about summary refs log tree commit diff
path: root/modules/nixos
diff options
context:
space:
mode:
Diffstat (limited to 'modules/nixos')
-rw-r--r--modules/nixos/openssh.nix21
-rw-r--r--modules/nixos/profiles/headful.nix1
2 files changed, 13 insertions, 9 deletions
diff --git a/modules/nixos/openssh.nix b/modules/nixos/openssh.nix
index 00d2852..36b85f8 100644
--- a/modules/nixos/openssh.nix
+++ b/modules/nixos/openssh.nix
@@ -7,27 +7,32 @@
 with lib; let
   cfg = config.nixfiles.modules.openssh;
 in {
-  options.nixfiles.modules.openssh.server.enable =
-    mkEnableOption "OpenSSH server";
+  options.nixfiles.modules.openssh.server = {
+    enable = mkEnableOption "OpenSSH server";
+
+    port = mkOption {
+      description = "OpenSSH server port.";
+      type = types.port;
+      default = 22022; # Port 22 should be occupied by a tarpit.
+    };
+  };
 
   config = mkIf cfg.server.enable {
     programs.mosh.enable = true;
 
-    services = let
-      port = 22022; # Port 22 should be occupied by a tarpit.
-    in {
+    services = {
       openssh = {
         enable = true;
-        ports = [port];
+        ports = [cfg.server.port];
         logLevel = "VERBOSE"; # Required by fail2ban.
-        permitRootLogin = "no";
+        permitRootLogin = mkForce "no";
         passwordAuthentication = false;
       };
 
       fail2ban.jails.sshd = ''
         enabled = true
         mode = aggressive
-        port = ${toString port}
+        port = ${toString cfg.server.port}
       '';
     };
   };
diff --git a/modules/nixos/profiles/headful.nix b/modules/nixos/profiles/headful.nix
index 01c442e..d15f004 100644
--- a/modules/nixos/profiles/headful.nix
+++ b/modules/nixos/profiles/headful.nix
@@ -68,7 +68,6 @@ in {
     programs = {
       iftop.enable = true;
       mtr.enable = true;
-      traceroute.enable = true;
     };
 
     services = {

Consider giving Nix/NixOS a try! <3