Compare commits
No commits in common. "ceb94d7cb182f93fce6364ac01da3df30d6c8e4c" and "a65cbaee81ef5519ea82d41cc9c6348f227b44ac" have entirely different histories.
ceb94d7cb1
...
a65cbaee81
3 changed files with 0 additions and 56 deletions
|
|
@ -1,29 +0,0 @@
|
||||||
_: {
|
|
||||||
security = {
|
|
||||||
audit = {
|
|
||||||
enable = true;
|
|
||||||
failureMode = 2;
|
|
||||||
rules = [
|
|
||||||
"-a always,exit -F arch=b64 -S mount,umount2,swapon,swapoff -k fs_ops"
|
|
||||||
"-a always,exit -F arch=b64 -S init_module,delete_module,finit_module -k kernel_mods"
|
|
||||||
"-a always,exit -F arch=b64 -S bind,connect,accept -F success=0 -k net_violations"
|
|
||||||
"-w /run/secrets -p r -k secret_read"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
auditd = {
|
|
||||||
enable = true;
|
|
||||||
settings = {
|
|
||||||
flush = "incremental_async";
|
|
||||||
freq = 50;
|
|
||||||
max_log_file = 10;
|
|
||||||
num_logs = 3;
|
|
||||||
max_log_file_action = "rotate";
|
|
||||||
admin_space_left_action = "suspend";
|
|
||||||
disk_full_action = "suspend";
|
|
||||||
disk_error_action = "suspend";
|
|
||||||
log_format = "ENRICHED";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
@ -1,13 +0,0 @@
|
||||||
_: {
|
|
||||||
security = {
|
|
||||||
unprivilegedUsernsClone = false;
|
|
||||||
forcePageTableIsolation = true;
|
|
||||||
allowSimultaneousMultithreading = false;
|
|
||||||
protectKernelImage = true;
|
|
||||||
lockKernelModules = true;
|
|
||||||
|
|
||||||
virtualisation = {
|
|
||||||
flushL1DataCache = "always";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
@ -1,14 +0,0 @@
|
||||||
_: {
|
|
||||||
services = {
|
|
||||||
journald = {
|
|
||||||
audit = true;
|
|
||||||
storage = "volatile";
|
|
||||||
rateLimitBurst = 1000;
|
|
||||||
rateLimitInterval = "30s";
|
|
||||||
extraConfig = ''
|
|
||||||
RuntimeMaxUse=128M
|
|
||||||
MaxRetentionSec=1day
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue