enable root SSH key-only login for deploy-rs

- Change PermitRootLogin from 'no' to 'prohibit-password' (key-only)
- Add forgejo-deploy public key to root's authorized_keys
- Revert deploy-rs user back to root (needs root for activation)

Root can only login via SSH key, password auth remains disabled.
This commit is contained in:
steffen 2026-03-14 14:13:26 +01:00
parent 3f07d27c78
commit 92abe2574d
3 changed files with 7 additions and 3 deletions

View file

@ -128,8 +128,7 @@
"2299"
];
profiles.system = {
user = "steffen";
sshUser = "steffen";
user = "root";
path = inputs.deploy-rs.lib.x86_64-linux.activate.nixos self.nixosConfigurations.cryodev-main;
};
};