diff options
| author | Gregor Kleen <gkleen@yggdrasil.li> | 2025-05-14 10:50:27 +0200 |
|---|---|---|
| committer | Gregor Kleen <gkleen@yggdrasil.li> | 2025-05-14 10:50:27 +0200 |
| commit | 43c9825e49d25fbd2c19abcdeb8f73aee8be2a4c (patch) | |
| tree | c1cc8a034395c9bb8188651f6835922b38887f32 /hosts/sif | |
| parent | 03d49aa8ec6f51c8f51bfb628e614ac537cca8e0 (diff) | |
| download | nixos-43c9825e49d25fbd2c19abcdeb8f73aee8be2a4c.tar nixos-43c9825e49d25fbd2c19abcdeb8f73aee8be2a4c.tar.gz nixos-43c9825e49d25fbd2c19abcdeb8f73aee8be2a4c.tar.bz2 nixos-43c9825e49d25fbd2c19abcdeb8f73aee8be2a4c.tar.xz nixos-43c9825e49d25fbd2c19abcdeb8f73aee8be2a4c.zip | |
...
Diffstat (limited to 'hosts/sif')
| -rw-r--r-- | hosts/sif/default.nix | 34 | ||||
| -rw-r--r-- | hosts/sif/ruleset.nft | 8 |
2 files changed, 4 insertions, 38 deletions
diff --git a/hosts/sif/default.nix b/hosts/sif/default.nix index 0897e1d8..f4de24e8 100644 --- a/hosts/sif/default.nix +++ b/hosts/sif/default.nix | |||
| @@ -126,38 +126,8 @@ in { | |||
| 126 | rulesetFile = ./ruleset.nft; | 126 | rulesetFile = ./ruleset.nft; |
| 127 | }; | 127 | }; |
| 128 | 128 | ||
| 129 | # firewall = { | ||
| 130 | # enable = true; | ||
| 131 | # allowedTCPPorts = [ 22 # ssh | ||
| 132 | # 8000 # quickserve | ||
| 133 | # ]; | ||
| 134 | # }; | ||
| 135 | |||
| 136 | # wlanInterfaces = { | ||
| 137 | # wlan0 = { | ||
| 138 | # device = "wlp82s0"; | ||
| 139 | # }; | ||
| 140 | # }; | ||
| 141 | |||
| 142 | # bonds = { | ||
| 143 | # "lan" = { | ||
| 144 | # interfaces = [ "wlan0" "enp0s31f6" "dock0" ]; | ||
| 145 | # driverOptions = { | ||
| 146 | # miimon = "1000"; | ||
| 147 | # mode = "active-backup"; | ||
| 148 | # primary_reselect = "always"; | ||
| 149 | # }; | ||
| 150 | # }; | ||
| 151 | # }; | ||
| 152 | |||
| 153 | useDHCP = false; | 129 | useDHCP = false; |
| 154 | useNetworkd = true; | 130 | useNetworkd = true; |
| 155 | |||
| 156 | # interfaces."tinc.yggdrasil" = { | ||
| 157 | # virtual = true; | ||
| 158 | # virtualType = config.services.tinc.networks.yggdrasil.interfaceType; | ||
| 159 | # macAddress = "5c:93:21:c3:61:39"; | ||
| 160 | # }; | ||
| 161 | }; | 131 | }; |
| 162 | 132 | ||
| 163 | environment.etc."NetworkManager/dnsmasq.d/libvirt_dnsmasq.conf" = { | 133 | environment.etc."NetworkManager/dnsmasq.d/libvirt_dnsmasq.conf" = { |
| @@ -751,10 +721,6 @@ in { | |||
| 751 | 721 | ||
| 752 | home-manager.sharedModules = [ flakeInputs.nixVirt.homeModules.default ]; | 722 | home-manager.sharedModules = [ flakeInputs.nixVirt.homeModules.default ]; |
| 753 | 723 | ||
| 754 | environment.pathsToLink = [ | ||
| 755 | "share/zsh" | ||
| 756 | ]; | ||
| 757 | |||
| 758 | system.stateVersion = "24.11"; | 724 | system.stateVersion = "24.11"; |
| 759 | }; | 725 | }; |
| 760 | } | 726 | } |
diff --git a/hosts/sif/ruleset.nft b/hosts/sif/ruleset.nft index 2af8b2ee..62339f69 100644 --- a/hosts/sif/ruleset.nft +++ b/hosts/sif/ruleset.nft | |||
| @@ -61,7 +61,7 @@ table inet filter { | |||
| 61 | counter mosh-rx {} | 61 | counter mosh-rx {} |
| 62 | counter wg-rx {} | 62 | counter wg-rx {} |
| 63 | counter yggdrasil-gre-rx {} | 63 | counter yggdrasil-gre-rx {} |
| 64 | counter quickserve-rx {} | 64 | counter miniserve-rx {} |
| 65 | counter ausweisapp2-rx {} | 65 | counter ausweisapp2-rx {} |
| 66 | 66 | ||
| 67 | counter established-rx {} | 67 | counter established-rx {} |
| @@ -81,7 +81,7 @@ table inet filter { | |||
| 81 | counter mosh-tx {} | 81 | counter mosh-tx {} |
| 82 | counter wg-tx {} | 82 | counter wg-tx {} |
| 83 | counter yggdrasil-gre-tx {} | 83 | counter yggdrasil-gre-tx {} |
| 84 | counter quickserve-tx {} | 84 | counter miniserve-tx {} |
| 85 | 85 | ||
| 86 | counter tx {} | 86 | counter tx {} |
| 87 | 87 | ||
| @@ -134,7 +134,7 @@ table inet filter { | |||
| 134 | tcp dport 22 counter name ssh-rx accept | 134 | tcp dport 22 counter name ssh-rx accept |
| 135 | udp dport 60000-61000 counter name mosh-rx accept | 135 | udp dport 60000-61000 counter name mosh-rx accept |
| 136 | 136 | ||
| 137 | tcp dport 8000 counter name quickserve-rx accept | 137 | tcp dport 8080 counter name miniserve-rx accept |
| 138 | udp dport 24727 counter name ausweisapp2-rx accept | 138 | udp dport 24727 counter name ausweisapp2-rx accept |
| 139 | 139 | ||
| 140 | udp dport 51820-51822 counter name wg-rx accept | 140 | udp dport 51820-51822 counter name wg-rx accept |
| @@ -173,7 +173,7 @@ table inet filter { | |||
| 173 | udp sport 51820-51822 counter name wg-tx | 173 | udp sport 51820-51822 counter name wg-tx |
| 174 | iifname "yggdrasil-wg-*" meta l4proto gre counter name yggdrasil-gre-tx | 174 | iifname "yggdrasil-wg-*" meta l4proto gre counter name yggdrasil-gre-tx |
| 175 | 175 | ||
| 176 | tcp sport 8000 counter name quickserve-tx accept | 176 | tcp sport 8080 counter name miniserve-tx accept |
| 177 | 177 | ||
| 178 | oifname virbr0 udp sport 67 counter name libvirt-dhcp accept | 178 | oifname virbr0 udp sport 67 counter name libvirt-dhcp accept |
| 179 | oifname virbr0 udp sport 547 counter name libvirt-dhcp accept | 179 | oifname virbr0 udp sport 547 counter name libvirt-dhcp accept |
