• 1 Post
  • 326 Comments
Joined 3 years ago
cake
Cake day: June 30th, 2023

help-circle
  • Add renovate bot (self-hosted or not) or a similar not to your nixos repository to automatically update your lock file. Enable automatic system rebuilds (not live, nixos-rebuild boot…) to keep in sync with the repo.

    Include multiple nixos systems in one repo, then reuse configuration or even make them reference each other (if you want that)

    Find an issue to report upstream (or even add a pull request)

    Fully automate your reinstall using disko and nixos-anywhere (don’t forget luks)

    Be happy (optional)

    Go over everything you’ve written in your repo so far, realise it’s formatted wrong and spend 2 hours fixing it until it no longer works

    Build a derivation for something that doesn’t exist (also add a pull request if applicable and you’ve got time to maintain it)

    Add a little nixpkgs-unstable, as a treat (use overlays)

    Backups

    Build a server so convoluted, kubernetes is easier to manage (I am here)







  • There exists shims that are signed by Microsoft and were not revoked. Normally this would be fine but these shims had weaknesses that allowes hackers to load any code using them. Normally the shims should only run other signed/trusted code. These vulnerable shims can be used to bypass secure boot by replacing your existing bootloader with the shim and then running rootkits/hackerOS/whatever and bypass bitlocker using TPM or just running a level 0 virus that can’t be detected by the OS on any PC which trusts Microsoft’s keys (99% of all PCs)

    To prevent this you’d have to not trust the vulnerable shims by either adding them manually to the exclusions list or using your own secure boot keys which would only trust the few bootloader files your pc uses and no other files.

    Worst case: it behaves as if secure boot wasn’t on. Without secure boot you wouldn’t need this exploit cause then you can replace the bootloader with whatever you want anyways. With or without secure boot you need administrative permission to replace the bootloader so this is only an issue after your PC is already compromised or if someone had physical access to your PC.



  • I have a Server with ~16 podman services, each their own user, network namespace and uids. This is managed using NixOS and Home manager (which supports quadlets) but I am changing my setup to a single node k3s cluster with user namespaces because that seems simpler to manage. Here a snippet for how the subuids/subuids are defined:

    users.users.<username> = {
            subUidRanges = [{
                startUid = 100000+65536*( config.users.users.<username>.uid - 999);
                count = 65536;
            }];
            subGidRanges = [{
                startGid = 100000+65536*( config.users.users.<username>.uid - 999);
                count = 65536;
            }];
            home = "[...]";
            isNormalUser = true;
            linger = true;
            group = "users";
            openssh.authorizedKeys.keys = config.users.users.root.openssh.authorizedKeys.keys;
        };