summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGregor Kleen <gkleen@yggdrasil.li>2021-09-29 21:55:16 +0200
committerGregor Kleen <gkleen@yggdrasil.li>2021-09-29 21:55:16 +0200
commiteebfe0864f92f5c390ed0e4a6959cb69f7f7f40e (patch)
treec2c49e061886108ec146f431daed73c47e0cca4f
parent05438304665bdaaf37ba4c148ab07bdf8fd3fb03 (diff)
downloadnixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.tar
nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.tar.gz
nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.tar.bz2
nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.tar.xz
nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.zip
yggdrasil-wg: init
-rw-r--r--modules/yggdrasil-wg/default.nix69
-rw-r--r--modules/yggdrasil-wg/hosts/surtr.priv26
-rw-r--r--modules/yggdrasil-wg/hosts/surtr.pub1
-rw-r--r--modules/yggdrasil-wg/hosts/vidhar.priv26
-rw-r--r--modules/yggdrasil-wg/hosts/vidhar.pub1
-rw-r--r--shell.nix1
6 files changed, 124 insertions, 0 deletions
diff --git a/modules/yggdrasil-wg/default.nix b/modules/yggdrasil-wg/default.nix
new file mode 100644
index 00000000..08665e33
--- /dev/null
+++ b/modules/yggdrasil-wg/default.nix
@@ -0,0 +1,69 @@
1{ config, hostName, lib, ... }:
2
3with lib;
4
5let
6 listenPort = 51820;
7 subnet = "2a03:4000:52:ada:1";
8
9 links = [
10 { from = "vidhar";
11 to = "surtr";
12 endpointHost = "surtr.yggdrasil.li";
13 persistentKeepalive = 25;
14 dynamicEndpointRefreshSeconds = 86400;
15 }
16 ];
17 hostIPs = {
18 surtr = ["${subnet}::/32"];
19 vidhar = ["${subnet}:1::/32"];
20 };
21
22 mkPublicKeyPath = host: ./hosts + "/${host}.pub";
23 mkPrivateKeyPath = host: ./hosts + "/${host}.priv";
24
25 publicKeyPath = mkPublicKeyPath hostName;
26 privateKeyPath = mkPrivateKeyPath hostName;
27 inNetwork = pathExists privateKeyPath && pathExists publicKeyPath;
28 hostLinks = filter ({ from, to, ... }: from == hostName || to == hostName) links;
29 linkToPeer = opts@{from, to, ...}:
30 let
31 other = if from == hostName then to else from;
32 in {
33 allowedIPs = hostIPs.${other};
34 publicKey = trim (readFile (mkPublicKeyPath other));
35 } // (optionalAttrs (from == hostName) (filterAttrs (n: _v: !(elem n ["from" "to" "endpointHost"])) opts // optionalAttrs (opts ? "endpointHost") { endpoint = "${opts.endpointHost}:${toString listenPort}"; }));
36
37 trim = str: if hasSuffix "\n" str then trim (removeSuffix "\n" str) else str;
38 stripSubnet = addr: let matchRes = builtins.match "^(.*)/[0-9]+$" addr; in if matchRes == null then addr else elemAt matchRes 0;
39in {
40 config = {
41 assertions = [
42 { assertion = inNetwork || !(pathExists privateKeyPath || pathExists publicKeyPath);
43 message = "yggdrasil-wg: Either both public and private keys must exist or neither.";
