fix(deploy): disable SSH password authentication on production machines

Removes the mkForce override that enabled password auth for initial
setup. Machines are now provisioned with SSH keys, so the base
config's PasswordAuthentication=false takes effect.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-04-02 21:04:37 -04:00
commit ac9f169366

View file

@ -205,8 +205,8 @@ in
# Clean /tmp on boot to prevent stale Nix build artifacts from filling disk
boot.tmp.cleanOnBoot = true;
# Allow SSH with password for initial setup on the live system
services.openssh.settings.PasswordAuthentication = lib.mkForce true;
# SSH password auth disabled — machines are provisioned with SSH keys.
# Base configuration.nix sets PasswordAuthentication = false.
# Serial port udev rules — generic permissions for all models
services.udev.extraRules = lib.mkAfter (''