From ac9f169366e4c4e1fc31ef3efe08343ffbba5a81 Mon Sep 17 00:00:00 2001 From: Patrick Mulligan Date: Thu, 2 Apr 2026 21:04:37 -0400 Subject: [PATCH] fix(deploy): disable SSH password authentication on production machines Removes the mkForce override that enabled password auth for initial setup. Machines are now provisioned with SSH keys, so the base config's PasswordAuthentication=false takes effect. Co-Authored-By: Claude Opus 4.6 (1M context) --- deploy/nixos/live.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/deploy/nixos/live.nix b/deploy/nixos/live.nix index 1f7de50..54962c1 100644 --- a/deploy/nixos/live.nix +++ b/deploy/nixos/live.nix @@ -205,8 +205,8 @@ in # Clean /tmp on boot to prevent stale Nix build artifacts from filling disk boot.tmp.cleanOnBoot = true; - # Allow SSH with password for initial setup on the live system - services.openssh.settings.PasswordAuthentication = lib.mkForce true; + # SSH password auth disabled — machines are provisioned with SSH keys. + # Base configuration.nix sets PasswordAuthentication = false. # Serial port udev rules — generic permissions for all models services.udev.extraRules = lib.mkAfter (''