From 7cbb59ea9a7ce811c7aed998349c47437b6b2c5f Mon Sep 17 00:00:00 2001 From: isabel Date: Wed, 15 Jul 2026 20:11:51 +0100 Subject: [PATCH] base/nix/nix: cleanup --- modules/base/nix/nix.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/modules/base/nix/nix.nix b/modules/base/nix/nix.nix index 3210cc55..5e23b11e 100644 --- a/modules/base/nix/nix.nix +++ b/modules/base/nix/nix.nix @@ -8,8 +8,6 @@ }: let inherit (lib.lists) optionals; - - sudoers = if (_class == "nixos") then "@wheel" else "@admin"; in { nix = { @@ -48,7 +46,9 @@ in auto-optimise-store = true; # users or groups which are allowed to do anything with the Nix daemon - allowed-users = [ sudoers ]; + # in the past trusted-users was also set but that's the same as adding a root + # user, so lets not do that! + allowed-users = [ (if (_class == "nixos") then "@wheel" else "@admin") ]; # we don't want to track the registry, but we do want to allow the usage # of the `flake:` references, so we need to enable use-registries -- 2.51.2