diff options
| -rw-r--r-- | flake.nix | 5 | ||||
| -rw-r--r-- | hosts.toml | 4 | ||||
| -rw-r--r-- | hosts/ganymede/config.nix | 16 | ||||
| -rw-r--r-- | hosts/ganymede/nixos.nix | 27 | ||||
| -rw-r--r-- | hosts/ganymede/wireguard-pk.age | 11 | ||||
| -rw-r--r-- | hosts/mercury/config.nix | 4 | ||||
| -rw-r--r-- | hosts/mercury/hjem.nix | 2 | ||||
| -rw-r--r-- | hosts/mercury/nixos.nix | 11 | ||||
| -rw-r--r-- | modules/system/nixos/networking/default.nix | 20 | ||||
| -rw-r--r-- | modules/system/nixos/networking/iwd.nix | 12 | ||||
| -rw-r--r-- | modules/system/nixos/networking/networkd.nix | 74 | ||||
| -rw-r--r-- | modules/system/nixos/networking/networkmanager.nix | 18 | ||||
| -rw-r--r-- | modules/system/nixos/networking/wpasupplicant.nix | 15 | ||||
| -rw-r--r-- | modules/system/options.nix | 56 | ||||
| -rw-r--r-- | modules/terminal/hjem/programs/git.nix | 17 | ||||
| -rw-r--r-- | secrets.nix | 1 |
16 files changed, 179 insertions, 114 deletions
@@ -99,6 +99,11 @@ hostname = "ganymede"; username = "collin"; }; + nixosConfigurations."gliese" = mkNixosSystem { + inherit inputs; + hostname = "gliese"; + username = "green"; + }; packages."x86_64-linux".docs = buildPkgs.callPackage genDocs { inherit inputs; @@ -13,3 +13,7 @@ host_pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPB7feUHl5qoD5zF9AMOV2meViA+w [hosts.io] hostnames = ["io", "192.168.50.3"] host_pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJXSvoVpMh/Y84THjKAYqkbuPmmv/yIU8DunMov7tKKT" + +[hosts.gliese] +hostnames = ["gliese", "20.251.8.247"] +host_pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBRa7adrNY1CskUWepNexmh86a6Lei8xuVzTCyEwbsnY" diff --git a/hosts/ganymede/config.nix b/hosts/ganymede/config.nix index db684ae..3f8c6e4 100644 --- a/hosts/ganymede/config.nix +++ b/hosts/ganymede/config.nix @@ -18,6 +18,10 @@ file = ./collin-forgejo-password.age; owner = "forgejo"; }; + "wireguard-pk" = { + file = ./wireguard-pk.age; + owner = "root"; + }; }; terminal = { @@ -33,13 +37,11 @@ }; system.network = { - networkd = { - enable = true; - static = { - ip = "192.168.50.2/24"; - gateway = "192.168.50.1"; - }; - + static = { + ip = "192.168.50.2/24"; + gateway = "192.168.50.1"; + }; + wireless.static = { ssid = "williams"; pskFile = config.collinux.secrets."williams-psk".path; }; diff --git a/hosts/ganymede/nixos.nix b/hosts/ganymede/nixos.nix index be59083..8b5cbf4 100644 --- a/hosts/ganymede/nixos.nix +++ b/hosts/ganymede/nixos.nix @@ -30,6 +30,33 @@ wantedBy = ["default.target"]; }; + # VPN to server + systemd.network = { + netdevs."10-wg0" = { + netdevConfig = { + Kind = "wireguard"; + Name = "wg0"; + }; + wireguardConfig = { + PrivateKeyFile = config.collinux.secrets."wireguard-pk".path; + ListenPort = 51820; + }; + wireguardPeers = [ + { + PublicKey = "seOq75FUGb+KThvOXCEAGdabWbb+jTRUntITpuAPgWA="; + AllowedIPs = "0.0.0.0/0"; + PersistentKeepalive = 25; + } + ]; + }; + networks."wg0" = { + matchConfig.Name = "wg0"; + address = ["10.100.0.2/24"]; + DHCP = "no"; + networkConfig.IPv6AcceptRA = false; + }; + }; + services.fail2ban.enable = true; # merge logs from subdomains diff --git a/hosts/ganymede/wireguard-pk.age b/hosts/ganymede/wireguard-pk.age new file mode 100644 index 0000000..c8e365a --- /dev/null +++ b/hosts/ganymede/wireguard-pk.age @@ -0,0 +1,11 @@ +-----BEGIN AGE ENCRYPTED FILE----- +YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IEpnNHlXUSBxZlFt +bWR5NFJ1N0FBMkc2eThudnI1TnQ2WFNzK2NsVzdtaVgzQXRYNFhzCkJXTGUzSU5E +U05jYnEvQXVwZEhIU1FMamt3bUM4UnB3bmNEZWQzZDlBSXcKLT4gc09lRVkkfTQt +Z3JlYXNlIHMgSHYsVTZxOzgKWVJHbG1Ua3NONE9QYjVCNEQzOXQrNlZXRTBKQ3JW +elpKeGwvYVgrOVVMRStrUGl0ay9HYmNOcW8xZFJER2tXWApPcUZxY2I5aDBoMVBO +bmNxWE9YakZqL2h2dlFVYVdra0JrZjMKLS0tIGJWQlRmaVREL242aVdudFVOZTd4 +V1BnTnM3aTdGY1lUcm81VUVkd1QzcFUKMMrCSdf0J/xuvhvpktJO/GbpBp8ZnXue +S0TTS/s3zCx8wCT70j/C6alX1CeMX+RpJwiba5BpvTuphGrgrMjMtA0oYDCRZzeQ +1EtdX+A= +-----END AGE ENCRYPTED FILE----- diff --git a/hosts/mercury/config.nix b/hosts/mercury/config.nix index abf38fb..cdf24d9 100644 --- a/hosts/mercury/config.nix +++ b/hosts/mercury/config.nix @@ -36,9 +36,9 @@ }; network = { - iwd.enable = true; - networkd.enable = true; + wireless.dynamic = true; }; + audio.enable = true; bluetooth.enable = true; }; diff --git a/hosts/mercury/hjem.nix b/hosts/mercury/hjem.nix index b50dd6f..9e0ca77 100644 --- a/hosts/mercury/hjem.nix +++ b/hosts/mercury/hjem.nix @@ -33,7 +33,7 @@ in { inputs.glide-browser.packages."x86_64-linux".default inputs.vermilion.packages."x86_64-linux".default - (pkgs.callPackage ../../pkgs/yoshi.nix {inherit inputs;}) + # (pkgs.callPackage ../../pkgs/yoshi.nix {inherit inputs;}) (pkgs.callPackage ../../pkgs/yo.nix {inherit inputs;}) ]; diff --git a/hosts/mercury/nixos.nix b/hosts/mercury/nixos.nix index f820b7f..fee1a5e 100644 --- a/hosts/mercury/nixos.nix +++ b/hosts/mercury/nixos.nix @@ -53,9 +53,18 @@ ]; programs.ssh.extraConfig = '' - Host ganymede + Match host ganymede exec "nc -z -w1 192.168.50.2 2222" HostName 192.168.50.2 Port 2222 + + Host ganymede + HostName williamsfam.us.com + Port 22 + + Host gliese + HostName 20.251.8.247 + Port 22 + IdentityFile ~/Gliese_key_2.pem ''; programs.firefox.policies.ExtensionSettings = { diff --git a/modules/system/nixos/networking/default.nix b/modules/system/nixos/networking/default.nix index f063036..04cd1c3 100644 --- a/modules/system/nixos/networking/default.nix +++ b/modules/system/nixos/networking/default.nix @@ -1,14 +1,22 @@ { imports = [ - ./iwd.nix - ./networkmanager.nix - ./networkd.nix ./resolved.nix + + ./networkd.nix + ./iwd.nix + ./wpasupplicant.nix ]; - networking.firewall = { - enable = true; - checkReversePath = "loose"; + networking = { + firewall = { + enable = true; + checkReversePath = "loose"; + }; + + # Disable default networking stuff + dhcpcd.enable = false; + useDHCP = false; + networkmanager.enable = false; }; # disable all ipv6 diff --git a/modules/system/nixos/networking/iwd.nix b/modules/system/nixos/networking/iwd.nix index eea35d8..0c5bdfa 100644 --- a/modules/system/nixos/networking/iwd.nix +++ b/modules/system/nixos/networking/iwd.nix @@ -3,25 +3,21 @@ config, ... }: let - cfg = config.collinux.system.network.iwd; + cfg = config.collinux.system.network; + enabled = cfg.wireless.dynamic; in - lib.mkIf cfg.enable { + lib.mkIf enabled { networking = { wireless.iwd = { enable = true; settings = { General = { - EnableNetworkConfiguration = !config.collinux.system.network.networkd.enable; + EnableNetworkConfiguration = false; # always let networkd handle this AddressRandomization = "once"; AddressRandomizationRange = "full"; }; Network.NameResolvingService = "systemd"; # either systemd or resolvconf }; }; - - # Disable default networking stuff - dhcpcd.enable = false; - useDHCP = false; - networkmanager.enable = false; }; } diff --git a/modules/system/nixos/networking/networkd.nix b/modules/system/nixos/networking/networkd.nix index d0e9eed..2c7f580 100644 --- a/modules/system/nixos/networking/networkd.nix +++ b/modules/system/nixos/networking/networkd.nix @@ -1,56 +1,44 @@ { - lib, + # lib, config, ... }: let - cfg = config.collinux.system.network.networkd; - + cfg = config.collinux.system.network; dhcp_enabled = cfg.static == null; -in - lib.mkIf cfg.enable { - networking = { - wireless = - if !config.collinux.system.network.iwd.enable - then { - enable = true; - networks.${cfg.ssid}.pskRaw = "ext:psk"; - secretsFile = cfg.pskFile; - } - else {}; - - useNetworkd = true; - # Disable default networking stuff - dhcpcd.enable = false; - useDHCP = false; - networkmanager.enable = false; - }; + device = + if (cfg.wireless == null) + then "eth0" + else "wl*"; +in { + networking.useNetworkd = true; + systemd.network = { + enable = true; - systemd.network = { + wait-online = { enable = true; + ignoredInterfaces = ["docker0"]; + anyInterface = true; + }; - wait-online = { - enable = true; - ignoredInterfaces = ["docker0"]; - anyInterface = true; - }; - - networks."11-lan" = { - name = "wl*"; - - networkConfig = ( - if dhcp_enabled - then {DHCP = "yes";} - else { - Address = cfg.static.ip; - Gateway = cfg.static.gateway; - DHCP = "no"; - # DNS is managed by systemd-resolved (not specified here) - } - ); + networks."11-default" = + if dhcp_enabled + then { + name = device; + networkConfig.DHCP = "yes"; + # never accept dhcp dns dhcpV4Config.UseDNS = "no"; dhcpV6Config.UseDNS = "no"; + } + else { + name = device; + networkConfig = { + Address = cfg.static.ip; + Gateway = cfg.static.gateway; + DHCP = "no"; + # DNS is managed by systemd-resolved (not specified here) + }; }; - }; - } + }; +} diff --git a/modules/system/nixos/networking/networkmanager.nix b/modules/system/nixos/networking/networkmanager.nix deleted file mode 100644 index c2d6dd1..0000000 --- a/modules/system/nixos/networking/networkmanager.nix +++ /dev/null @@ -1,18 +0,0 @@ -{ - lib, - config, - ... -}: let - cfg = config.collinux.system.network.networkmanager; -in - lib.mkIf cfg.enable { - networking = { - networkmanager = { - enable = true; - dns = "systemd-resolved"; - dhcp = "internal"; - }; - - dhcpcd.enable = false; - }; - } diff --git a/modules/system/nixos/networking/wpasupplicant.nix b/modules/system/nixos/networking/wpasupplicant.nix new file mode 100644 index 0000000..8314095 --- /dev/null +++ b/modules/system/nixos/networking/wpasupplicant.nix @@ -0,0 +1,15 @@ +{ + config, + lib, + ... +}: let + cfg = config.collinux.system.network.wireless; + enabled = cfg.static != null; +in + lib.mkIf enabled { + networking.wireless = { + enable = true; + networks.${cfg.static.ssid}.pskRaw = "ext:psk"; + secretsFile = cfg.static.pskFile; + }; + } diff --git a/modules/system/options.nix b/modules/system/options.nix index 72d0392..d827387 100644 --- a/modules/system/options.nix +++ b/modules/system/options.nix @@ -27,36 +27,42 @@ in { }; network = { - iwd.enable = mkEnableOption "lightweight wifi daemon"; - networkmanager.enable = mkEnableOption "heavier wifi daemon"; - networkd = { - enable = mkEnableOption "use systemd-networkd"; - ssid = mkOption { - description = "SSID for this network"; - type = lib.types.str; - }; - pskFile = mkOption { - description = "Absolute path to a file containing the pre-shared key for this network in the form `psk:<wifi psk>`"; - type = lib.types.str; - example = "/run/secrets.d/wifi-psk"; - }; + static = lib.mkOption { + description = "Set a static IP address for this device on this network. Leave unset to use DHCP"; + type = lib.types.nullOr (lib.types.submodule { + options = { + ip = mkOption { + description = "IP address"; + type = ipAddrCidr; + }; + gateway = mkOption { + description = "default gateway"; + type = ipAddr; + }; + }; + }); + default = null; + }; + wireless = { static = lib.mkOption { - description = "Set a static IP address for this device on this network. Leave unset to use DHCP"; + description = "Set a preconfigured SSID and PSK for the wireless config"; type = lib.types.nullOr (lib.types.submodule { options = { - ip = mkOption { - description = "IP address"; - type = ipAddrCidr; + ssid = mkOption { + description = "SSID for this network"; + type = lib.types.str; }; - gateway = mkOption { - description = "default gateway"; - type = ipAddr; + pskFile = mkOption { + description = "Absolute path to a file containing the pre-shared key for this network in the form `psk:<wifi psk>`"; + type = lib.types.str; + example = "/run/secrets.d/wifi-psk"; }; }; }); default = null; }; + dynamic = lib.mkEnableOption "Enable dynamically joining wireless networks with iwd"; }; tailscale.enable = mkEnableOption "tailscale"; @@ -65,4 +71,14 @@ in { audio.enable = mkEnableOption "pipewire and wireplumber"; bluetooth.enable = mkEnableOption "bluetooth"; }; + + config.assertions = [ + { + assertion = let + cfg = config.collinux.system.network.wireless; + in + !(cfg.static != null && cfg.dynamic); + message = "Configure a static wireless connection or a dynamic one; not both."; + } + ]; } diff --git a/modules/terminal/hjem/programs/git.nix b/modules/terminal/hjem/programs/git.nix index 1c557bc..918381c 100644 --- a/modules/terminal/hjem/programs/git.nix +++ b/modules/terminal/hjem/programs/git.nix @@ -25,13 +25,14 @@ commit.gpgsign = "true"; }) ]; -in { - files = { - ".config/git/config" = { - generator = lib.generators.toGitINI; - value = git_config; +in + lib.mkIf cfg.enable { + files = { + ".config/git/config" = { + generator = lib.generators.toGitINI; + value = git_config; + }; }; - }; - packages = [pkgs.git]; -} + packages = [pkgs.git]; + } diff --git a/secrets.nix b/secrets.nix index 6c90aa3..d8b2cad 100644 --- a/secrets.nix +++ b/secrets.nix @@ -7,4 +7,5 @@ in { "hosts/ganymede/collin-copyparty-password.age".publicKeys = [mercury.host_pubkey ganymede.host_pubkey]; "hosts/ganymede/collin-forgejo-password.age".publicKeys = [mercury.host_pubkey ganymede.host_pubkey]; + "hosts/ganymede/wireguard-pk.age".publicKeys = [ganymede.host_pubkey]; } |
