fix hardened kernel config, enable for runner
This commit is contained in:
parent
51b7e7887d
commit
3b465c7eb1
2 changed files with 5 additions and 3 deletions
|
@ -6,6 +6,7 @@
|
|||
];
|
||||
lyn.sops.secrets."hosts/forgejo-ci/forgejo_ci_token" = {};
|
||||
lyn.kernel.latest.enable = true;
|
||||
lyn.kernel.hardened.enable = true;
|
||||
lyn.profiles.base.enable = true;
|
||||
lyn.profiles.vm.enable = true;
|
||||
lyn.services.forgejo-ci.enable = true;
|
||||
|
|
|
@ -1,6 +1,7 @@
|
|||
{lib, pkgs, config, ...}: let
|
||||
ifApparmor = config.lyn.kernel.hardened.apparmor.enable;
|
||||
in{
|
||||
{lib, pkgs, config, cfg, ...}: let
|
||||
ifApparmor = cfg.apparmor.enable;
|
||||
in {
|
||||
opt.apparmor.enable = lib.mkEnableOption "apparmor";
|
||||
boot.kernelPackages = let
|
||||
kernel = pkgs.linux-libre;
|
||||
llvm = pkgs.llvmPackages_latest;
|
||||
|
|
Loading…
Reference in a new issue