44 }
45 { assertion = !inNetwork || (hostIPs ? "${hostName}");
46 message = "yggdrasil-wg: Entry in hostIPs must exist.";
47 }
48 ] ++ map ({from, to, ...}: let other = if from == hostName then to else from; in { assertion = pathExists (mkPublicKeyPath other); message = "yggdrasil-wg: This host (${hostName}) has a link with ‘${other}’, but no public key is available for ‘${other}’."; }) hostLinks;
49
50 networking.wireguard.interfaces = mkIf inNetwork {
51 yggdrasil = {
52 allowedIPsAsRoutes = true;
53 inherit listenPort;
54 ips = hostIPs.${hostName};
55 peers = map linkToPeer hostLinks;
56 privateKeyFile = config.sops.secrets."yggdrasil-wg.priv".path;
57 };
58 };
59
60 sops.secrets = mkIf (pathExists privateKeyPath) {
61 "yggdrasil-wg.priv" = {
62 format = "binary";
63 sopsFile = privateKeyPath;
64 };
65 };
66
67 networking.hosts = mkIf inNetwork (listToAttrs (concatMap ({name, value}: map (ip: nameValuePair (stripSubnet ip) ["${name}.yggdrasil"]) value) (mapAttrsToList nameValuePair hostIPs)));
68 };
69}
diff --git a/modules/yggdrasil-wg/hosts/surtr.priv b/modules/yggdrasil-wg/hosts/surtr.priv
new file mode 100644
index 00000000..b5d107f5
--- /dev/null
+++ b/modules/yggdrasil-wg/hosts/surtr.priv
@@ -0,0 +1,26 @@
1{
2 "data": "ENC[AES256_GCM,data:TbEkDgs1y71JYTfmF8wXtPDtkFlhYRnpOPIVQPV+u5Se9D7l5TT6r7CFP/FP,iv:OjktMWZhKYIklsKTdj3cViXcO6LcnGSsDllZatof4hg=,tag:oHoSbCPEcQWkAu7mhSOUiA==,type:str]",
3 "sops": {
4 "kms": null,
5 "gcp_kms": null,
6 "azure_kv": null,
7 "hc_vault": null,
8 "age": null,
9 "lastmodified": "2021-09-29T19:10:07Z",
10 "mac": "ENC[AES256_GCM,data:/hFdwXsAxrt3SCU0rbPPeBZ6mBsWcGkN3IMcOP3c28Df452/H0FM67/54NXwSErubnfIY4RXyGfj1dgLBV3A3r43E/F3uN4K8Qt1Ms+dJJdMjKiYpsOuCMgLe27yvI6LtUu0ePPJAPu+me1dOMSdvlQAMwNByrtKmLceMFVJ7gw=,iv:UauO61EBRWvVxYU2vlMI8nqIWw+KO1lEVIc82vVs4ZA=,tag:BzYnM9XcefVd/2T0JcMM2A==,type:str]",
11 "pgp": [
12 {
13 "created_at": "2021-09-29T19:10:06Z",
14 "enc": "-----BEGIN PGP MESSAGE-----\n\nhF4DXxoViZlp6dISAQdAoHdrbuBJjuTnrUDbeAf7aeb6Kz6HbLuLiHZmSt/rSlow\nfgcSqsdYKMdSFeemRzAw++dBuIeduye31GGNDpsZUYyK9r90x0PJaFL3AABudAsj\n0l4Bm1YyqMDv/gzZeK87QDGpYZPu7+dkSrYO1sRe1qHrdI0L1WUs38l0eQM1qSUR\n4Gv4JBXNipoVTH8cfcGRvAy9y2+deEdzDtNK8rqLaQrc+q2TdV8Qlngp/EZqsQef\n=PM7q\n-----END PGP MESSAGE-----\n",
15 "fp": "30D3453B8CD02FE2A3E7C78C0FB536FB87AE8F51"
16 },
17 {
18 "created_at": "2021-09-29T19:10:06Z",
19 "enc": "-----BEGIN PGP MESSAGE-----\n\nhF4DyFKFNkTVG5oSAQdAIQL7kGdUkG3CgEyRFdayydeTJGxjD4epYvaQBl4L0g4w\npKoTQuDf8FD3HeFI6ZO/jaE0BFX9Ifd3TYINK/XtqePOkYteos8aqJ/83t35aCIa\n0l4Bq2wt9BRR1pOQzJxnu8Dn9BsnOAQTp8JpwX5fY/FuPXTP8SV2XwWuHKnRd0j/\np7cSOUrog9agk9pc8tjwR+M451xN5AOpqdbqLkuNhi1b6QuxvI+sGsdh3sMz0UBs\n=5ozm\n-----END PGP MESSAGE-----\n",
20 "fp": "7ED22F4AA7BB55728B643DC5471B7D88E4EF66F8"
