From f35599a59a080f0e7a173e21cae3d51dc230a212 Mon Sep 17 00:00:00 2001 From: Grisha Shipunov Date: Fri, 15 Aug 2025 18:34:37 +0200 Subject: Revert "retire toaster" This reverts commit 1baa256be04a8b4e711a7d48a76197b5ffad6637. --- hosts/toaster/network/default.nix | 45 +++++++++++++++ hosts/toaster/network/dumpdvb.nix | 38 +++++++++++++ hosts/toaster/network/full-networkd.nix | 71 ++++++++++++++++++++++++ hosts/toaster/network/mullvad.nix | 98 +++++++++++++++++++++++++++++++++ hosts/toaster/network/zw.nix | 61 ++++++++++++++++++++ 5 files changed, 313 insertions(+) create mode 100644 hosts/toaster/network/default.nix create mode 100644 hosts/toaster/network/dumpdvb.nix create mode 100644 hosts/toaster/network/full-networkd.nix create mode 100644 hosts/toaster/network/mullvad.nix create mode 100644 hosts/toaster/network/zw.nix (limited to 'hosts/toaster/network') diff --git a/hosts/toaster/network/default.nix b/hosts/toaster/network/default.nix new file mode 100644 index 0000000..6504dbb --- /dev/null +++ b/hosts/toaster/network/default.nix @@ -0,0 +1,45 @@ +{ lib, config, ... }: +{ + imports = [ + ./mullvad.nix + ./dumpdvb.nix + ./zw.nix + ]; + + # Networkmanager shouldn't interfere with systemd managed interfaces + networking.networkmanager = { + enable = true; + unmanaged = + let + systemd_netdevs = lib.attrsets.attrValues ( + lib.attrsets.mapAttrs (_name: value: value.netdevConfig.Name) config.systemd.network.netdevs + ); + in + systemd_netdevs; + }; + + systemd.network = { + enable = true; + wait-online.enable = false; # uplink is managed by networkmanager + }; + + users.users."0xa".extraGroups = [ "networkmanager" ]; + + networking = { + hostName = "toaster"; + firewall.enable = true; + wireguard.enable = true; + }; + + services.resolved = { + enable = true; + dnssec = "false"; + fallbackDns = [ + "9.9.9.9" + "2620:fe::fe" + "149.112.112.112" + "2620:fe::9" + ]; + }; + +} diff --git a/hosts/toaster/network/dumpdvb.nix b/hosts/toaster/network/dumpdvb.nix new file mode 100644 index 0000000..d3fba93 --- /dev/null +++ b/hosts/toaster/network/dumpdvb.nix @@ -0,0 +1,38 @@ +{ config, ... }: +{ + systemd.network = { + # Wireguard + # Dump-dvb + netdevs."30-wg-dumpdvb" = { + netdevConfig = { + Kind = "wireguard"; + Name = "wg-dumpdvb"; + Description = "dvb.solutions enterprise network"; + }; + wireguardConfig = { + PrivateKeyFile = config.sops.secrets."wg/dvb".path; + }; + wireguardPeers = [ + { + PublicKey = "WDvCObJ0WgCCZ0ORV2q4sdXblBd8pOPZBmeWr97yphY="; + Endpoint = "academicstrokes.com:51820"; + AllowedIPs = [ "10.13.37.0/24" ]; + PersistentKeepalive = 25; + } + ]; + }; + networks."30-wg-dumpdvb" = { + matchConfig.Name = "wg-dumpdvb"; + networkConfig = { + Address = "10.13.37.3/24"; + IPv6AcceptRA = true; + }; + routes = [ + { + Gateway = "10.13.37.1"; + Destination = "10.13.37.0/24"; + } + ]; + }; + }; +} diff --git a/hosts/toaster/network/full-networkd.nix b/hosts/toaster/network/full-networkd.nix new file mode 100644 index 0000000..ee0bdbe --- /dev/null +++ b/hosts/toaster/network/full-networkd.nix @@ -0,0 +1,71 @@ +{ lib, pkgs, ... }: +{ + imports = [ + ./mullvad.nix + ./dumpdvb.nix + ./zw.nix + ]; + + environment.systemPackages = with pkgs; [ + iwgtk + impala + ]; + + # kick out networkmanager + networking.networkmanager.enable = lib.mkForce false; + networking.useNetworkd = true; + systemd.network.enable = true; + + networking = { + hostName = "toaster"; + firewall.enable = true; + wireguard.enable = true; + wireless.iwd.enable = true; + }; + + services.resolved = { + enable = true; + dnssec = "false"; + fallbackDns = [ + "9.9.9.9" + "2620:fe::fe" + "149.112.112.112" + "2620:fe::9" + ]; + }; + + # we might