From 3a669dd8fd05725e86ddb890d602d970bf5c5ee0 Mon Sep 17 00:00:00 2001 From: SebastianStork Date: Fri, 23 Jan 2026 11:26:59 +0100 Subject: [PATCH] sshd: Make sure to only ever listen on overlay address --- modules/system/services/sshd.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/system/services/sshd.nix b/modules/system/services/sshd.nix index a4621f4..a591940 100644 --- a/modules/system/services/sshd.nix +++ b/modules/system/services/sshd.nix @@ -16,7 +16,7 @@ in openssh = { enable = true; openFirewall = false; - ports = [ ]; + ports = lib.mkForce [ ]; listenAddresses = lib.singleton { addr = netCfg.overlay.address; port = 22; @@ -46,7 +46,7 @@ in users.users.seb.openssh.authorizedKeys.keyFiles = self.nixosConfigurations |> lib.attrValues - |> lib.filter (host: host.config.custom.networking.hostName != netCfg.hostName) + |> lib.filter (host: host.config.networking.hostName != netCfg.hostName) |> lib.filter (host: host.config |> lib.hasAttr "home-manager") |> lib.map (host: host.config.home-manager.users.seb.custom.programs.ssh) |> lib.filter (ssh: ssh.enable)