21 }
22 ],
23 "unencrypted_suffix": "_unencrypted",
24 "version": "3.7.1"
25 }
26} \ No newline at end of file
diff --git a/modules/yggdrasil-wg/hosts/surtr.pub b/modules/yggdrasil-wg/hosts/surtr.pub
new file mode 100644
index 00000000..abe753eb
--- /dev/null
+++ b/modules/yggdrasil-wg/hosts/surtr.pub
@@ -0,0 +1 @@
YP/sWEUWw51czlGxvgrgyEZ+ssx/3C9siufgd0a8d3g=
diff --git a/modules/yggdrasil-wg/hosts/vidhar.priv b/modules/yggdrasil-wg/hosts/vidhar.priv
new file mode 100644
index 00000000..c5b2ea99
--- /dev/null
+++ b/modules/yggdrasil-wg/hosts/vidhar.priv
@@ -0,0 +1,26 @@
1{
2 "data": "ENC[AES256_GCM,data:5RT5TQsBBZY5c4yRpDTYL+M3zLIzYSLST8L31ZmwlQdZs7saXwfehnHo5j0o,iv:/3QrjBfLqQ//ySv9TdTV7jGIzFkR+ZPBi0KJBAkxH+Y=,tag:kwx+Uln6AFBxkv7EE2jFgg==,type:str]",
3 "sops": {
4 "kms": null,
5 "gcp_kms": null,
6 "azure_kv": null,
7 "hc_vault": null,
8 "age": null,
9 "lastmodified": "2021-09-29T19:10:37Z",
10 "mac": "ENC[AES256_GCM,data:iglf4GccydO5//TZbw2TWndqeIuZz3G1k7blAW1fNgoxdEDGN16NtsH+/iduQj27BsFhRdPXLO9JWmpeOjwzUMnmkuEOhmALYMZGaZRBzO/x6k5EICFacm6lGUHDm307hexzWtIpNaViuZJiWVlT4IDi5k3N2QaUCYp02AqzPeU=,iv:c5RCIl4zLxrWewc37QIwKIyK5lrBWwSe7Me/yP3UCoU=,tag:LfjGnveOB/lMGhOYk3Ev3A==,type:str]",
11 "pgp": [
12 {
13 "created_at": "2021-09-29T19:10:37Z",
14 "enc": "-----BEGIN PGP MESSAGE-----\n\nhF4DXxoViZlp6dISAQdA0wHAgvPYDG0FBH2rql1gX37YtzsK1K/AUNSarn71dAQw\nJ6FEldRQ6M+hN41ooX9DSebEtumtiLNQHnvShICw8ULFhrsgyGdUkZAb9eJ9pHnO\n0l4BDS9/MbcTpsZWW+LfFPAZCGsVi1eF5abQKDFDt5RMvxERefIR7jHd6vmjDKgy\nrESOG1nGFsvLnU5/OKJtSmWKDsnMh4ohJ1Agojh4YeVRUnFkM0vdihdZnEAlMz6E\n=DO1o\n-----END PGP MESSAGE-----\n",
15 "fp": "30D3453B8CD02FE2A3E7C78C0FB536FB87AE8F51"
16 },
17 {
18 "created_at": "2021-09-29T19:10:37Z",
19 "enc": "-----BEGIN PGP MESSAGE-----\n\nhF4DbYDvGI0HDr0SAQdAJ09HBaaPhDdTOfpzVxuhtzG7s5ZjVrpZWmKKeO23bGYw\n2ctQ4YdNJt5Wv0AhgA0XVZK06rHtBV18utaeXhP7DYZID+wyMUkO7UR4/hhEGmb9\n0l4BzTxnL9liRwH5zB9r7erJYcDOUixtqtriRaoHUM2hDemprMqg+GoBj/Js7V52\nOKCiNGx5uDZ83W6+SFITIExm6I9pvBIcKUNc5aXSov3IWRRik46nU1iqYqYg5n/0\n=2+px\n-----END PGP MESSAGE-----\n",
20 "fp": "A1C7C95E6CAF0A965CB47277BCF50A89C1B1F362"
21 }
22 ],
23 "unencrypted_suffix": "_unencrypted",
24 "version": "3.7.1"
25 }
26} \ No newline at end of file
diff --git a/modules/yggdrasil-wg/hosts/vidhar.pub b/modules/yggdrasil-wg/hosts/vidhar.pub
new file mode 100644
index 00000000..2807df64
--- /dev/null
+++ b/modules/yggdrasil-wg/hosts/vidhar.pub
@@ -0,0 +1 @@
IOuHpNQ2ff09HCPKtKY95lDXoRhd8FIBsbB8kaMeUUA=
diff --git a/shell.nix b/shell.nix
index 2840bec7..af0a0e9e 100644
--- a/shell.nix
+++ b/shell.nix
@@ -13,5 +13,6 @@ in pkgs.mkShell {
13 nativeBuildInputs = with pkgs; [ 13 nativeBuildInputs = with pkgs; [
14 nixWithFlakes 14 nixWithFlakes
15 sops 15 sops
16 wireguard
16 ]; 17 ];
17} 18}