dotfiles/modules/nixos/core/doas/default.nix

55 lines
836 B
Nix
Raw Normal View History

{
flake,
config,
...
}:
let
inherit (flake.config.people)
2025-01-08 19:06:14 -06:00
user0
2025-01-31 01:49:36 -06:00
user1
user2
2025-01-08 19:06:14 -06:00
;
inherit (flake.config.machines)
devices
;
hostname = config.networking.hostName;
2025-03-01 15:55:23 -06:00
mars = devices.mars.name;
ceres = devices.ceres.name;
venus = devices.venus.name;
2025-03-01 15:55:23 -06:00
charon = devices.charon.name;
deimos = devices.deimos.name;
userLogic =
if
builtins.elem hostname [
mars
deimos
ceres
]
then
user0
else if hostname == charon then
user1
else if hostname == venus then
user2
else
"";
in
{
2024-10-06 15:25:05 -05:00
security = {
doas = {
enable = true;
extraRules = [
{
keepEnv = true;
noPass = true;
2025-01-08 19:06:14 -06:00
users = [
userLogic
2025-01-08 19:06:14 -06:00
];
2024-10-06 15:25:05 -05:00
}
];
};
# sudo.enable = false;
};
}