refactor: final architecture audit and hardening

This commit is contained in:
Bernardo Magri
2026-04-06 21:49:34 +01:00
parent 8b4e9ef6c8
commit 0ce8602384
6 changed files with 85 additions and 41 deletions

View File

@@ -47,10 +47,10 @@ in
"/var/log"
"/var/lib/nixos"
"/var/lib/systemd/coredump"
"/var/lib/systemd/timesync"
"/var/lib/NetworkManager"
"/etc/NetworkManager/system-connections"
"/var/lib/bluetooth"
"/var/lib/fprint"
"/etc/NetworkManager/system-connections"
"/etc/nixos"
"/etc/ssh"
];
@@ -58,6 +58,18 @@ in
"/etc/machine-id"
"/etc/supergfxd.conf"
];
users.nomarchy = {
directories = [
".ssh"
".gnupg"
".local/share/keyrings"
"Documents"
"Downloads"
"Pictures"
"Videos"
"Projects"
];
};
};
};
}