dotfiles/nixos/boot.nix

23 lines
506 B
Nix
Raw Normal View History

2019-04-21 10:18:35 +01:00
{ config, pkgs, ... }:
{
fileSystems."/".options = [ "noatime" "nodiratime" "discard" ];
2020-02-16 10:15:11 +00:00
security.lockKernelModules = false;
2019-04-21 10:18:35 +01:00
boot = {
2019-07-06 08:55:20 +01:00
kernel.sysctl = {
"vm.swappiness" = 1;
"max_user_watches" = 524288;
2019-12-24 19:13:52 +00:00
"kernel.dmesg_restrict" = true;
"kernel.unprivileged_bpf_disabled" = true;
"kernel.unprivileged_userns_clone" = 1;
"net.core.bpf_jit_harden" = true;
2019-07-06 08:55:20 +01:00
};
2019-04-21 10:18:35 +01:00
loader.grub = {
enable = true;
version = 2;
2019-07-06 08:55:20 +01:00
useOSProber = true;
2019-04-21 10:18:35 +01:00
};
};
2019-12-24 19:13:52 +00:00
2019-07-06 08:55:20 +01:00
}