security: harden some SP modules NixOS config evaluation permissions

This commit is contained in:
Alexander Tomokhov 2024-12-26 18:42:41 +04:00
parent 3a904f599e
commit f07b867af2
3 changed files with 17 additions and 17 deletions

View file

@ -1,11 +1,10 @@
[
["mailserver", "fqdn"],
["mailserver", "ldap"],
["mailserver", "vmailUID"],
["passthru", "selfprivacy", "auth"],
["security", "acme", "certs"],
["selfprivacy", "domain"],
["selfprivacy", "modules"],
["services"],
["systemd", "services", "kanidm"]
[ "passthru", "selfprivacy", "auth" ],
[ "security", "acme", "certs" ],
[ "selfprivacy", "domain" ],
[ "selfprivacy", "modules", "auth" ],
[ "services", "kanidm" ],
[ "services", "oauth2-proxy", "enable" ],
[ "services", "oauth2-proxy", "nginx" ],
[ "systemd", "services", "kanidm" ]
]

View file

@ -1,9 +1,8 @@
[
["mailserver", "fqdn"],
["passthru", "selfprivacy", "auth", "auth-fqdn"],
["passthru", "selfprivacy", "auth", "oauth2-provider-name"],
["selfprivacy", "domain"],
["selfprivacy", "modules", "auth"],
["selfprivacy", "modules", "roundcube"],
["service", "kanidm"]
[ "mailserver", "fqdn" ],
[ "passthru", "selfprivacy", "auth", "auth-fqdn" ],
[ "passthru", "selfprivacy", "auth", "oauth2-provider-name" ],
[ "selfprivacy", "domain" ],
[ "selfprivacy", "modules", "auth" ],
[ "selfprivacy", "modules", "roundcube" ]
]

View file

@ -13,6 +13,8 @@
[ "services", "opendkim" ],
[ "services", "postfix", "group" ],
[ "services", "postfix", "user" ],
[ "services", "redis" ],
[ "services", "redis", "servers", "rspamd", "bind" ],
[ "services", "redis", "servers", "rspamd", "port" ],
[ "services", "redis", "servers", "rspamd", "requirePass" ],
[ "services", "rspamd" ]
]