diff --git a/modules/nixos/security/default.nix b/modules/nixos/security/default.nix index cb9c3038..55b7d442 100644 --- a/modules/nixos/security/default.nix +++ b/modules/nixos/security/default.nix @@ -9,7 +9,6 @@ ./pam.nix # pam configuration ./polkit.nix # polkit configuration ./run0.nix # run0 config - ./sudo.nix # sudo rules and configuration # keep-sorted end ]; } diff --git a/modules/nixos/security/run0.nix b/modules/nixos/security/run0.nix index 3e04cc28..f2c8c352 100644 --- a/modules/nixos/security/run0.nix +++ b/modules/nixos/security/run0.nix @@ -5,10 +5,16 @@ ... }: { - security.run0 = { - # wheelNeedsPassword = false means wheel group can execute commands without - # a password so just disable it - wheelNeedsPassword = false; + security = { + run0 = { + # wheelNeedsPassword = false means wheel group can execute commands without + # a password so just disable it + wheelNeedsPassword = false; + }; + + # we are committed + sudo.enable = false; + sudo-rs.enable = false; }; garden.packages = { diff --git a/modules/nixos/security/sudo.nix b/modules/nixos/security/sudo.nix deleted file mode 100644 index 65c7aa8e..00000000 --- a/modules/nixos/security/sudo.nix +++ /dev/null @@ -1,30 +0,0 @@ -{ lib, ... }: -let - inherit (lib.modules) mkDefault; -in -{ - security = { - sudo.enable = false; - - # lets swap out our sudo for sudo-rs just like ubuntu does - # - sudo-rs = { - enable = false; - - # wheelNeedsPassword = false means wheel group can execute commands without a password - # so just disable it, it only hurt security, BUT ... see below what commands can be run without password - wheelNeedsPassword = mkDefault false; - - # only allow members of the wheel group to execute sudo - execWheelOnly = true; - - # i dont like lectures - extraConfig = '' - Defaults !lecture - Defaults pwfeedback - Defaults env_keep += "EDITOR PATH DISPLAY" - Defaults timestamp_timeout = 300 - ''; - }; - }; -}