{ pkgs, config, ... }: { config = { services.openssh.enable = true; services.avahi = { enable = true; nssmdns4 = true; }; environment.systemPackages = with pkgs; [ home-manager bash busybox git eza sops ]; security.sudo-rs = { enable = true; execWheelOnly = false; wheelNeedsPassword = false; # allows sudo without password for those in the wheel group }; }; }