{ config, pkgs, ... }:

{
  imports = [
    ../common
  ];

  services = {
    openssh = {
      enable = true;
      settings = {
        PasswordAuthentication = false;
      };
    };
  };

  security.sudo.wheelNeedsPassword = false;

  # For remote rebuilds with --target-host.
  nix.settings.trusted-users = ["@wheel"];
}