summaryrefslogtreecommitdiff
path: root/hosts/toaster/network
diff options
context:
space:
mode:
Diffstat (limited to 'hosts/toaster/network')
-rw-r--r--hosts/toaster/network/default.nix45
-rw-r--r--hosts/toaster/network/dumpdvb.nix38
-rw-r--r--hosts/toaster/network/full-networkd.nix71
-rw-r--r--hosts/toaster/network/mullvad.nix98
-rw-r--r--hosts/toaster/network/zw.nix61
5 files changed, 313 insertions, 0 deletions
diff --git a/hosts/toaster/network/default.nix b/hosts/toaster/network/default.nix
new file mode 100644
index 0000000..6504dbb
--- /dev/null
+++ b/hosts/toaster/network/default.nix
@@ -0,0 +1,45 @@
+{ lib, config, ... }:
+{
+ imports = [
+ ./mullvad.nix
+ ./dumpdvb.nix
+ ./zw.nix
+ ];
+
+ # Networkmanager shouldn't interfere with systemd managed interfaces
+ networking.networkmanager = {
+ enable = true;
+ unmanaged =
+ let
+ systemd_netdevs = lib.attrsets.attrValues (
+ lib.attrsets.mapAttrs (_name: value: value.netdevConfig.Name) config.systemd.network.netdevs
+ );
+ in
+ systemd_netdevs;
+ };
+
+ systemd.network = {
+ enable = true;
+ wait-online.enable = false; # uplink is managed by networkmanager
+ };
+
+ users.users."0xa".extraGroups = [ "networkmanager" ];
+
+ networking = {
+ hostName = "toaster";
+ firewall.enable = true;
+ wireguard.enable = true;
+ };
+
+ services.resolved = {
+ enable = true;
+ dnssec = "false";
+ fallbackDns = [
+ "9.9.9.9"
+ "2620:fe::fe"
+ "149.112.112.112"
+ "2620:fe::9"
+ ];
+ };
+
+}
diff --git a/hosts/toaster/network/dumpdvb.nix b/hosts/toaster/network/dumpdvb.nix
new file mode 100644
index 0000000..d3fba93
--- /dev/null
+++ b/hosts/toaster/network/dumpdvb.nix
@@ -0,0 +1,38 @@
+{ config, ... }:
+{
+ systemd.network = {
+ # Wireguard
+ # Dump-dvb
+ netdevs."30-wg-dumpdvb" = {
+ netdevConfig = {
+ Kind = "wireguard";
+ Name = "wg-dumpdvb";
+ Description = "dvb.solutions enterprise network";
+ };
+ wireguardConfig = {
+ PrivateKeyFile = config.sops.secrets."wg/dvb".path;
+ };
+ wireguardPeers = [
+ {
+ PublicKey = "WDvCObJ0WgCCZ0ORV2q4sdXblBd8pOPZBmeWr97yphY=";
+ Endpoint = "academicstrokes.com:51820";
+ AllowedIPs = [ "10.13.37.0/24" ];
+ PersistentKeepalive = 25;
+ }
+ ];
+ };
+ networks."30-wg-dumpdvb" = {
+ matchConfig.Name = "wg-dumpdvb";
+ networkConfig = {
+ Address = "10.13.37.3/24";
+ IPv6AcceptRA = true;
+ };
+ routes = [
+ {
+ Gateway = "10.13.37.1";
+ Destination = "10.13.37.0/24";
+ }
+ ];
+ };
+ };
+}
diff --git a/hosts/toaster/network/full-networkd.nix b/hosts/toaster/network/full-networkd.nix
new file mode 100644
index 0000000..ee0bdbe
--- /dev/null
+++ b/hosts/toaster/network/full-networkd.nix
@@ -0,0 +1,71 @@
+{ lib, pkgs, ... }:
+{
+ imports = [
+ ./mullvad.nix
+ ./dumpdvb.nix
+ ./zw.nix
+ ];
+
+ environment.systemPackages = with pkgs; [
+ iwgtk
+ impala
+ ];
+
+ # kick out networkmanager
+ networking.networkmanager.enable = lib.mkForce false;
+ networking.useNetworkd = true;
+ systemd.network.enable = true;
+
+ networking = {
+ hostName = "toaster";
+ firewall.enable = true;
+ wireguard.enable = true;
+ wireless.iwd.enable = true;
+ };
+
+ services.resolved = {
+ enable = true;
+ dnssec = "false";
+ fallbackDns = [
+ "9.9.9.9"
+ "2620:fe::fe"
+ "149.112.112.112"
+ "2620:fe::9"
+ ];
+ };
+
+ # we might have no interwebs at all
+ systemd.network.wait-online.enable = false;
+
+ # uplinks
+ systemd.network.networks = {
+ "10-ether-uplink" = {
+ matchConfig.Name = "enp1s0f0";
+ networkConfig = {
+ DHCP = "yes";
+ IPv6AcceptRA = true;
+ };
+ };
+ "10-dock-uplink" = {
+ matchConfig.Name = "enp5s0f4u1u1";
+ networkConfig = {
+ DHCP = "yes";
+ IPv6AcceptRA = true;
+ };
+ dhcpV4Config = {
+ RouteMetric = 666;
+ };
+ dhcpV6Config = {
+ RouteMetric = 666;
+ };
+ };
+ "wlan-uplink" = {
+ matchConfig.Name = "wlan0";
+ networkConfig = {
+ DHCP = "yes";
+ IPv6AcceptRA = true;
+ };
+ };
+ };
+
+}
diff --git a/hosts/toaster/network/mullvad.nix b/hosts/toaster/network/mullvad.nix
new file mode 100644
index 0000000..54fec8d
--- /dev/null
+++ b/hosts/toaster/network/mullvad.nix
@@ -0,0 +1,98 @@
+{
+ config,
+ ...