have no interwebs at all + systemd.network.wait-online.enable = false; + + # uplinks + systemd.network.networks = { + "10-ether-uplink" = { + matchConfig.Name = "enp1s0f0"; + networkConfig = { + DHCP = "yes"; + IPv6AcceptRA = true; + }; + }; + "10-dock-uplink" = { + matchConfig.Name = "enp5s0f4u1u1"; + networkConfig = { + DHCP = "yes"; + IPv6AcceptRA = true; + }; + dhcpV4Config = { + RouteMetric = 666; + }; + dhcpV6Config = { + RouteMetric = 666; + }; + }; + "wlan-uplink" = { + matchConfig.Name = "wlan0"; + networkConfig = { + DHCP = "yes"; + IPv6AcceptRA = true; + }; + }; + }; + +} diff --git a/hosts/toaster/network/mullvad.nix b/hosts/toaster/network/mullvad.nix new file mode 100644 index 0000000..54fec8d --- /dev/null +++ b/hosts/toaster/network/mullvad.nix @@ -0,0 +1,98 @@ +{ + config, + ... +}: +{ + systemd.network = + let + pubkey = "xpZ3ZDEukbqKQvdHwaqKMUhsYhcYD3uLPUh1ACsVr1s="; + endpoint = "185.65.134.86"; + port = "51820"; + addr = [ + "10.74.16.48/32" + "fc00:bbbb:bbbb:bb01::b:102f/128" + ]; + in + { + netdevs."10-wg-mullvad" = { + netdevConfig = { + Kind = "wireguard"; + Name = "wg-mullvad"; + }; + wireguardConfig = { + PrivateKeyFile = config.sops.secrets."wg/mullvad".path; + FirewallMark = 34952; # 0x8888 + RouteTable = "off"; + }; + wireguardPeers = [ + { + PublicKey = pubkey; + Endpoint = "${endpoint}:${port}"; + AllowedIPs = [ + "0.0.0.0/0" + "::0/0" + ]; + } + ]; + }; + networks."10-wg-mullvad" = { + matchConfig.Name = "wg-mullvad"; + address = addr; + networkConfig = { + DNS = "10.64.0.1"; + DNSDefaultRoute = true; + Domains = [ "~." ]; + }; + routes = + map + (gate: { + Gateway = gate; + Table = 1000; + }) + [ + "0.0.0.0" + "::" + ]; + + routingPolicyRules = + [ + { + Family = "both"; + FirewallMark = 34952; # 0x8888 + InvertRule = true; + Table = "1000"; + Priority = 100; + } + { + Family = "both"; + SuppressPrefixLength = 0; + Table = "main"; + Priority = 90; + } + ] + ++ map + (net: { + # only route global addresses over VPN + Priority = 80; + To = net; + }) + [ + # Mullvad endpoint + "${endpoint}/32" + # zw endpoint + "81.201.149.152/32" + # oxalab/oxa endpoint + "188.245.196.27/32" + # "10.0.0.0/8" + "10.13.37.0/24" + # 0xa-mgmt + "10.89.87.0/24" + # "172.16.0.0/12" + "172.16.0.0/12" + # "182.168.0.0/16" + "182.168.0.0/16" + # "fc00::/7" + ]; + }; + }; +} diff --git a/hosts/toaster/network/zw.nix b/hosts/toaster/network/zw.nix new file mode 100644 index 0000000..71e75be --- /dev/null +++ b/hosts/toaster/network/zw.nix @@ -0,0 +1,61 @@ +{ config, ... }: +{ + # zentralwerk + systemd.network = { + netdevs."10-wg-zentralwerk" = { + netdevConfig = { + Kind = "wireguard"; + Name = "wg-zentralwerk"; + Description = "Tunnel to the best basement in Dresden"; + }; + wireguardConfig = { + PrivateKeyFile = config.sops.secrets."wg/zw".path; + RouteTable = "off"; + }; + wireguardPeers = [ + { + PublicKey = "PG2VD0EB+Oi+U5/uVMUdO5MFzn59fAck6hz8GUyLMRo="; + Endpoint = "81.201.149.152:1337"; + AllowedIPs = [ + "172.20.72.0/21" + "172.22.90.0/24" + "172.22.99.0/24" + ]; + PersistentKeepalive = 25; + } + ]; + }; + networks."10-wg-zentralwerk" = { + matchConfig.Name = "wg-zentralwerk"; + networkConfig = { + Address = "172.20.76.226/21"; + IPv6AcceptRA = true; + DNS = "172.20.73.8"; + Domains = [ + "~hq.c3d2.de" + "~serv.zentralwerk.org" + "~hq.zentralwerk.org" + "~cluster.zentralwerk.org" + ]; + }; + routes = [ + { + Gateway = "172.20.76.225"; + Destination = "172.20.72.0/21"; + Metric = 1023; + } + { + Gateway = "172.20.76.225"; + Destination = "172.20.90.0/24"; + Metric = 1023; + } + { + Gateway = "172.20.76.225"; + Destination = "172.22.99.0/24"; + Metric = 1023; + } + + ]; + }; + }; +} -- cgit v1.3.1