summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--accounts/gkleen@skadhi/default.nix2
-rw-r--r--accounts/gkleen@skadhi/rzm/default.nix41
-rw-r--r--home-modules/autossh-proxy.nix114
3 files changed, 155 insertions, 2 deletions
diff --git a/accounts/gkleen@skadhi/default.nix b/accounts/gkleen@skadhi/default.nix
index e4b35a78..1d6381a5 100644
--- a/accounts/gkleen@skadhi/default.nix
+++ b/accounts/gkleen@skadhi/default.nix
@@ -288,6 +288,8 @@ in {
288 }; 288 };
289 289
290 programs.chromium.enable = true; 290 programs.chromium.enable = true;
291
292 services.autosshProxy.vidhar.port = 8121;
291 }; 293 };
292 }; 294 };
293} 295}
diff --git a/accounts/gkleen@skadhi/rzm/default.nix b/accounts/gkleen@skadhi/rzm/default.nix
index 11d8af8b..e2a47362 100644
--- a/accounts/gkleen@skadhi/rzm/default.nix
+++ b/accounts/gkleen@skadhi/rzm/default.nix
@@ -97,7 +97,7 @@ in {
97 ''; 97 '';
98 }; 98 };
99 99
100 home-manager.users.gkleen = { sysConfig, config, ... }: { 100 home-manager.users.gkleen = { sysConfig, config, lib, ... }: {
101 home.persistence."/persistent" = { 101 home.persistence."/persistent" = {
102 files = [ 102 files = [
103 "rz.kdbx" 103 "rz.kdbx"
@@ -176,7 +176,36 @@ in {
176 pro = "$HOME/projects/pro"; 176 pro = "$HOME/projects/pro";
177 }; 177 };
178 178
179 programs.ssh.matchBlocks = { 179 programs.ssh.matchBlocks = let
180 autosshProxy = host: "${lib.getExe pkgs.socat} - SOCKS4A:127.0.0.1:%h:%p,socksport=${toString config.services.autosshProxy.${host}.port}";
181 in {
182 "repo-apt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
183 user = "root";
184 hostname = "repo-apt01.mathinst.loc";
185 proxyCommand = autosshProxy "mgmt01";
186 };
187 "mgmt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
188 user = "root";
189 hostname = "mgmt01.mathinst.loc";
190 proxyCommand = autosshProxy "mathw0h";
191 };
192 "mathw0e" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
193 hostname = "mathw0e.mathinst.loc";
194 proxyCommand = autosshProxy "mathw0h";
195 };
196 "cip04" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
197 hostname = "cip04.cipmath.loc";
198 proxyCommand = autosshProxy "mathw0h";
199 };
200 "mathw0h" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
201 hostname = "mathw0h.mathinst.loc";
202 proxyCommand = autosshProxy "ssh.math.lmu.de";
203 };
204 "math05" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
205 hostname = "math05.mathinst.loc";
206 proxyCommand = autosshProxy "mathw0h";
207 extraOptions.KexAlgorithms = "+diffie-hellman-group1-sha1";
208 };
180 "*.mathinst.loc" = { 209 "*.mathinst.loc" = {
181 match = "host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de"; 210 match = "host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de";
182 identityFile = "~/.ssh/gkleen@mathinst.loc"; 211 identityFile = "~/.ssh/gkleen@mathinst.loc";
@@ -191,6 +220,14 @@ in {
191 }; 220 };
192 }; 221 };
193 222
223 services.autosshProxy = {
224 "mgmt01" = { port = 8129; sshpassSecret = "root@mgmt01.mathinst.loc"; };
225 "mathw0e" = { port = 8125; sshpassSecret = "gkleen@mathw0e.mathinst.loc"; };
226 "mathw0h" = { port = 8123; sshpassSecret = "gkleen@mathw0h.mathinst.loc"; };
227 "cip04" = { port = 8127; sshpassSecret = "gkleen@cip04.cipmath.loc"; };
228 "ssh.math.lmu.de" = { port = 8119; sshpassSecret = "gkleen@ssh.math.lmu.de"; };
229 };
230
194 home.file = { 231 home.file = {
195 ".cups/client.conf".text = '' 232 ".cups/client.conf".text = ''
196 ServerName cups.mathinst.loc 233 ServerName cups.mathinst.loc
