# Security (/docs/haus/rooms/security)



**Security** is the auth room: what you prove yourself to, what you are excused
from proving, and where this Mac's secrets come from.

## Enable it [#enable-it]

```nix
haus.security.touchId.enable = true;
haus.security.touchId.passwordlessRebuild = true;
```

Off in the foundation; hacker turns both on.

`enable` puts [`pam_reattach`](https://github.com/fabianishere/pam_reattach) in
front of `pam_tid`, so `sudo` prompts instead of beachballing inside tmux, or
inside the `zmx` session every haus terminal runs in. `sudo -v` is the check:
the dialog floats over the multiplexer, and cancelling it falls back to your
password.

`passwordlessRebuild` writes `/etc/sudoers.d/darwin-rebuild`, NOPASSWD for your
account on `/run/current-system/sw/bin/darwin-rebuild` and `haus-activate`, so
`haus rebuild` and `haus rollback` never stop for a fingerprint you already
gave. It is a real root grant, since anything you can build you can then
activate as root unprompted, so turn it off on a machine you don't administer
alone. The stable path is deliberate: sudo 1.9.17 (macOS 26.6) stopped
dereferencing symlinks before matching sudoers, so a `/nix/store/…` rule would
match only the literal path.

Key material never enters Nix: YubiKey, GPG and `pinentry` are `gpg-agent`'s at
runtime, and `haus.git.signingKey` wires up commit signing over in [the
Development room](/docs/haus/rooms/development).

## Secrets your rooms need [#secrets-your-rooms-need]

A room needing a value haus cannot invent declares it, so **the room asks, not
you**, and haus asks once for all of them:

```bash
haus-secret --list     # what's asked for, and where to get each
haus-secret --check    # enter what's missing
haus-secret --status   # which have a value (it prints no values)
```

Values land wherever `haus.secrets.provider` names: `"keyring"` (this Mac's
login keychain) by default, or `"onepassword"`, `"bws"`, `"gcsm"`, `"vault"` and
the rest secretspec takes. Never your config, a dotfile or the store. `haus
doctor` and `haus permissions` name the empty ones; turn a room off and its
secret stops being asked for.

<Callout title="Two lists of secrets, not one">
  A *project* keeps its own `secretspec.toml` beside its code, which
  [secretspec](https://secretspec.dev) finds under `secretspec run -- npm start`.
  The list above is the **machine's**, read only by `haus-secret`, in its own
  namespace, so the same name in both is two values. Point `haus.secrets.project`
  at a project you already use to share one namespace; it and
  `haus.secrets.provider` are host-only.
</Callout>

## The rest of the room [#the-rest-of-the-room]

Unset by default, so a fresh Mac keeps macOS's own answer:

```nix
haus.lock.requirePassword     = true;   # and .requirePasswordDelay
haus.security.firewall.enable = true;   # the built-in one, off on a fresh Mac
haus.security.guestAccount    = false;
haus.lock.login.showNameField = true;   # a name to type, not faces to shoulder-surf
haus.lock.login.message       = "If found, please call +1 555 0100.";
haus.lock.login.hideShutDown  = true;   # and .hideRestart, .hideSleep
```

**`guestAccount` is the one worth doing today.** Fresh Macs ship with Guest
**on**, handing whoever holds the machine a browser, your network and any file
share you are connected to, no password.

**Coming off `blockAllIncoming` can leave ssh refused.** The first ssh that
arrives while block-all is on can write a lasting "Block" entry for
`/usr/libexec/sshd-auth`, and with the firewall still on that entry turns
every new ssh away. While `firewall.enable` is true and `blockAllIncoming`
isn't, every rebuild clears that one entry.

`guestAccount` and every `haus.lock.login.*` key write to
`com.apple.loginwindow`, which macOS reads once at login: the rebuild writes
them, your next login shows them, and `haus plan` names them before you rebuild.

Deleting any of these lines stops managing that setting rather than restoring
what macOS had before it.

## Options [#options]

[Every setting, with types and
defaults](/docs/haus/reference/options#security).
