feat(security): swap sudo for the memory-safe sudo-rs
CI / flake (push) Skipped
CI / flake (pull_request) Successful in 4m6s
CI / flake (push) Skipped
CI / flake (pull_request) Successful in 4m6s
security.sudo-rs.enable sets security.sudo.enable = false via mkDefault, so this is a straight swap; the two modules assert against being on together. The fleet only uses the stock policy -- wheel may run anything, with a password -- which sudo-rs implements fully. It does not cover host aliases, LDAP/SSSD sudoers, sudoreplay or most Defaults settings; needing any of those means reverting to security.sudo. The macOS host is unaffected and keeps Apple's sudo with Touch ID. Recovery from a host that will not escalate is documented in the module and in home/README.md: get a root shell that does not go through sudo, then roll back the generation.
This commit is contained in:
+24
-8
@@ -176,6 +176,21 @@ to `KUBECONFIG=prodconfig kubectl …`, per the alias-expansion note above.
|
||||
Completions are kubectl's own (`compdef kubecolor=kubectl`). Escape hatch as
|
||||
ever: `command kubectl`.
|
||||
|
||||
### sudo → sudo-rs
|
||||
|
||||
Every NixOS host now uses **sudo-rs**, the memory-safe reimplementation, in
|
||||
place of `sudo` (`modules/common-nixos.nix`; the macOS host keeps Apple's sudo
|
||||
with Touch ID). Day to day there is nothing to learn — `sudo`, `sudo -i`,
|
||||
`sudo -u`, `sudo -l`, `sudoedit` and `visudo` all behave as before against this
|
||||
fleet's stock "wheel, with a password" policy. What it does **not** implement:
|
||||
host aliases, LDAP/SSSD sudoers, `sudoreplay`, and most `Defaults` settings.
|
||||
Needing any of those means reverting to `security.sudo`.
|
||||
|
||||
If a host ever refuses to escalate, get a root shell that does not go through
|
||||
sudo (`wsl -u root -d NixOS` on the work box; the console or a serial/HDMI login
|
||||
elsewhere) and roll back with `nixos-rebuild switch --rollback`, or pick the
|
||||
previous generation from the boot menu.
|
||||
|
||||
## tmux
|
||||
|
||||
**Auto-start:** opening any interactive terminal — foot, iTerm2, the WSL shell, the
|
||||
@@ -334,11 +349,12 @@ Claude to route new memories there.
|
||||
|
||||
## Per-host differences
|
||||
|
||||
| | Personal Linux (sway) | macOS | Work WSL (EDaaS) |
|
||||
| --------------------------- | --------------------- | ----------------- | --------------------------- |
|
||||
| Auto-tmux | yes (foot/TTY) | yes (iTerm2) | yes (WSL shell) |
|
||||
| `kubectl` → kubecolor | no (no kubectl) | no | yes (work module) |
|
||||
| git email | `iam@emmathe.dev` | `iam@emmathe.dev` | `…@citrix.com` (work) |
|
||||
| ssh config managed | yes | yes | no (keeps corporate config) |
|
||||
| ssh-agent | yes | launchd | yes (work module) |
|
||||
| GUI / theming (desktop.nix) | yes | no | no |
|
||||
| | Personal Linux (sway) | macOS | Work WSL (EDaaS) |
|
||||
| --------------------------- | --------------------- | --------------------- | --------------------------- |
|
||||
| Auto-tmux | yes (foot/TTY) | yes (iTerm2) | yes (WSL shell) |
|
||||
| `kubectl` → kubecolor | no (no kubectl) | no | yes (work module) |
|
||||
| `sudo` implementation | sudo-rs | Apple sudo + Touch ID | sudo-rs |
|
||||
| git email | `iam@emmathe.dev` | `iam@emmathe.dev` | `…@citrix.com` (work) |
|
||||
| ssh config managed | yes | yes | no (keeps corporate config) |
|
||||
| ssh-agent | yes | launchd | yes (work module) |
|
||||
| GUI / theming (desktop.nix) | yes | no | no |
|
||||
|
||||
Reference in New Issue
Block a user