diff --git a/home-modules/autossh-proxy.nix b/home-modules/autossh-proxy.nix
new file mode 100644
index 00000000..e3179096
--- /dev/null
+++ b/home-modules/autossh-proxy.nix
@@ -0,0 +1,114 @@
1{ lib, sysConfig, config, pkgs, ... }:
2
3let
4 cfg = config.services.autosshProxy;
5in {
6 options = {
7 services.autosshProxy = lib.mkOption {
8 type = lib.types.attrsOf (lib.types.submodule ({ name, config, ... }: {
9 options = {
10 port = lib.mkOption {
11 type = lib.types.port;
12 };
13
14 socksPort = lib.mkOption {
15 type = lib.types.port;
16 default = config.port - 1;
17 };
18
19 host = lib.mkOption {
20 type = lib.types.str;
21 default = name;
22 };
23
24 sshpassSecret = lib.mkOption {
25 type = lib.types.nullOr lib.types.str;
26 };
27 };
28 }));
29 };
30 };
31
32 config = {
33 assertions = [
34 {
35 assertion = builtins.length (lib.unique (lib.concatMap (cfg: [cfg.port cfg.socksPort]) (builtins.attrValues cfg))) == builtins.length (builtins.attrValues cfg) * 2;
36 message = "autosshProxy ports are not unique";
37 }
38 ];
39
40 systemd.user.services = lib.mkMerge (map (cfg: {
41 "autossh-socks@${cfg.host}:${toString cfg.socksPort}" = {
42 Service = {
43 Type = "notify";
44 NotifyAccess = "all";
45 WorkingDirectory = "~";
46 Restart = "always";
47 RestartSec = "23s";
48 ExecStart = "${pkgs.writeScript "autossh" ''
49 #!${lib.getExe config.programs.zsh.package} -xe
50
51 host="''${1%:*}"
52 port="''${1#*:}"
53
54 typeset -a cmd
55 cmd=()
56
57 if [[ -n "''${SSHPASS_SECRET}" ]]; then
58 cmd+=(${lib.getExe' pkgs.sshpassSecret "sshpass-secret"})
59 cmd+=("''${(@s/:/)SSHPASS_SECRET}")
60 cmd+=(--)
61 fi
62
63 cmd+=(${lib.getExe' pkgs.openssh "ssh"} -vN -D 127.0.0.1:''${port} -o ControlPath=none -o ExitOnForwardFailure=yes -o ServerAliveCountMax=15 -o ServerAliveInterval=2 "''${host}")
64
65 ( exec -a "''${cmd[1]}" -- ''${cmd} ) &
66 pid=$!
67
68 newpid=""
69 i=200
70 while ! { newpid=$(${lib.getExe' pkgs.iproute2 "ss"} -HO -pln "src localhost sport ''${port}" | ${lib.getExe pkgs.gnused} -r 's/^.*pid=([0-9]+).*$/\1/'); [[ -n $newpid ]] }; do
71 if ! kill -0 "''${pid}"; then
72 wait "''${pid}"
73 exit $?
74 fi
75 [[ "''${i}" -gt 0 ]] || exit 1
76 i=$((''${i} - 1))
77 ${lib.getExe' pkgs.coreutils "sleep"} 0.1
78 done
79
80 ${lib.getExe' sysConfig.systemd.package "systemd-notify"} --pid=''${newpid} --ready
81 ''} \"%I\"";
82 Environment = lib.optional (cfg.sshpassSecret != null) "SSHPASS_SECRET=${cfg.sshpassSecret}";
83 };
84 Unit = {
85 StopWhenUnneeded = true;
86 StartLimitInterval = "180s";
87 StartLimitBurst = 7;
88 };
89 };
90 "proxy-to-autossh-socks@${toString cfg.port}" = {
91 Unit = {
92 BindsTo = ["autossh-socks@${cfg.host}:${toString cfg.socksPort}.service" "proxy-to-autossh-socks@${toString cfg.port}.socket"];
93 After = ["autossh-socks@${cfg.host}:${toString cfg.socksPort}.service" "proxy-to-autossh-socks@${toString cfg.port}.socket"];
94 };
95 Service = {
96 ExecStart = "${sysConfig.systemd.package}/lib/systemd/systemd-socket-proxyd --exit-idle-time=60s 127.0.0.1:${toString cfg.socksPort}";
97 Restart = "always";
98 RestartSec = "23s";
99 };
100 };
101 }) (builtins.attrValues cfg));
102 systemd.user.sockets = builtins.listToAttrs (map (cfg: lib.nameValuePair "proxy-to-autossh-socks@${toString cfg.port}" {
103 Socket = {
104 ListenStream = "%I";
105 TriggerLimitIntervalSec = 0;
106 PollLimitIntervalSec = "180s";
107 PollLimitBurst = 6;
108 };
109 Install = {
110 WantedBy = ["sockets.target"];
111 };
112 }) (builtins.attrValues cfg));
113 };
114}