{ ... }: { services.openssh = { enable = true; forwardX11 = true; permitRootLogin = "no"; startWhenNeeded = true; openFirewall = true; passwordAuthentication = false; }; nix.allowedUsers = [ "nix-ssh" ]; }