diff options
author | Gregor Kleen <gkleen@yggdrasil.li> | 2021-09-29 21:55:16 +0200 |
---|---|---|
committer | Gregor Kleen <gkleen@yggdrasil.li> | 2021-09-29 21:55:16 +0200 |
commit | eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e (patch) | |
tree | c2c49e061886108ec146f431daed73c47e0cca4f | |
parent | 05438304665bdaaf37ba4c148ab07bdf8fd3fb03 (diff) | |
download | nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.tar nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.tar.gz nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.tar.bz2 nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.tar.xz nixos-eebfe0864f92f5c390ed0e4a6959cb69f7f7f40e.zip |
yggdrasil-wg: init
-rw-r--r-- | modules/yggdrasil-wg/default.nix | 69 | ||||
-rw-r--r-- | modules/yggdrasil-wg/hosts/surtr.priv | 26 | ||||
-rw-r--r-- | modules/yggdrasil-wg/hosts/surtr.pub | 1 | ||||
-rw-r--r-- | modules/yggdrasil-wg/hosts/vidhar.priv | 26 | ||||
-rw-r--r-- | modules/yggdrasil-wg/hosts/vidhar.pub | 1 | ||||
-rw-r--r-- | shell.nix | 1 |
6 files changed, 124 insertions, 0 deletions
diff --git a/modules/yggdrasil-wg/default.nix b/modules/yggdrasil-wg/default.nix new file mode 100644 index 00000000..08665e33 --- /dev/null +++ b/modules/yggdrasil-wg/default.nix | |||
@@ -0,0 +1,69 @@ | |||
1 | { config, hostName, lib, ... }: | ||
2 | |||
3 | with lib; | ||
4 | |||
5 | let | ||
6 | listenPort = 51820; | ||
7 | subnet = "2a03:4000:52:ada:1"; | ||
8 | |||
9 | links = [ | ||
10 | { from = "vidhar"; | ||
11 | to = "surtr"; | ||
12 | endpointHost = "surtr.yggdrasil.li"; | ||
13 | persistentKeepalive = 25; | ||
14 | dynamicEndpointRefreshSeconds = 86400; | ||
15 | } | ||
16 | ]; | ||
17 | hostIPs = { | ||
18 | surtr = ["${subnet}::/32"]; | ||
19 | vidhar = ["${subnet}:1::/32"]; | ||
20 | }; | ||
21 | |||
22 | mkPublicKeyPath = host: ./hosts + "/${host}.pub"; | ||
23 | mkPrivateKeyPath = host: ./hosts + "/${host}.priv"; | ||
24 | |||
25 | publicKeyPath = mkPublicKeyPath hostName; | ||
26 | privateKeyPath = mkPrivateKeyPath hostName; | ||
27 | inNetwork = pathExists privateKeyPath && pathExists publicKeyPath; | ||
28 | hostLinks = filter ({ from, to, ... }: from == hostName || to == hostName) links; | ||
29 | linkToPeer = opts@{from, to, ...}: | ||
30 | let | ||
31 | other = if from == hostName then to else from; | ||
32 | in { | ||
33 | allowedIPs = hostIPs.${other}; | ||
34 | publicKey = trim (readFile (mkPublicKeyPath other)); | ||
35 | } // (optionalAttrs (from == hostName) (filterAttrs (n: _v: !(elem n ["from" "to" "endpointHost"])) opts // optionalAttrs (opts ? "endpointHost") { endpoint = "${opts.endpointHost}:${toString listenPort}"; })); | ||
36 | |||
37 | trim = str: if hasSuffix "\n" str then trim (removeSuffix "\n" str) else str; | ||
38 | stripSubnet = addr: let matchRes = builtins.match "^(.*)/[0-9]+$" addr; in if matchRes == null then addr else elemAt matchRes 0; | ||
39 | in { | ||
40 | config = { | ||
41 | assertions = [ | ||
42 | { assertion = inNetwork || !(pathExists privateKeyPath || pathExists publicKeyPath); | ||
