sshd
];
# Enable the OpenSSH daemon.
services.openssh = {
enable = true;
settings = {
LogLevel = "VERBOSE";
PermitRootLogin = "yes";
};
};
};
}