Skip to content
notifications
D

Configuration editor info Values set here apply at the selected scope. Enforce locks a value for everything below (most-general wins); a plain value is a default the more specific scope may override. Every change passes the gate and commits to git. Changing a value here configures it. If it is something your organisation has to be able to DEMONSTRATE - and most controls are - set it through a policy instead: that records why, keeps a lower scope from weakening it, and re-checks it. See Policies.

You are editing
domainOrganisation chevron_right
chevron_right

appsCapabilities info One click turns on a capability and its sensible companions, leaving only the real choices visible. Applies at the scope above; adjust anything afterwards.

shield_personSecure workplace

Harden a staff laptop in one step: Secure Boot on, the office suite installed, and a conservative SSH login limit. Apply it, then adjust anything below.

inventory_2Apps at this scope info Additive across the chain: a device gets the union of org, group ancestry and its own lists. Names only (nixpkgs attrs, flathub ids, repo overlays) - never code.

packages nothing at this scope
flatpaks nothing at this scope
overlays nothing at this scope

apps

2 keys
Web browser info apps.browser boolean default: true

Web browser (Firefox).

inherits
Office suite info apps.office boolean default: false

Office suite (LibreOffice).

inherits

general

9 keys
Audio info audio boolean default: true Off is for machines with nobody sitting at them.

Sound and microphone (PipeWire), including the real-time scheduling a call needs.

inherits
Bluetooth info bluetooth boolean default: true

Bluetooth for headsets, mice and keyboards.

inherits
Desktop environment info desktop one of "gnome", "plasma", "none" default: "gnome"

Desktop environment. `none` gives a console-only machine, which is what a server or a kiosk wants.

inherits
Docking stations info docks boolean default: true A dock is the first thing an office user plugs in; without this it is authorised by nobody and works for nobody.

Thunderbolt dock support (bolt).

inherits
Firmware updates info firmwareUpdates boolean default: true BIOS and dock firmware are part of the attack surface, and a fleet that cannot be patched is a finding.

Let devices fetch firmware updates (fwupd).

inherits
Printing info printing boolean default: false Off by default: it starts a daemon and makes the device answer for printers on whatever network it is on, which is an organisation's decision rather than a default.

Printing (CUPS), discovering printers announced on the local network.

inherits
Secure Boot high risk info secureboot boolean default: false Takes effect when a device is (re)imaged: the firmware has to be in setup mode for the keys to be enrolled, which cannot be arranged remotely.

Enforce Secure Boot with machine-owned keys.

inherits
Time servers info timeServers list of string default: ["0.pool.ntp.org","1.pool.ntp.org"] Point these at your own infrastructure if you have it: a fleet that trusts a public pool for time is trusting it for authentication too.

NTP servers.

inherits
Time zone info timeZone string default: "Europe/Amsterdam"

System time zone.

inherits

ssh

1 keys
SSH login attempts info ssh.maxAuthTries positive integer, meaning >0 default: 3

Maximum SSH authentication attempts per connection.

inherits