43 | message = "yggdrasil-wg: Either both public and private keys must exist or neither."; | ||
44 | } | ||
45 | { assertion = !inNetwork || (hostIPs ? "${hostName}"); | ||
46 | message = "yggdrasil-wg: Entry in hostIPs must exist."; | ||
47 | } | ||
48 | ] ++ map ({from, to, ...}: let other = if from == hostName then to else from; in { assertion = pathExists (mkPublicKeyPath other); message = "yggdrasil-wg: This host (${hostName}) has a link with ‘${other}’, but no public key is available for ‘${other}’."; }) hostLinks; | ||
49 | |||
50 | networking.wireguard.interfaces = mkIf inNetwork { | ||
51 | yggdrasil = { | ||
52 | allowedIPsAsRoutes = true; | ||
53 | inherit listenPort; | ||
54 | ips = hostIPs.${hostName}; | ||
55 | peers = map linkToPeer hostLinks; | ||
56 | privateKeyFile = config.sops.secrets."yggdrasil-wg.priv".path; | ||
57 | }; | ||
58 | }; | ||
59 | |||
60 | sops.secrets = mkIf (pathExists privateKeyPath) { | ||
61 | "yggdrasil-wg.priv" = { | ||
62 | format = "binary"; | ||
63 | sopsFile = privateKeyPath; | ||
64 | }; | ||
65 | }; | ||
66 | |||
67 | networking.hosts = mkIf inNetwork (listToAttrs (concatMap ({name, value}: map (ip: nameValuePair (stripSubnet ip) ["${name}.yggdrasil"]) value) (mapAttrsToList nameValuePair hostIPs))); | ||
68 | }; | ||
69 | } | ||
diff --git a/modules/yggdrasil-wg/hosts/surtr.priv b/modules/yggdrasil-wg/hosts/surtr.priv new file mode 100644 index 00000000..b5d107f5 --- /dev/null +++ b/modules/yggdrasil-wg/hosts/surtr.priv | |||
@@ -0,0 +1,26 @@ | |||
1 | { | ||
2 | "data": "ENC[AES256_GCM,data:TbEkDgs1y71JYTfmF8wXtPDtkFlhYRnpOPIVQPV+u5Se9D7l5TT6r7CFP/FP,iv:OjktMWZhKYIklsKTdj3cViXcO6LcnGSsDllZatof4hg=,tag:oHoSbCPEcQWkAu7mhSOUiA==,type:str]", | ||
3 | "sops": { | ||
4 | "kms": null, | ||
5 | "gcp_kms": null, | ||
6 | "azure_kv": null, | ||
7 | "hc_vault": null, | ||
8 | "age": null, | ||
9 | "lastmodified": "2021-09-29T19:10:07Z", | ||
10 | "mac": "ENC[AES256_GCM,data:/hFdwXsAxrt3SCU0rbPPeBZ6mBsWcGkN3IMcOP3c28Df452/H0FM67/54NXwSErubnfIY4RXyGfj1dgLBV3A3r43E/F3uN4K8Qt1Ms+dJJdMjKiYpsOuCMgLe27yvI6LtUu0ePPJAPu+me1dOMSdvlQAMwNByrtKmLceMFVJ7gw=,iv:UauO61EBRWvVxYU2vlMI8nqIWw+KO1lEVIc82vVs4ZA=,tag:BzYnM9XcefVd/2T0JcMM2A==,type:str]", | ||
11 | "pgp": [ | ||
12 | { | ||
13 | "created_at": "2021-09-29T19:10:06Z", | ||
14 | "enc": "-----BEGIN PGP MESSAGE-----\n\nhF4DXxoViZlp6dISAQdAoHdrbuBJjuTnrUDbeAf7aeb6Kz6HbLuLiHZmSt/rSlow\nfgcSqsdYKMdSFeemRzAw++dBuIeduye31GGNDpsZUYyK9r90x0PJaFL3AABudAsj\n0l4Bm1YyqMDv/gzZeK87QDGpYZPu7+dkSrYO1sRe1qHrdI0L1WUs38l0eQM1qSUR\n4Gv4JBXNipoVTH8cfcGRvAy9y2+deEdzDtNK8rqLaQrc+q2TdV8Qlngp/EZqsQef\n=PM7q\n-----END PGP MESSAGE-----\n", | ||
15 | "fp": "30D3453B8CD02FE2A3E7C78C0FB536FB87AE8F51" | ||
16 | }, | ||
17 | { | ||
18 | "created_at": "2021-09-29T19:10:06Z", | ||
19 | "enc": "-----BEGIN PGP MESSAGE-----\n\nhF4DyFKFNkTVG5oSAQdAIQL7kGdUkG3CgEyRFdayydeTJGxjD4epYvaQBl4L0g4w\npKoTQuDf8FD3HeFI6ZO/jaE0BFX9Ifd3TYINK/XtqePOkYteos8aqJ/83t35aCIa\n0l4Bq2wt9BRR1pOQzJxnu8Dn9BsnOAQTp8JpwX5fY/FuPXTP8SV2XwWuHKnRd0j/\np7cSOUrog9agk9pc8tjwR+M451xN5AOpqdbqLkuNhi1b6QuxvI+sGsdh3sMz0UBs\n=5ozm\n-----END PGP MESSAGE-----\n", | ||
