chore: minor cleanups (remove unused lens, LSP doc, editorconfig, docker subnet)
CI / flake (pull_request) Successful in 3m30s
CI / flake (pull_request) Successful in 3m30s
- Remove the unused Lens package entirely: drop pkgs.lens from the work host and its unfree entry from flake.nix. Nothing else needed it, so unfreePackages is now just claude-code. (pkgs.lens has pname "lens-desktop", which was the string the unfree predicate matched.) - home/README.md: the Nix LSP is nil_ls, not nil. - .editorconfig: remove the rule block that duplicated the [*] defaults. - hosts/RPi5/docker.nix: name the trusted Docker subnet in a let binding rather than repeating the literal CIDR. Deferred from the audit bundle: the .gitignore firmware entry (documented, low value) and the per-eval nixpkgs-unstable overlay import (inherently per-system, no clean hoist). Closes #53
This commit is contained in:
@@ -8,6 +8,10 @@
|
||||
# secure upgrade path is mutual TLS on 2376 (--tlsverify with client certs);
|
||||
# that needs out-of-band cert provisioning and is intentionally not wired here.
|
||||
{ ... }:
|
||||
let
|
||||
# LAN allowed to reach the unauthenticated Docker TCP socket (see SECURITY above).
|
||||
trustedSubnet = "10.187.1.0/24";
|
||||
in
|
||||
{
|
||||
virtualisation.docker.enable = true;
|
||||
|
||||
@@ -29,6 +33,6 @@
|
||||
# CIDR to match the LAN that should reach the Docker API.
|
||||
networking.nftables.enable = true;
|
||||
networking.firewall.extraInputRules = ''
|
||||
ip saddr 10.187.1.0/24 tcp dport 2375 accept
|
||||
ip saddr ${trustedSubnet} tcp dport 2375 accept
|
||||
'';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user