aboutsummaryrefslogtreecommitdiff
path: root/modules/system/nixos/networking/tailscale.nix
diff options
context:
space:
mode:
authorCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-01-29 20:15:19 -0600
committerCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-01-30 08:38:21 -0600
commitc9a1d2da80bca0a85e8c18f6d2db71c4d1127eda (patch)
tree9da79e318ff0533a3708aee85a0b6a6d7f1d1036 /modules/system/nixos/networking/tailscale.nix
parentc81952cbcb6c6f1b41c2b6e2a366891991cceaee (diff)
Spring Cleaning
- create new module, `system`, that consumes the `boot` module and takes in the more system-interested services from the `services` module - touch up left over services (which are more self-hosting interested) - touch up yo and yoshi configs
Diffstat (limited to 'modules/system/nixos/networking/tailscale.nix')
-rw-r--r--modules/system/nixos/networking/tailscale.nix33
1 files changed, 33 insertions, 0 deletions
diff --git a/modules/system/nixos/networking/tailscale.nix b/modules/system/nixos/networking/tailscale.nix
new file mode 100644
index 0000000..552ec8b
--- /dev/null
+++ b/modules/system/nixos/networking/tailscale.nix
@@ -0,0 +1,33 @@
+{
+ config,
+ pkgs,
+ lib,
+ ...
+}: let
+ cfg = config.collinux.system.network.tailscale;
+in
+ lib.mkIf cfg.enable {
+ services.tailscale = {
+ enable = true;
+ useRoutingFeatures = "both";
+ };
+
+ networking.firewall = {
+ trustedInterfaces = ["tailscale0"];
+ allowedUDPPorts = [config.services.tailscale.port];
+ };
+
+ systemd.services."tailscaled" =
+ if config.collinux.services.selfhost.headscale.enable
+ then {
+ # don't start tailscale until after headscale starts
+ wants = lib.mkForce ["network.target" "headscale.target"];
+ after = lib.mkForce ["network.target" "headscale.target"];
+ }
+ else {
+ wants = lib.mkForce ["network.target"];
+ after = lib.mkForce ["network.target"];
+ };
+
+ environment.systemPackages = [pkgs.tailscale];
+ }