restrict nix remote builder ssh to nix daemon
Snippet taken from SrvOS
This commit is contained in:
@@ -39,7 +39,9 @@ in
|
|||||||
isSystemUser = true;
|
isSystemUser = true;
|
||||||
group = cfg.group;
|
group = cfg.group;
|
||||||
useDefaultShell = true;
|
useDefaultShell = true;
|
||||||
openssh.authorizedKeys.keys = cfg.authorizedKeys;
|
openssh.authorizedKeys.keys = map (
|
||||||
|
key: ''restrict,command="nix-daemon --stdio" ${key}''
|
||||||
|
) cfg.authorizedKeys;
|
||||||
};
|
};
|
||||||
|
|
||||||
users.groups.${cfg.user} = { };
|
users.groups.${cfg.user} = { };
|
||||||
|
|||||||
Reference in New Issue
Block a user