dotfiles/nixos/boot.nix
Cyryl Płotnicki c8102cafbe hardened
2020-02-16 09:23:31 +00:00

23 lines
579 B
Nix

{ config, pkgs, ... }:
{
fileSystems."/".options = [ "noatime" "nodiratime" "discard" ];
boot = {
kernelModules = [ "acpi_call" ];
extraModulePackages = with config.boot.kernelPackages; [ acpi_call ];
kernel.sysctl = {
"vm.swappiness" = 1;
"max_user_watches" = 524288;
"kernel.dmesg_restrict" = true;
"kernel.unprivileged_bpf_disabled" = true;
"kernel.unprivileged_userns_clone" = 1;
"net.core.bpf_jit_harden" = true;
};
loader.grub = {
enable = true;
version = 2;
useOSProber = true;
};
};
}