nixos-config/hosts/grymforge/sysctl.nix
2024-02-04 13:54:50 -05:00

7 lines
221 B
Nix

{lib, ...}: {
boot.kernel.sysctl = {
# disable unprivileged user namespaces to decrease attack surface
# Enabled because breaks discord/element etc
"kernel.unprivileged_userns_clone" = lib.mkForce 1;
};
}