Take some ideas from NixOS/nixpkgs hardened kernel config