20 | "fp": "7ED22F4AA7BB55728B643DC5471B7D88E4EF66F8" | ||
21 | } | ||
22 | ], | ||
23 | "unencrypted_suffix": "_unencrypted", | ||
24 | "version": "3.7.1" | ||
25 | } | ||
26 | } \ No newline at end of file | ||
diff --git a/modules/yggdrasil-wg/hosts/surtr.pub b/modules/yggdrasil-wg/hosts/surtr.pub new file mode 100644 index 00000000..abe753eb --- /dev/null +++ b/modules/yggdrasil-wg/hosts/surtr.pub | |||
@@ -0,0 +1 @@ | |||
YP/sWEUWw51czlGxvgrgyEZ+ssx/3C9siufgd0a8d3g= | |||
diff --git a/modules/yggdrasil-wg/hosts/vidhar.priv b/modules/yggdrasil-wg/hosts/vidhar.priv new file mode 100644 index 00000000..c5b2ea99 --- /dev/null +++ b/modules/yggdrasil-wg/hosts/vidhar.priv | |||
@@ -0,0 +1,26 @@ | |||
1 | { | ||
2 | "data": "ENC[AES256_GCM,data:5RT5TQsBBZY5c4yRpDTYL+M3zLIzYSLST8L31ZmwlQdZs7saXwfehnHo5j0o,iv:/3QrjBfLqQ//ySv9TdTV7jGIzFkR+ZPBi0KJBAkxH+Y=,tag:kwx+Uln6AFBxkv7EE2jFgg==,type:str]", | ||
3 | "sops": { | ||
4 | "kms": null, | ||
5 | "gcp_kms": null, | ||
6 | "azure_kv": null, | ||
7 | "hc_vault": null, | ||
8 | "age": null, | ||
9 | "lastmodified": "2021-09-29T19:10:37Z", | ||
10 | "mac": "ENC[AES256_GCM,data:iglf4GccydO5//TZbw2TWndqeIuZz3G1k7blAW1fNgoxdEDGN16NtsH+/iduQj27BsFhRdPXLO9JWmpeOjwzUMnmkuEOhmALYMZGaZRBzO/x6k5EICFacm6lGUHDm307hexzWtIpNaViuZJiWVlT4IDi5k3N2QaUCYp02AqzPeU=,iv:c5RCIl4zLxrWewc37QIwKIyK5lrBWwSe7Me/yP3UCoU=,tag:LfjGnveOB/lMGhOYk3Ev3A==,type:str]", | ||
11 | "pgp": [ | ||
12 | { | ||
13 | "created_at": "2021-09-29T19:10:37Z", | ||
14 | "enc": "-----BEGIN PGP MESSAGE-----\n\nhF4DXxoViZlp6dISAQdA0wHAgvPYDG0FBH2rql1gX37YtzsK1K/AUNSarn71dAQw\nJ6FEldRQ6M+hN41ooX9DSebEtumtiLNQHnvShICw8ULFhrsgyGdUkZAb9eJ9pHnO\n0l4BDS9/MbcTpsZWW+LfFPAZCGsVi1eF5abQKDFDt5RMvxERefIR7jHd6vmjDKgy\nrESOG1nGFsvLnU5/OKJtSmWKDsnMh4ohJ1Agojh4YeVRUnFkM0vdihdZnEAlMz6E\n=DO1o\n-----END PGP MESSAGE-----\n", | ||
15 | "fp": "30D3453B8CD02FE2A3E7C78C0FB536FB87AE8F51" | ||
16 | }, | ||
17 | { | ||
18 | "created_at": "2021-09-29T19:10:37Z", | ||
19 | "enc": "-----BEGIN PGP MESSAGE-----\n\nhF4DbYDvGI0HDr0SAQdAJ09HBaaPhDdTOfpzVxuhtzG7s5ZjVrpZWmKKeO23bGYw\n2ctQ4YdNJt5Wv0AhgA0XVZK06rHtBV18utaeXhP7DYZID+wyMUkO7UR4/hhEGmb9\n0l4BzTxnL9liRwH5zB9r7erJYcDOUixtqtriRaoHUM2hDemprMqg+GoBj/Js7V52\nOKCiNGx5uDZ83W6+SFITIExm6I9pvBIcKUNc5aXSov3IWRRik46nU1iqYqYg5n/0\n=2+px\n-----END PGP MESSAGE-----\n", | ||
20 | "fp": "A1C7C95E6CAF0A965CB47277BCF50A89C1B1F362" | ||
21 | } | ||
22 | ], | ||
23 | "unencrypted_suffix": "_unencrypted", | ||
24 | "version": "3.7.1" | ||
25 | } | ||
26 | } \ No newline at end of file | ||
diff --git a/modules/yggdrasil-wg/hosts/vidhar.pub b/modules/yggdrasil-wg/hosts/vidhar.pub new file mode 100644 index 00000000..2807df64 --- /dev/null +++ b/modules/yggdrasil-wg/hosts/vidhar.pub | |||
@@ -0,0 +1 @@ | |||
IOuHpNQ2ff09HCPKtKY95lDXoRhd8FIBsbB8kaMeUUA= | |||
@@ -13,5 +13,6 @@ in pkgs.mkShell { | |||
13 | nativeBuildInputs = with pkgs; [ | 13 | nativeBuildInputs = with pkgs; [ |
14 | nixWithFlakes | 14 | nixWithFlakes |
15 | sops | 15 | sops |
16 | wireguard | ||
16 | ]; | 17 | ]; |
17 | } | 18 | } |