wallago/nix-system-services-hardened

System services hardened (lynis BOOT-5264) under nixos.

Nix

102

13 commits

updated Apr 27, 2026

See the code

README

nix-system-services-hardened

:zap: Hardening Result

System services hardened (lynis BOOT-5264) under nixos.
Suggest you to see https://linux-audit.com, if you are interested of how to hardened your config.

❯ systemd-analyze security
UNIT                                  EXPOSURE PREDICATE HAPPY
--------------------------------------------------------------
NetworkManager-dispatcher.service          3.5 OK        πŸ™‚
NetworkManager.service                     4.2 OK        πŸ™‚
accounts-daemon.service                    2.9 OK        πŸ™‚
acpid.service                              4.8 OK        πŸ™‚
auditd.service                             4.0 OK        πŸ™‚
blocky.service                             4.2 OK        πŸ™‚
bluetooth.service                          4.7 OK        πŸ™‚
colord.service                             4.9 OK        πŸ™‚
cups.service                               4.8 OK        πŸ™‚
dbus.service                               4.2 OK        πŸ™‚
display-manager.service                    4.8 OK        πŸ™‚
docker.service                             4.8 OK        πŸ™‚
getty@tty1.service                         4.7 OK        πŸ™‚
getty@tty2.service                         4.7 OK        πŸ™‚
getty@tty7.service                         4.7 OK        πŸ™‚
nix-daemon.service                         4.9 OK        πŸ™‚
nscd.service                               4.9 OK        πŸ™‚
polkit.service                             1.2 OK        πŸ™‚
reload-systemd-vconsole-setup.service      4.9 OK        πŸ™‚
rescue.service                             4.5 OK        πŸ™‚
rtkit-daemon.service                       3.1 OK        πŸ™‚
sshd.service                               4.9 OK        πŸ™‚
systemd-ask-password-console.service       4.3 OK        πŸ™‚
systemd-ask-password-wall.service          4.1 OK        πŸ™‚
systemd-hostnamed.service                  1.7 OK        πŸ™‚
systemd-journald.service                   4.5 OK        πŸ™‚
systemd-logind.service                     2.8 OK        πŸ™‚
systemd-machined.service                   3.0 OK        πŸ™‚
systemd-oomd.service                       1.8 OK        πŸ™‚
systemd-rfkill.service                     4.0 OK        πŸ™‚
systemd-timesyncd.service                  2.1 OK        πŸ™‚
systemd-udevd.service                      4.9 OK        πŸ™‚
user@1000.service                          4.8 OK        πŸ™‚
wpa_supplicant.service                     2.7 OK        πŸ™‚

⌨️ Commands

  • Check service log: journalctl -u SERVICE_NAME
  • Check service security: systemd-analyze security SERVICE_NAME
  • Check services security: systemd-analyze security

:book: Note

  1. Why i did it:
    • I didn't find any repo which provide hardened system service configs.
    • So the idea merged i my head to do it for nix lovers and others.
  2. What you can find inside this repo:
    • Each system service config file for listed above.
  3. Keep in mind:
    • I know it's not perfect, i want to give you help that i couldn't find.
    • If you want to suggest any improvement, make a PR.
    • If you find any error, make an issue.

πŸ“œ License

Apache License - see the LICENSE file for details.

πŸ’ Acknowledgements

Love u guys πŸ’œ.
Buy me a coffe if you've a mind to:1CJwob8qgoX7e897fupbyu3VbATMkgBpwM

image

Contributors

wallago

12 commits

hauskens

1 commits

Languages

Nix

100.0%

wallago/nix-system-services-hardened

System services hardened (lynis BOOT-5264) under nixos.

Nix

102

13 commits

updated Apr 27, 2026

See the code

README

nix-system-services-hardened

:zap: Hardening Result

System services hardened (lynis BOOT-5264) under nixos.
Suggest you to see https://linux-audit.com, if you are interested of how to hardened your config.

❯ systemd-analyze security
UNIT                                  EXPOSURE PREDICATE HAPPY
--------------------------------------------------------------
NetworkManager-dispatcher.service          3.5 OK        πŸ™‚
NetworkManager.service                     4.2 OK        πŸ™‚
accounts-daemon.service                    2.9 OK        πŸ™‚
acpid.service                              4.8 OK        πŸ™‚
auditd.service                             4.0 OK        πŸ™‚
blocky.service                             4.2 OK        πŸ™‚
bluetooth.service                          4.7 OK        πŸ™‚
colord.service                             4.9 OK        πŸ™‚
cups.service                               4.8 OK        πŸ™‚
dbus.service                               4.2 OK        πŸ™‚
display-manager.service                    4.8 OK        πŸ™‚
docker.service                             4.8 OK        πŸ™‚
getty@tty1.service                         4.7 OK        πŸ™‚
getty@tty2.service                         4.7 OK        πŸ™‚
getty@tty7.service                         4.7 OK        πŸ™‚
nix-daemon.service                         4.9 OK        πŸ™‚
nscd.service                               4.9 OK        πŸ™‚
polkit.service                             1.2 OK        πŸ™‚
reload-systemd-vconsole-setup.service      4.9 OK        πŸ™‚
rescue.service                             4.5 OK        πŸ™‚
rtkit-daemon.service                       3.1 OK        πŸ™‚
sshd.service                               4.9 OK        πŸ™‚
systemd-ask-password-console.service       4.3 OK        πŸ™‚
systemd-ask-password-wall.service          4.1 OK        πŸ™‚
systemd-hostnamed.service                  1.7 OK        πŸ™‚
systemd-journald.service                   4.5 OK        πŸ™‚
systemd-logind.service                     2.8 OK        πŸ™‚
systemd-machined.service                   3.0 OK        πŸ™‚
systemd-oomd.service                       1.8 OK        πŸ™‚
systemd-rfkill.service                     4.0 OK        πŸ™‚
systemd-timesyncd.service                  2.1 OK        πŸ™‚
systemd-udevd.service                      4.9 OK        πŸ™‚
user@1000.service                          4.8 OK        πŸ™‚
wpa_supplicant.service                     2.7 OK        πŸ™‚

⌨️ Commands

  • Check service log: journalctl -u SERVICE_NAME
  • Check service security: systemd-analyze security SERVICE_NAME
  • Check services security: systemd-analyze security

:book: Note

  1. Why i did it:
    • I didn't find any repo which provide hardened system service configs.
    • So the idea merged i my head to do it for nix lovers and others.
  2. What you can find inside this repo:
    • Each system service config file for listed above.
  3. Keep in mind:
    • I know it's not perfect, i want to give you help that i couldn't find.
    • If you want to suggest any improvement, make a PR.
    • If you find any error, make an issue.

πŸ“œ License

Apache License - see the LICENSE file for details.

πŸ’ Acknowledgements

Love u guys πŸ’œ.
Buy me a coffe if you've a mind to:1CJwob8qgoX7e897fupbyu3VbATMkgBpwM

image

Contributors

wallago

12 commits

hauskens

1 commits

Languages

Nix

100.0%