aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--flake.nix5
-rw-r--r--hosts.toml4
-rw-r--r--hosts/ganymede/config.nix16
-rw-r--r--hosts/ganymede/nixos.nix27
-rw-r--r--hosts/ganymede/wireguard-pk.age11
-rw-r--r--hosts/mercury/config.nix4
-rw-r--r--hosts/mercury/hjem.nix2
-rw-r--r--hosts/mercury/nixos.nix11
-rw-r--r--modules/system/nixos/networking/default.nix20
-rw-r--r--modules/system/nixos/networking/iwd.nix12
-rw-r--r--modules/system/nixos/networking/networkd.nix74
-rw-r--r--modules/system/nixos/networking/networkmanager.nix18
-rw-r--r--modules/system/nixos/networking/wpasupplicant.nix15
-rw-r--r--modules/system/options.nix56
-rw-r--r--modules/terminal/hjem/programs/git.nix17
-rw-r--r--secrets.nix1
16 files changed, 179 insertions, 114 deletions
diff --git a/flake.nix b/flake.nix
index 453ace8..5cb45aa 100644
--- a/flake.nix
+++ b/flake.nix
@@ -99,6 +99,11 @@
hostname = "ganymede";
username = "collin";
};
+ nixosConfigurations."gliese" = mkNixosSystem {
+ inherit inputs;
+ hostname = "gliese";
+ username = "green";
+ };
packages."x86_64-linux".docs = buildPkgs.callPackage genDocs {
inherit inputs;
diff --git a/hosts.toml b/hosts.toml
index 812d620..b249345 100644
--- a/hosts.toml
+++ b/hosts.toml
@@ -13,3 +13,7 @@ host_pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPB7feUHl5qoD5zF9AMOV2meViA+w
[hosts.io]
hostnames = ["io", "192.168.50.3"]
host_pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJXSvoVpMh/Y84THjKAYqkbuPmmv/yIU8DunMov7tKKT"
+
+[hosts.gliese]
+hostnames = ["gliese", "20.251.8.247"]
+host_pubkey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBRa7adrNY1CskUWepNexmh86a6Lei8xuVzTCyEwbsnY"
diff --git a/hosts/ganymede/config.nix b/hosts/ganymede/config.nix
index db684ae..3f8c6e4 100644
--- a/hosts/ganymede/config.nix
+++ b/hosts/ganymede/config.nix
@@ -18,6 +18,10 @@
file = ./collin-forgejo-password.age;
owner = "forgejo";
};
+ "wireguard-pk" = {
+ file = ./wireguard-pk.age;
+ owner = "root";
+ };
};
terminal = {
@@ -33,13 +37,11 @@
};
system.network = {
- networkd = {
- enable = true;
- static = {
- ip = "192.168.50.2/24";
- gateway = "192.168.50.1";
- };
-
+ static = {
+ ip = "192.168.50.2/24";
+ gateway = "192.168.50.1";
+ };
+ wireless.static = {
ssid = "williams";
pskFile = config.collinux.secrets."williams-psk".path;
};
diff --git a/hosts/ganymede/nixos.nix b/hosts/ganymede/nixos.nix
index be59083..8b5cbf4 100644
--- a/hosts/ganymede/nixos.nix
+++ b/hosts/ganymede/nixos.nix
@@ -30,6 +30,33 @@
wantedBy = ["default.target"];
};
+ # VPN to server
+ systemd.network = {
+ netdevs."10-wg0" = {
+ netdevConfig = {
+ Kind = "wireguard";
+ Name = "wg0";
+ };
+ wireguardConfig = {
+ PrivateKeyFile = config.collinux.secrets."wireguard-pk".path;
+ ListenPort = 51820;
+ };
+ wireguardPeers = [
+ {
+ PublicKey = "seOq75FUGb+KThvOXCEAGdabWbb+jTRUntITpuAPgWA=";
+ AllowedIPs = "0.0.0.0/0";
+ PersistentKeepalive = 25;
+ }
+ ];
+ };
+ networks."wg0" = {
+ matchConfig.Name = "wg0";
+ address = ["10.100.0.2/24"];
+ DHCP = "no";
+ networkConfig.IPv6AcceptRA = false;
+ };
+ };
+
services.fail2ban.enable = true;
# merge logs from subdomains
diff --git a/hosts/ganymede/wireguard-pk.age b/hosts/ganymede/wireguard-pk.age
new file mode 100644
index 0000000..c8e365a
--- /dev/null
+++ b/hosts/ganymede/wireguard-pk.age
@@ -0,0 +1,11 @@
+-----BEGIN AGE ENCRYPTED FILE-----
+YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IEpnNHlXUSBxZlFt
+bWR5NFJ1N0FBMkc2eThudnI1TnQ2WFNzK2NsVzdtaVgzQXRYNFhzCkJXTGUzSU5E
+U05jYnEvQXVwZEhIU1FMamt3bUM4UnB3bmNEZWQzZDlBSXcKLT4gc09lRVkkfTQt
+Z3JlYXNlIHMgSHYsVTZxOzgKWVJHbG1Ua3NONE9QYjVCNEQzOXQrNlZXRTBKQ3JW
+elpKeGwvYVgrOVVMRStrUGl0ay9HYmNOcW8xZFJER2tXWApPcUZxY2I5aDBoMVBO
+bmNxWE9YakZqL2h2dlFVYVdra0JrZjMKLS0tIGJWQlRmaVREL242aVdudFVOZTd4
+V1BnTnM3aTdGY1lUcm81VUVkd1QzcFUKMMrCSdf0J/xuvhvpktJO/GbpBp8ZnXue
+S0TTS/s3zCx8wCT70j/C6alX1CeMX+RpJwiba5BpvTuphGrgrMjMtA0oYDCRZzeQ
+1EtdX+A=
+-----END AGE ENCRYPTED FILE-----
diff --git a/hosts/mercury/config.nix b/hosts/mercury/config.nix
index abf38fb..cdf24d9 100644
--- a/hosts/mercury/config.nix
+++ b/hosts/mercury/config.nix
@@ -36,9 +36,9 @@
};
network = {
- iwd.enable = true;
- networkd.enable = true;
+ wireless.dynamic = true;
};
+
audio.enable = true;
bluetooth.enable = true;
};
diff --git a/hosts/mercury/hjem.nix b/hosts/mercury/hjem.nix
index b50dd6f..9e0ca77 100644
--- a/hosts/mercury/hjem.nix
+++ b/hosts/mercury/hjem.nix
@@ -33,7 +33,7 @@ in {
inputs.glide-browser.packages."x86_64-linux".default
inputs.vermilion.packages."x86_64-linux".default
- (pkgs.callPackage ../../pkgs/yoshi.nix {inherit inputs;})
+ # (pkgs.callPackage ../../pkgs/yoshi.nix {inherit inputs;})
(pkgs.callPackage ../../pkgs/yo.nix {inherit inputs;})
];
diff --git a/hosts/mercury/nixos.nix b/hosts/mercury/nixos.nix
index f820b7f..fee1a5e 100644
--- a/hosts/mercury/nixos.nix
+++ b/hosts/mercury/nixos.nix
@@ -53,9 +53,18 @@
];
programs.ssh.extraConfig = ''
- Host ganymede
+ Match host ganymede exec "nc -z -w1 192.168.50.2 2222"
HostName 192.168.50.2
Port 2222
+
+ Host ganymede
+ HostName williamsfam.us.com
+ Port 22
+
+ Host gliese
+ HostName 20.251.8.247
+ Port 22
+ IdentityFile ~/Gliese_key_2.pem
'';
programs.firefox.policies.ExtensionSettings = {
diff --git a/modules/system/nixos/networking/default.nix b/modules/system/nixos/networking/default.nix
index f063036..04cd1c3 100644
--- a/modules/system/nixos/networking/default.nix
+++ b/modules/system/nixos/networking/default.nix
@@ -1,14 +1,22 @@
{
imports = [
- ./iwd.nix
- ./networkmanager.nix
- ./networkd.nix
./resolved.nix
+
+ ./networkd.nix
+ ./iwd.nix
+ ./wpasupplicant.nix
];
- networking.firewall = {
- enable = true;
- checkReversePath = "loose";
+ networking = {
+ firewall = {
+ enable = true;
+ checkReversePath = "loose";
+ };
+
+ # Disable default networking stuff
+ dhcpcd.enable = false;
+ useDHCP = false;
+ networkmanager.enable = false;
};
# disable all ipv6
diff --git a/modules/system/nixos/networking/iwd.nix b/modules/system/nixos/networking/iwd.nix
index eea35d8..0c5bdfa 100644
--- a/modules/system/nixos/networking/iwd.nix
+++ b/modules/system/nixos/networking/iwd.nix
@@ -3,25 +3,21 @@
config,
...
}: let
- cfg = config.collinux.system.network.iwd;
+ cfg = config.collinux.system.network;
+ enabled = cfg.wireless.dynamic;
in
- lib.mkIf cfg.enable {
+ lib.mkIf enabled {
networking = {
wireless.iwd = {
enable = true;
settings = {
General = {
- EnableNetworkConfiguration = !config.collinux.system.network.networkd.enable;
+ EnableNetworkConfiguration = false; # always let networkd handle this
AddressRandomization = "once";
AddressRandomizationRange = "full";
};
Network.NameResolvingService = "systemd"; # either systemd or resolvconf
};
};
-
- # Disable default networking stuff
- dhcpcd.enable = false;
- useDHCP = false;
- networkmanager.enable = false;
};
}
diff --git a/modules/system/nixos/networking/networkd.nix b/modules/system/nixos/networking/networkd.nix
index d0e9eed..2c7f580 100644
--- a/modules/system/nixos/networking/networkd.nix
+++ b/modules/system/nixos/networking/networkd.nix
@@ -1,56 +1,44 @@
{
- lib,
+ # lib,
config,
...
}: let
- cfg = config.collinux.system.network.networkd;
-
+ cfg = config.collinux.system.network;
dhcp_enabled = cfg.static == null;
-in
- lib.mkIf cfg.enable {
- networking = {
- wireless =
- if !config.collinux.system.network.iwd.enable
- then {
- enable = true;
- networks.${cfg.ssid}.pskRaw = "ext:psk";
- secretsFile = cfg.pskFile;
- }
- else {};
-
- useNetworkd = true;
- # Disable default networking stuff
- dhcpcd.enable = false;
- useDHCP = false;
- networkmanager.enable = false;
- };
+ device =
+ if (cfg.wireless == null)
+ then "eth0"
+ else "wl*";
+in {
+ networking.useNetworkd = true;
+ systemd.network = {
+ enable = true;
- systemd.network = {
+ wait-online = {
enable = true;
+ ignoredInterfaces = ["docker0"];
+ anyInterface = true;
+ };
- wait-online = {
- enable = true;
- ignoredInterfaces = ["docker0"];
- anyInterface = true;
- };
-
- networks."11-lan" = {
- name = "wl*";
-
- networkConfig = (
- if dhcp_enabled
- then {DHCP = "yes";}
- else {
- Address = cfg.static.ip;
- Gateway = cfg.static.gateway;
- DHCP = "no";
- # DNS is managed by systemd-resolved (not specified here)
- }
- );
+ networks."11-default" =
+ if dhcp_enabled
+ then {
+ name = device;
+ networkConfig.DHCP = "yes";
+ # never accept dhcp dns
dhcpV4Config.UseDNS = "no";
dhcpV6Config.UseDNS = "no";
+ }
+ else {
+ name = device;
+ networkConfig = {
+ Address = cfg.static.ip;
+ Gateway = cfg.static.gateway;
+ DHCP = "no";
+ # DNS is managed by systemd-resolved (not specified here)
+ };
};
- };
- }
+ };
+}
diff --git a/modules/system/nixos/networking/networkmanager.nix b/modules/system/nixos/networking/networkmanager.nix
deleted file mode 100644
index c2d6dd1..0000000
--- a/modules/system/nixos/networking/networkmanager.nix
+++ /dev/null
@@ -1,18 +0,0 @@
-{
- lib,
- config,
- ...
-}: let
- cfg = config.collinux.system.network.networkmanager;
-in
- lib.mkIf cfg.enable {
- networking = {
- networkmanager = {
- enable = true;
- dns = "systemd-resolved";
- dhcp = "internal";
- };
-
- dhcpcd.enable = false;
- };
- }
diff --git a/modules/system/nixos/networking/wpasupplicant.nix b/modules/system/nixos/networking/wpasupplicant.nix
new file mode 100644
index 0000000..8314095
--- /dev/null
+++ b/modules/system/nixos/networking/wpasupplicant.nix
@@ -0,0 +1,15 @@
+{
+ config,
+ lib,
+ ...
+}: let
+ cfg = config.collinux.system.network.wireless;
+ enabled = cfg.static != null;
+in
+ lib.mkIf enabled {
+ networking.wireless = {
+ enable = true;
+ networks.${cfg.static.ssid}.pskRaw = "ext:psk";
+ secretsFile = cfg.static.pskFile;
+ };
+ }
diff --git a/modules/system/options.nix b/modules/system/options.nix
index 72d0392..d827387 100644
--- a/modules/system/options.nix
+++ b/modules/system/options.nix
@@ -27,36 +27,42 @@ in {
};
network = {
- iwd.enable = mkEnableOption "lightweight wifi daemon";
- networkmanager.enable = mkEnableOption "heavier wifi daemon";
- networkd = {
- enable = mkEnableOption "use systemd-networkd";
- ssid = mkOption {
- description = "SSID for this network";
- type = lib.types.str;
- };
- pskFile = mkOption {
- description = "Absolute path to a file containing the pre-shared key for this network in the form `psk:<wifi psk>`";
- type = lib.types.str;
- example = "/run/secrets.d/wifi-psk";
- };
+ static = lib.mkOption {
+ description = "Set a static IP address for this device on this network. Leave unset to use DHCP";
+ type = lib.types.nullOr (lib.types.submodule {
+ options = {
+ ip = mkOption {
+ description = "IP address";
+ type = ipAddrCidr;
+ };
+ gateway = mkOption {
+ description = "default gateway";
+ type = ipAddr;
+ };
+ };
+ });
+ default = null;
+ };
+ wireless = {
static = lib.mkOption {
- description = "Set a static IP address for this device on this network. Leave unset to use DHCP";
+ description = "Set a preconfigured SSID and PSK for the wireless config";
type = lib.types.nullOr (lib.types.submodule {
options = {
- ip = mkOption {
- description = "IP address";
- type = ipAddrCidr;
+ ssid = mkOption {
+ description = "SSID for this network";
+ type = lib.types.str;
};
- gateway = mkOption {
- description = "default gateway";
- type = ipAddr;
+ pskFile = mkOption {
+ description = "Absolute path to a file containing the pre-shared key for this network in the form `psk:<wifi psk>`";
+ type = lib.types.str;
+ example = "/run/secrets.d/wifi-psk";
};
};
});
default = null;
};
+ dynamic = lib.mkEnableOption "Enable dynamically joining wireless networks with iwd";
};
tailscale.enable = mkEnableOption "tailscale";
@@ -65,4 +71,14 @@ in {
audio.enable = mkEnableOption "pipewire and wireplumber";
bluetooth.enable = mkEnableOption "bluetooth";
};
+
+ config.assertions = [
+ {
+ assertion = let
+ cfg = config.collinux.system.network.wireless;
+ in
+ !(cfg.static != null && cfg.dynamic);
+ message = "Configure a static wireless connection or a dynamic one; not both.";
+ }
+ ];
}
diff --git a/modules/terminal/hjem/programs/git.nix b/modules/terminal/hjem/programs/git.nix
index 1c557bc..918381c 100644
--- a/modules/terminal/hjem/programs/git.nix
+++ b/modules/terminal/hjem/programs/git.nix
@@ -25,13 +25,14 @@
commit.gpgsign = "true";
})
];
-in {
- files = {
- ".config/git/config" = {
- generator = lib.generators.toGitINI;
- value = git_config;
+in
+ lib.mkIf cfg.enable {
+ files = {
+ ".config/git/config" = {
+ generator = lib.generators.toGitINI;
+ value = git_config;
+ };
};
- };
- packages = [pkgs.git];
-}
+ packages = [pkgs.git];
+ }
diff --git a/secrets.nix b/secrets.nix
index 6c90aa3..d8b2cad 100644
--- a/secrets.nix
+++ b/secrets.nix
@@ -7,4 +7,5 @@ in {
"hosts/ganymede/collin-copyparty-password.age".publicKeys = [mercury.host_pubkey ganymede.host_pubkey];
"hosts/ganymede/collin-forgejo-password.age".publicKeys = [mercury.host_pubkey ganymede.host_pubkey];
+ "hosts/ganymede/wireguard-pk.age".publicKeys = [ganymede.host_pubkey];
}