diff options
| author | Collin Williams <96917990+bluedragon1221@users.noreply.github.com> | 2026-01-29 20:15:19 -0600 |
|---|---|---|
| committer | Collin Williams <96917990+bluedragon1221@users.noreply.github.com> | 2026-01-30 08:38:21 -0600 |
| commit | c9a1d2da80bca0a85e8c18f6d2db71c4d1127eda (patch) | |
| tree | 9da79e318ff0533a3708aee85a0b6a6d7f1d1036 /modules/system/nixos/networking/tailscale.nix | |
| parent | c81952cbcb6c6f1b41c2b6e2a366891991cceaee (diff) | |
Spring Cleaning
- create new module, `system`, that consumes the `boot` module and takes
in the more system-interested services from the `services` module
- touch up left over services (which are more self-hosting interested)
- touch up yo and yoshi configs
Diffstat (limited to 'modules/system/nixos/networking/tailscale.nix')
| -rw-r--r-- | modules/system/nixos/networking/tailscale.nix | 33 |
1 files changed, 33 insertions, 0 deletions
diff --git a/modules/system/nixos/networking/tailscale.nix b/modules/system/nixos/networking/tailscale.nix new file mode 100644 index 0000000..552ec8b --- /dev/null +++ b/modules/system/nixos/networking/tailscale.nix @@ -0,0 +1,33 @@ +{ + config, + pkgs, + lib, + ... +}: let + cfg = config.collinux.system.network.tailscale; +in + lib.mkIf cfg.enable { + services.tailscale = { + enable = true; + useRoutingFeatures = "both"; + }; + + networking.firewall = { + trustedInterfaces = ["tailscale0"]; + allowedUDPPorts = [config.services.tailscale.port]; + }; + + systemd.services."tailscaled" = + if config.collinux.services.selfhost.headscale.enable + then { + # don't start tailscale until after headscale starts + wants = lib.mkForce ["network.target" "headscale.target"]; + after = lib.mkForce ["network.target" "headscale.target"]; + } + else { + wants = lib.mkForce ["network.target"]; + after = lib.mkForce ["network.target"]; + }; + + environment.systemPackages = [pkgs.tailscale]; + } |
