nixpkgs/nixos/modules/services/misc
Martin Weinelt a691549f7e
nixos/zigbee2mqtt: harden systemd unit
This is what is still exposed, and it allows me to control my lamps from
within home-assistant.

✗ PrivateNetwork=                                             Service has access to the host's network                                            0.5
✗ RestrictAddressFamilies=~AF_(INET|INET6)                    Service may allocate Internet sockets                                               0.3
✗ DeviceAllow=                                                Service has a device ACL with some special devices                                  0.1
✗ IPAddressDeny=                                              Service does not define an IP address allow list                                    0.2
✗ PrivateDevices=                                             Service potentially has access to hardware devices                                  0.2
✗ RootDirectory=/RootImage=                                   Service runs within the host's root directory                                       0.1
✗ SupplementaryGroups=                                        Service runs with supplementary groups                                              0.1
✗ MemoryDenyWriteExecute=                                     Service may create writable executable memory mappings                              0.1

→ Overall exposure level for zigbee2mqtt.service: 1.3 OK 🙂
2021-04-30 19:42:26 +02:00
..
taskserver
airsonic.nix airsonic: enable nginx.recommendedProxySettings with virtualHost 2020-02-28 19:38:58 +01:00
ankisyncd.nix nixos/ankisyncd: init at 2.1.0 2020-03-10 22:45:33 +01:00
apache-kafka.nix nixos/apache-kafka: Use version-matched jre 2021-03-10 08:10:30 +01:00
autofs.nix nixos/autofs: add timeout type 2021-01-24 13:17:07 +01:00
autorandr.nix nixos/modules: fix systemd start rate-limits 2020-10-31 01:35:56 -07:00
bazarr.nix nixos/users: require one of users.users.name.{isSystemUser,isNormalUser} 2021-04-14 20:40:00 +02:00
beanstalkd.nix nixos/beanstalkd: add openFirewall option 2020-09-01 10:07:28 -04:00
bees.nix
bepasty.nix
calibre-server.nix nixos/calibre-server: Allow multiple libraries 2020-09-17 12:04:39 +02:00
canto-daemon.nix
cfdyndns.nix nixos/cfdyndns: add apikeyFile option 2020-11-10 14:00:16 +01:00
cgminer.nix nixos/cgminer: add types 2021-01-26 12:24:48 +01:00
clipmenu.nix
confd.nix nixos/*: use $out instead of $bin with buildGoPackage 2020-04-28 20:30:29 +10:00
couchpotato.nix
cpuminer-cryptonight.nix
devmon.nix treewide: add bool type to enable options, or make use of mkEnableOption 2020-04-21 08:55:36 +02:00
dictd.nix treewide: fix double quoted strings in meta.description 2021-01-24 19:56:59 +07:00
disnix.nix Revert "nixos/dysnomia nixos/disnix: Drop modules" 2021-03-28 21:37:43 +02:00
docker-registry.nix nixos/docker-registry: always run systemctl of the currently running systemd 2020-05-21 10:29:37 +02:00
domoticz.nix nixos/domoticz: use DynamicUser and StateDirectory 2020-10-11 11:15:56 +01:00
duckling.nix init duckling service 2021-04-27 10:41:07 -07:00
dwm-status.nix
dysnomia.nix nixos/dysnomia: configure systemd unit path 2021-03-28 21:39:23 +02:00
errbot.nix
etcd.nix nixos/*: use $out instead of $bin with buildGoPackage 2020-04-28 20:30:29 +10:00
etebase-server.nix nixos/etebase-server: do not prompt for input during automatic upgrade 2021-04-16 13:08:42 +02:00
etesync-dav.nix nixos/etesync-dav: init module 2021-02-17 10:43:08 +01:00
ethminer.nix
exhibitor.nix treewide: fix double quoted strings in meta.description 2021-01-24 19:56:59 +07:00
felix.nix nixos/felix: add types 2021-01-27 11:44:59 -08:00
freeswitch.nix nixos/freeswitch: Unit improvements and add fs_cli 2020-06-05 20:16:43 +02:00
fstrim.nix utillinux: rename to util-linux 2020-11-24 12:42:06 -05:00
gammu-smsd.nix treewide: fix modules options types where the default is null 2020-04-28 19:13:59 +02:00
geoip-updater.nix
gitea.nix treewide: fix double quoted strings in meta.description 2021-01-24 19:56:59 +07:00
gitit.nix nixos: use functionTo to prevent evaluation errors while merging 2021-01-24 17:18:37 +01:00
