{ flake, config, ... }: let inherit (flake.config.people) user0 user1 user2 ; inherit (flake.config.machines) devices ; hostname = config.networking.hostName; desktop = devices.desktop.name; server = devices.server.name; fallaryn = devices.fallaryn.name; bartholomew = devices.bartholomew.name; in { security = { doas = { enable = true; extraRules = [ { keepEnv = true; noPass = true; users = [ ( if hostname == desktop then user0 else if hostname == server then user0 else if hostname == bartholomew then user1 else if hostname == fallaryn then user2 else "" ) ]; } ]; }; # sudo.enable = false; }; }