dotfiles/modules/nixos/ssh.nix
2025-10-22 13:38:59 +07:00

17 lines
443 B
Nix

{ lib, ... }: {
services.openssh = {
enable = lib.mkDefault true;
openFirewall = lib.mkDefault true;
settings = {
PermitRootLogin = "no";
PasswordAuthentication = false;
};
};
# Run tailscale so the VM can be reached over the mesh network for SSH.
services.tailscale = {
enable = lib.mkDefault true;
useRoutingFeatures = lib.mkDefault "client";
extraUpFlags = lib.mkDefault [ "--ssh" ];
};
}