diff options
| author | Grisha Shipunov | 2025-08-29 13:15:13 +0200 |
|---|---|---|
| committer | Grisha Shipunov | 2025-08-29 13:15:13 +0200 |
| commit | faf1e32c8a6bdaf5616f075fcca1e2ee121cebe2 (patch) | |
| tree | b24b09c9488845ea7066d28b164bc0020459f44a /modules | |
| parent | 02cbd04bf63976db64891a2712210f9644a14a75 (diff) | |
allow null private key for non-flake clients
Diffstat (limited to 'modules')
| -rw-r--r-- | modules/wg/module.nix | 8 | ||||
| -rw-r--r-- | modules/wg/options.nix | 4 |
2 files changed, 9 insertions, 3 deletions
diff --git a/modules/wg/module.nix b/modules/wg/module.nix index 53ed2bb..45a9335 100644 --- a/modules/wg/module.nix +++ b/modules/wg/module.nix @@ -50,7 +50,9 @@ Kind = "wireguard"; Name = "wg-${net.networkName}"; }; - wireguardConfig.PrivateKeyFile = net.hosts.${currenthost}.privateKeyFile; + wireguardConfig.PrivateKeyFile = + assert !(isNull net.hosts.${currenthost}.privateKeyFile); + net.hosts.${currenthost}.privateKeyFile; # for client this is only endpoint for now wireguardPeers = let @@ -88,7 +90,9 @@ Kind = "wireguard"; Name = "wg-${net.networkName}"; }; - wireguardConfig.PrivateKeyFile = net.hosts.${currenthost}.privateKeyFile; + wireguardConfig.PrivateKeyFile = + assert !(isNull net.hosts.${currenthost}.privateKeyFile); + net.hosts.${currenthost}.privateKeyFile; wireguardConfig.ListenPort = net.hosts.${currenthost}.endpoint.port; wireguardPeers = let diff --git a/modules/wg/options.nix b/modules/wg/options.nix index d4e8567..c5ed665 100644 --- a/modules/wg/options.nix +++ b/modules/wg/options.nix @@ -39,7 +39,9 @@ default = null; }; privateKeyFile = mkOption { - type = types.path; + # nullOr because non-flake hosts don't need a private key in this repo + # assert in the module checks for the key presence on flake hosts + type = types.nullOr types.path; default = null; }; |
