forked from the-distro/infra
23 lines
590 B
Nix
23 lines
590 B
Nix
|
{ lib, pkgs, ... }: {
|
||
|
nix.package = pkgs.lix;
|
||
|
services.openssh.enable = lib.mkForce true;
|
||
|
|
||
|
networking.firewall.enable = true;
|
||
|
networking.firewall.logRefusedConnections = false;
|
||
|
networking.firewall.logReversePathDrops = true;
|
||
|
|
||
|
services.nginx = {
|
||
|
recommendedOptimisation = lib.mkDefault true;
|
||
|
recommendedTlsSettings = lib.mkDefault true;
|
||
|
recommendedProxySettings = lib.mkDefault true;
|
||
|
recommendedGzipSettings = lib.mkDefault true;
|
||
|
};
|
||
|
|
||
|
nix.gc = {
|
||
|
automatic = true;
|
||
|
persistent = true;
|
||
|
dates = "daily";
|
||
|
options = "--delete-older-than 30d";
|
||
|
};
|
||
|
}
|