From 121e2f5004e109c5fc9530d136aae497061b8ef7 Mon Sep 17 00:00:00 2001 From: Grigory Shipunov Date: Sat, 18 Jun 2022 11:49:27 +0200 Subject: oxalab: init --- hosts/dishwasher/default.nix | 8 ++++++++ hosts/dishwasher/oxalab.nix | 32 ++++++++++++++++++++++++++++++++ hosts/dishwasher/secrets.nix | 9 +++++++++ 3 files changed, 49 insertions(+) create mode 100644 hosts/dishwasher/default.nix create mode 100644 hosts/dishwasher/oxalab.nix create mode 100644 hosts/dishwasher/secrets.nix (limited to 'hosts/dishwasher') diff --git a/hosts/dishwasher/default.nix b/hosts/dishwasher/default.nix new file mode 100644 index 0000000..c50e6cf --- /dev/null +++ b/hosts/dishwasher/default.nix @@ -0,0 +1,8 @@ +{ + imports = [ + ./configuration.nix + ./hardware-configuration.nix + ./secrets.nix + ./oxalab.nix + ]; +} diff --git a/hosts/dishwasher/oxalab.nix b/hosts/dishwasher/oxalab.nix new file mode 100644 index 0000000..b6521cf --- /dev/null +++ b/hosts/dishwasher/oxalab.nix @@ -0,0 +1,32 @@ +{ config, ... }: +{ + systemd.network = { + netdevs."oxalab" = { + netdevConfig = { + Kind = "wireguard"; + Name = "oxalab"; + Description = "oxa's enterprise network"; + }; + wireguardConfig = { + PrivateKeyFile = config.sops.secrets."wg/oxalab-seckey".path; + }; + wireguardPeers = [ + { + # cirrus + wireguardPeerConfig = { + PublicKey = "5nCVC21BL+1r70OGwA4Q6Z/gcPLC3+ZF8sTurdn7N0E="; + AllowedIPs = [ "10.66.66.0/24" ]; + Endpoint = [ "95.216.166.21:51820" ]; + PersistentKeepalive = 25; + }; + } + ]; + }; + networks."oxalab" = { + matchConfig.Name = "oxalab"; + networkConfig = { + Address = "10.13.37.100"; + }; + }; + }; +} diff --git a/hosts/dishwasher/secrets.nix b/hosts/dishwasher/secrets.nix new file mode 100644 index 0000000..679c511 --- /dev/null +++ b/hosts/dishwasher/secrets.nix @@ -0,0 +1,9 @@ +{ config, ... }: +{ + sops.defaultSopsFile = ../../secrets/dishwasher/secrets.yaml; + sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; + + sops.secrets = { + "wg/oxalab-seckey" = { }; + }; +} -- cgit v1.3.1