fix(deploy): disable SSH password authentication on production machines
Removes the mkForce override that enabled password auth for initial setup. Machines are now provisioned with SSH keys, so the base config's PasswordAuthentication=false takes effect. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
b6521c4788
commit
ac9f169366
1 changed files with 2 additions and 2 deletions
|
|
@ -205,8 +205,8 @@ in
|
||||||
# Clean /tmp on boot to prevent stale Nix build artifacts from filling disk
|
# Clean /tmp on boot to prevent stale Nix build artifacts from filling disk
|
||||||
boot.tmp.cleanOnBoot = true;
|
boot.tmp.cleanOnBoot = true;
|
||||||
|
|
||||||
# Allow SSH with password for initial setup on the live system
|
# SSH password auth disabled — machines are provisioned with SSH keys.
|
||||||
services.openssh.settings.PasswordAuthentication = lib.mkForce true;
|
# Base configuration.nix sets PasswordAuthentication = false.
|
||||||
|
|
||||||
# Serial port udev rules — generic permissions for all models
|
# Serial port udev rules — generic permissions for all models
|
||||||
services.udev.extraRules = lib.mkAfter (''
|
services.udev.extraRules = lib.mkAfter (''
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue