aboutsummaryrefslogtreecommitdiff
path: root/modules/wireguard
diff options
context:
space:
mode:
Diffstat (limited to 'modules/wireguard')
-rw-r--r--modules/wireguard/nixos/default.nix50
-rw-r--r--modules/wireguard/options.nix41
2 files changed, 0 insertions, 91 deletions
diff --git a/modules/wireguard/nixos/default.nix b/modules/wireguard/nixos/default.nix
deleted file mode 100644
index 9f05e43..0000000
--- a/modules/wireguard/nixos/default.nix
+++ /dev/null
@@ -1,50 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.collinux.wireguard;
-in
- lib.mkIf cfg.enable {
- networking.firewall.checkReversePath = "loose";
-
- networking.useNetworkd = true;
- systemd.network = {
- enable = true;
-
- netdevs."10-wg" = {
- netdevConfig = {
- Kind = "wireguard";
- Name = "wg0";
- };
-
- wireguardConfig = {
- PrivateKeyFile = cfg.privateKeyFile;
- ListenPort = 51820;
- };
-
- wireguardPeers =
- cfg.peers
- |> builtins.mapAttrs (_: m:
- {
- PublicKey = m.publicKey;
- AllowedIPs = [m.ip];
- PersistentKeepalive = 25;
- }
- // (lib.optionalAttrs (m.endpoint != null) {
- Endpoint = m.endpoint;
- }))
- |> builtins.attrValues;
- };
-
- networks."12-wireguard" = {
- name = "wg0";
-
- networkConfig = {
- Address = cfg.ip;
- DHCP = "no";
- Gateway = cfg.gateway;
- };
- };
- };
- }
diff --git a/modules/wireguard/options.nix b/modules/wireguard/options.nix
deleted file mode 100644
index c3c574f..0000000
--- a/modules/wireguard/options.nix
+++ /dev/null
@@ -1,41 +0,0 @@
-{lib, ...}: let
- inherit (lib) mkOption mkEnableOption;
-in {
- options = {
- collinux.wireguard = {
- enable = mkEnableOption "wireguard";
- ip = mkOption {
- type = lib.types.str;
- description = "host's ip address on the wireguard network (with cidr)";
- };
- gateway = mkOption {
- type = lib.types.str;
- description = "host's gateway";
- };
- privateKeyFile = mkOption {
- type = lib.types.str;
- description = "path to local private key file";
- example = "/run/secretd.d/wireguard-key";
- };
- peers = mkOption {
- type = lib.types.attrsOf (lib.types.submodule {
- options = {
- publicKey = mkOption {
- type = lib.types.str;
- description = "peer's public key";
- };
- ip = mkOption {
- type = lib.types.str;
- description = "peer's IP address";
- };
- endpoint = mkOption {
- type = lib.types.nullOr lib.types.str;
- description = "peer's endpoint";
- default = null;
- };
- };
- });
- };
- };
- };
-}