gitlab.nix Merge pull request #118898 from talyz/gitlab-memory-bloat 2021-04-30 16:58:30 +02:00
gitlab.xml nixos/gitlab: Document automatic backups 2021-03-30 19:15:33 +02:00
gitolite.nix gitAndTools: move everything to the top level 2021-01-14 21:27:48 +00:00
gitweb.nix
gogs.nix gogs: 0.11.91 -> 0.12.3 2020-11-28 06:50:52 +01:00
gollum.nix gollum: Transfer maintainership to erictapen 2021-02-27 21:39:16 +01:00
gpsd.nix
greenclip.nix
headphones.nix
home-assistant.nix nixos/home-assistant: warn about overridePythonAttrs in package option 2021-04-17 02:20:07 +02:00
ihaskell.nix nixos: use functionTo to prevent evaluation errors while merging 2021-01-24 17:18:37 +01:00
irkerd.nix
jackett.nix
jellyfin.nix jellyfin_10_5: remove unmaintained version 2021-04-26 14:11:29 +02:00
klipper.nix nixos/klipper: init 2020-10-11 15:55:50 -07:00
leaps.nix nixos/*: use $out instead of $bin with buildGoPackage 2020-04-28 20:30:29 +10:00
lidarr.nix
lifecycled.nix nixos/lifecycled: init 2021-03-03 11:15:35 -08:00
logkeys.nix
mame.nix iproute: deprecate alias 2021-04-04 01:43:46 +02:00
matrix-appservice-discord.nix nixos/matrix-appservice-discord: update module for v1.0.0 2020-12-27 12:59:11 +01:00
matrix-appservice-irc.nix modules.matrix-appservice-irc: allow connecting to unix sockets 2021-04-20 15:48:50 +08:00
matrix-synapse-log_config.yaml
matrix-synapse.nix treewide: fix double quoted strings in meta.description 2021-01-24 19:56:59 +07:00
matrix-synapse.xml nixos/services/matrix-synapse: fix eval errors in manual example 2021-04-16 18:13:42 +02:00
mautrix-telegram.nix nixos/mautrix-telegram: substitute secrets in config file at runtime (#112966) 2021-03-13 13:56:17 +01:00
mbpfan.nix
mediatomb.nix nixos/mediatomb: fix doc errors 2020-10-08 16:04:11 +02:00
metabase.nix
mwlib.nix
n8n.nix nixos/n8n: init module and test 2020-12-05 11:02:40 +01:00
nix-daemon.nix nixos/users: require one of users.users.name.{isSystemUser,isNormalUser} 2021-04-14 20:40:00 +02:00
nix-gc.nix nixos/nix-gc: add persistent and randomizeDelaySec options 2021-02-28 04:21:21 -05:00
nix-optimise.nix
nix-ssh-serve.nix
novacomd.nix
nzbget.nix
nzbhydra2.nix nixos/nzbhydra2: init 2020-12-21 19:41:24 +01:00
octoprint.nix nixos: use functionTo to prevent evaluation errors while merging 2021-01-24 17:18:37 +01:00
ombi.nix nixos/ombi: set ombi as system user 2021-04-29 10:52:02 +03:00
osrm.nix
packagekit.nix nixos/packagekit: RFC42 support and drop pointless setting 2021-04-06 11:41:37 +08:00
paperless.nix
parsoid.nix nixos/parsoid: enable systemd sandboxing 2020-02-25 01:32:31 +01:00
pinnwand.nix nixos/pinnwand: init 2020-08-09 01:52:22 +02:00
plex.nix
plikd.nix nixos/plikd: Add new service module 2021-02-23 15:35:16 +01:00
podgrab.nix nixos/podgrab: add module 2021-04-15 20:57:21 +00:00
pykms.nix nixos/pykms: fix launcher 2021-02-03 15:59:17 +08:00
radarr.nix
redmine.nix treewide: unzip buldInputs to nativeBuildInputs (2) 2021-03-06 15:18:05 +07:00
ripple-data-api.nix
rippled.nix nixos/rippled: add extraConfig type 2021-01-31 12:10:14 +01:00
safeeyes.nix nixos/modules: fix systemd start rate-limits 2020-10-31 01:35:56 -07:00
serviio.nix
sickbeard.nix
siproxd.nix nixos/*: fix indentation 2020-11-23 08:42:51 +10:00
snapper.nix nixos/snapper: improve config example 2021-01-17 19:13:35 +11:00
sonarr.nix
spice-vdagentd.nix
ssm-agent.nix ssm-agent: fix bad user declaration 2020-10-07 09:36:21 +10:00
sssd.nix nixos/sssd: fix the module 2020-08-24 10:10:47 -04:00
subsonic.nix
sundtek.nix
svnserve.nix nixos/svnserve: add svnBaseDir type 2021-01-31 12:15:45 +01:00
synergy.nix nixos/synergy: add types 2021-01-31 12:17:41 +01:00
sysprof.nix
tautulli.nix
tiddlywiki.nix
tzupdate.nix nixos/modules: remove trailing whitespace 2020-08-07 14:45:39 +01:00
uhub.nix
weechat.nix nixos/weechat: add binary 2021-01-31 12:59:04 +01:00
weechat.xml
xmr-stak.nix
zigbee2mqtt.nix nixos/zigbee2mqtt: harden systemd unit 2021-04-30 19:42:26 +02:00
zoneminder.nix nixos/zoneminder: fix evaluation with php refactor 2020-05-17 13:42:42 -04:00
zookeeper.nix nixos/zookeeper: adapt to zookeeper 3.6.2 2020-12-09 15:46:38 +01:00