Skip to content

Instantly share code, notes, and snippets.

View mibmo's full-sized avatar

mib mibmo

View GitHub Profile
@DJ-Laser
DJ-Laser / oops_all_greetd.nix
Created September 28, 2025 04:52
Replaces all getty/login instances with greetd+agreety
{
config,
pkgs,
lib,
...
}: let
inherit
(lib)
mkIf
mkOption
@ageis
ageis / systemd_service_hardening.md
Last active December 6, 2025 17:05
Options for hardening systemd service units

security and hardening options for systemd service units

A common and reliable pattern in service unit files is thus:

NoNewPrivileges=yes
PrivateTmp=yes
PrivateDevices=yes
DevicePolicy=closed
ProtectSystem=strict