+}:
+{
+ systemd.network =
+ let
+ pubkey = "xpZ3ZDEukbqKQvdHwaqKMUhsYhcYD3uLPUh1ACsVr1s=";
+ endpoint = "185.65.134.86";
+ port = "51820";
+ addr = [
+ "10.74.16.48/32"
+ "fc00:bbbb:bbbb:bb01::b:102f/128"
+ ];
+ in
+ {
+ netdevs."10-wg-mullvad" = {
+ netdevConfig = {
+ Kind = "wireguard";
+ Name = "wg-mullvad";
+ };
+ wireguardConfig = {
+ PrivateKeyFile = config.sops.secrets."wg/mullvad".path;
+ FirewallMark = 34952; # 0x8888
+ RouteTable = "off";
+ };
+ wireguardPeers = [
+ {
+ PublicKey = pubkey;
+ Endpoint = "${endpoint}:${port}";
+ AllowedIPs = [
+ "0.0.0.0/0"
+ "::0/0"
+ ];
+ }
+ ];
+ };
+ networks."10-wg-mullvad" = {
+ matchConfig.Name = "wg-mullvad";
+ address = addr;
+ networkConfig = {
+ DNS = "10.64.0.1";
+ DNSDefaultRoute = true;
+ Domains = [ "~." ];
+ };
+ routes =
+ map
+ (gate: {
+ Gateway = gate;
+ Table = 1000;
+ })
+ [
+ "0.0.0.0"
+ "::"
+ ];
+
+ routingPolicyRules =
+ [
+ {
+ Family = "both";
+ FirewallMark = 34952; # 0x8888
+ InvertRule = true;
+ Table = "1000";
+ Priority = 100;
+ }
+ {
+ Family = "both";
+ SuppressPrefixLength = 0;
+ Table = "main";
+ Priority = 90;
+ }
+ ]
+ ++ map
+ (net: {
+ # only route global addresses over VPN
+ Priority = 80;
+ To = net;
+ })
+ [
+ # Mullvad endpoint
+ "${endpoint}/32"
+ # zw endpoint
+ "81.201.149.152/32"
+ # oxalab/oxa endpoint
+ "188.245.196.27/32"
+ # "10.0.0.0/8"
+ "10.13.37.0/24"
+ # 0xa-mgmt
+ "10.89.87.0/24"
+ # "172.16.0.0/12"
+ "172.16.0.0/12"
+ # "182.168.0.0/16"
+ "182.168.0.0/16"
+ # "fc00::/7"
+ ];
+ };
+ };
+}
diff --git a/hosts/toaster/network/zw.nix b/hosts/toaster/network/zw.nix
new file mode 100644
index 0000000..71e75be
--- /dev/null
+++ b/hosts/toaster/network/zw.nix
@@ -0,0 +1,61 @@
+{ config, ... }:
+{
+ # zentralwerk
+ systemd.network = {
+ netdevs."10-wg-zentralwerk" = {
+ netdevConfig = {
+ Kind = "wireguard";
+ Name = "wg-zentralwerk";
+ Description = "Tunnel to the best basement in Dresden";
+ };
+ wireguardConfig = {
+ PrivateKeyFile = config.sops.secrets."wg/zw".path;
+ RouteTable = "off";
+ };
+ wireguardPeers = [
+ {
+ PublicKey = "PG2VD0EB+Oi+U5/uVMUdO5MFzn59fAck6hz8GUyLMRo=";
+ Endpoint = "81.201.149.152:1337";
+ AllowedIPs = [
+ "172.20.72.0/21"
+ "172.22.90.0/24"
+ "172.22.99.0/24"
+ ];
+ PersistentKeepalive = 25;
+ }
+ ];
+ };
+ networks."10-wg-zentralwerk" = {
+ matchConfig.Name = "wg-zentralwerk";
+ networkConfig = {
+ Address = "172.20.76.226/21";
+ IPv6AcceptRA = true;
+ DNS = "172.20.73.8";
+ Domains = [
+ "~hq.c3d2.de"
+ "~serv.zentralwerk.org"
+ "~hq.zentralwerk.org"
+ "~cluster.zentralwerk.org"
+ ];
+ };
+ routes = [
+ {
+ Gateway = "172.20.76.225";
+ Destination = "172.20.72.0/21";
+ Metric = 1023;
+ }
+ {
+ Gateway = "172.20.76.225";
+ Destination = "172.20.90.0/24";
+ Metric = 1023;
+ }
+ {
+ Gateway = "172.20.76.225";
+ Destination = "172.22.99.0/24";
+ Metric = 1023;
+ }
+
+ ];
+ };
+ };
+}