aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorFranck Cuny <franck@fcuny.net>2025-08-12 10:18:59 -0700
committerFranck Cuny <franck@fcuny.net>2025-08-12 10:18:59 -0700
commit2fd25ace93bb7057ff5e0044907b0f3b431883a8 (patch)
tree0718521ea133e817ab0360d9fff342243f56659e
parentadd profiles for security, firewalls, and users (diff)
downloadinfra-2fd25ace93bb7057ff5e0044907b0f3b431883a8.tar.gz
add profiles for darwin and remote builder
-rw-r--r--machines/darwin/aarch64-darwin/HQ-KWNY2VH41P/default.nix1
-rw-r--r--machines/darwin/aarch64-darwin/mba-m2/default.nix3
-rw-r--r--profiles/darwin.nix3
-rw-r--r--profiles/darwin/security.nix5
-rw-r--r--profiles/nix/remote-builder.nix (renamed from profiles/remote-builder.nix)0
5 files changed, 8 insertions, 4 deletions
diff --git a/machines/darwin/aarch64-darwin/HQ-KWNY2VH41P/default.nix b/machines/darwin/aarch64-darwin/HQ-KWNY2VH41P/default.nix
index 3b8cab7..5581210 100644
--- a/machines/darwin/aarch64-darwin/HQ-KWNY2VH41P/default.nix
+++ b/machines/darwin/aarch64-darwin/HQ-KWNY2VH41P/default.nix
@@ -9,6 +9,7 @@
imports = [
"${self}/profiles/home-manager.nix"
"${self}/profiles/darwin.nix"
+ "${self}/profiles/darwin/security.nix"
];
system.primaryUser = adminUser.name;
diff --git a/machines/darwin/aarch64-darwin/mba-m2/default.nix b/machines/darwin/aarch64-darwin/mba-m2/default.nix
index 737c4a4..2ec7882 100644
--- a/machines/darwin/aarch64-darwin/mba-m2/default.nix
+++ b/machines/darwin/aarch64-darwin/mba-m2/default.nix
@@ -17,7 +17,8 @@
imports = [
"${self}/profiles/home-manager.nix"
"${self}/profiles/darwin.nix"
- "${self}/profiles/remote-builder.nix"
+ "${self}/profiles/nix/remote-builder.nix"
+ "${self}/profiles/darwin/security.nix"
];
system.primaryUser = adminUser.name;
diff --git a/profiles/darwin.nix b/profiles/darwin.nix
index 0ff8cc0..36010c7 100644
--- a/profiles/darwin.nix
+++ b/profiles/darwin.nix
@@ -46,9 +46,6 @@
# mkdir -p ~/Documents/screenshots
# '';
- # Touch ID for sudo auth
- security.pam.services.sudo_local.touchIdAuth = true;
-
nix = {
extraOptions = ''
tarball-ttl = 900
diff --git a/profiles/darwin/security.nix b/profiles/darwin/security.nix
new file mode 100644
index 0000000..178fca1
--- /dev/null
+++ b/profiles/darwin/security.nix
@@ -0,0 +1,5 @@
+{ ... }:
+{
+ # Touch ID for sudo auth
+ security.pam.services.sudo_local.touchIdAuth = true;
+}
diff --git a/profiles/remote-builder.nix b/profiles/nix/remote-builder.nix
index 50d3e84..50d3e84 100644
--- a/profiles/remote-builder.nix
+++ b/profiles/nix/remote-builder.nix