summaryrefslogtreecommitdiff
path: root/hosts/cirrus/wireguard-server.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hosts/cirrus/wireguard-server.nix')
-rw-r--r--hosts/cirrus/wireguard-server.nix43
1 files changed, 43 insertions, 0 deletions
diff --git a/hosts/cirrus/wireguard-server.nix b/hosts/cirrus/wireguard-server.nix
new file mode 100644
index 0000000..742912e
--- /dev/null
+++ b/hosts/cirrus/wireguard-server.nix
@@ -0,0 +1,43 @@
+{ config, ... }:
+{
+ systemd.network = {
+ netdevs."oxalab" = {
+ netdevConfig = {
+ Kind = "wireguard";
+ Name = "oxalab";
+ Description = "oxa's enterprise network";
+ };
+ wireguardConfig = {
+ PrivateKeyFile = config.sops.secrets."wg/oxalab-seckey".path;
+ ListenPort = 51820;
+ # own pubkey: 5nCVC21BL+1r70OGwA4Q6Z/gcPLC3+ZF8sTurdn7N0E=
+ };
+ wireguardPeers = [
+ {
+ # microwave
+ wireguardPeerConfig = {
+ # nextcloud down, have to keep things in here: https://www.youtube.com/watch?v=1c6v7j1TUBI
+ PublicKey = "0zpfcNrmbsNwwbnDDX4SMl4BVTB0zuhGKixT9TJQoHc=";
+ AllowedIPs = [ "10.66.66.10/32" ];
+ PersistentKeepalive = 25;
+ };
+ }
+ {
+ # Dishwasher
+ wireguardPeerConfig = {
+ # nextcloud down, have to keep things in here: https://www.youtube.com/watch?v=1c6v7j1TUBI
+ PublicKey = "xrremJFIcxwR6snoTUK+mytjez60I91XE120OQGQ7gc=";
+ AllowedIPs = [ "10.66.66.100/32" ];
+ PersistentKeepalive = 25;
+ };
+ }
+ ];
+ };
+ networks."oxalab" = {
+ matchConfig.Name = "oxalab";
+ networkConfig = {
+ Address = "10.13.37.1";
+ };
+ };
+ };
+}