summaryrefslogtreecommitdiff
path: root/accounts/gkleen@skadhi/rzm/default.nix
diff options
context:
space:
mode:
Diffstat (limited to 'accounts/gkleen@skadhi/rzm/default.nix')
-rw-r--r--accounts/gkleen@skadhi/rzm/default.nix248
1 files changed, 248 insertions, 0 deletions
diff --git a/accounts/gkleen@skadhi/rzm/default.nix b/accounts/gkleen@skadhi/rzm/default.nix
new file mode 100644
index 00000000..a545bae9
--- /dev/null
+++ b/accounts/gkleen@skadhi/rzm/default.nix
@@ -0,0 +1,248 @@
1{ config, pkgs, lib, ... }:
2let
3 mwnSubnetsPublic =
4 [ "129.187.0.0/16" "141.40.0.0/16" "141.84.0.0/16"
5 "192.68.211.0/24" "192.68.212.0/24" "192.68.213.0/24" "192.68.214.0/24" "192.68.215.0/24"
6 "193.174.96.0/22"
7 "194.95.59.0/24"
8 ];
9 mwnSubnetsPrivate =
10 [ "10.153.0.0/16" "10.162.0.0/16" "10.156.0.0/16"
11 ];
12in {
13 config = {
14 systemd.network = {
15 config.routeTables.wgrz = 1025;
16 netdevs = {
17 wgrz = {
18 netdevConfig = {
19 Name = "wgrz";
20 Kind = "wireguard";
21 MTUBytes = "1558";
22 };
23 wireguardConfig = {
24 PrivateKeyFile = "/run/credentials/systemd-networkd.service/wgrz.priv";
25 ListenPort = 51822;
26 # FirewallMark = 1;
27 };
28 wireguardPeers = [
29 { AllowedIPs = [ "10.200.116.1/32" "10.163.88.40/32" ] ++ mwnSubnetsPrivate ++ mwnSubnetsPublic;
30 PublicKey = "YlRFLc+rD2k2KXl7pIJbOKbcPgdJCl8ZTsv0xlK4VEI=";
31 PersistentKeepalive = 25;
32 Endpoint = "wg.math.lmu.de:51820";
33 }
34 ];
35 };
36 };
37 networks = {
38 wgrz = {
39 name = "wgrz";
40 matchConfig = {
41 Name = "wgrz";
42 };
43 address = ["10.200.116.131/24"];
44 routes = map (Destination: {
45 inherit Destination;
46 Gateway = "10.200.116.1";
47 GatewayOnLink = true;
48 Table = "wgrz";
49 }) (mwnSubnetsPrivate ++ mwnSubnetsPublic ++ ["10.163.88.40/32"]);
50 routingPolicyRules = [
51 { Table = "main";
52 # FirewallMark = 1;
53 To = "129.187.111.225";
54 Priority = 100;
55 }
56 { Table = "main";
57 To = "10.153.91.204";
58 Priority = 100;
59 }
60 { Table = "wgrz";
61 From = "10.200.116.131";
62 Priority = 200;
63 }
64 { Table = "wgrz";
65 To = "10.163.88.40";
66 Priority = 200;
67 }
68 ] ++ map (To: { Table = "wgrz";
69 inherit To;
70 Priority = 200;
71 }) (mwnSubnetsPrivate ++ mwnSubnetsPublic);
72 linkConfig = {
73 RequiredForOnline = false;
74 };
75 networkConfig = {
76 LLMNR = false;
77 MulticastDNS = false;
78 DNS = ["10.153.88.9" "129.187.111.202" "10.156.33.53"];
79 # Tunnel = "rz-gre-1";
80 };
81 };
82 };
83 };
84 networking.networkmanager.unmanaged = ["wgrz"];
85 sops.secrets.wgrz = {
86 format = "binary";
87 sopsFile = ./wgrz.priv;
88 };
89 systemd.services."systemd-networkd".serviceConfig.LoadCredential = [
90 "wgrz.priv:${config.sops.secrets.wgrz.path}"
91 ];
92
93 environment.etc."NetworkManager/dnsmasq.d/wgrz.conf" = {
94 text = ''
95 server=/mathinst.loc/10.153.88.9@wgrz
96 server=/cipmath.loc/10.153.88.9@wgrz
97 '';
98 };
99
100 home-manager.users.gkleen = { sysConfig, config, lib, ... }: {
101 home.persistence."/persistent" = {
102 files = [
103 "rz.kdbx"
104 ];
105 directories = [
106 ".config/Element-lmu" ".config/worktime"
107 ".config/chromium-kimai" ".config/chromium-rainbow"
108 ];
109 };
110
111 xdg.desktopEntries = {
112 element-lmu = {
113 name = "Element (LMU)";
114 exec = "element-desktop --profile=lmu %u";
115 icon = "element";
116 genericName = "Matrix Client";
117 categories = [ "Network" "InstantMessaging" "Chat" ];
118 settings = {
119 StartupWMClass = "Element";
120 };
121 };
122 thunderbird-lmu = {
123 name = "Thunderbird (LMU)";
124 exec = "thunderbird --name thunderbird -P lmu %U";
125 icon = "thunderbird";
126 genericName = "Email Client";
127 categories = [ "Network" "Chat" "Email" "Feed" "GTK" "News" ];
128 settings = {
129 StartupWMClass = "thunderbird";
130 StartupNotify = "true";
131 };
132 };
133 rainbow = {
134 name = "Rainbow";
135 exec = toString (pkgs.writeShellScript "rainbow" ''
136 exec -- \
137 ${lib.getExe' sysConfig.systemd.package "systemd-run"} --wait --user --slice-inherit \
138 --property 'CPUAccounting=yes' --property 'CPUQuotaPeriodSec=50ms' \
139 -E DSCP=46 -E NIXOS_OZONE_WL \
140 -- ${lib.getExe pkgs.dscp} ${lib.getExe config.programs.chromium.package} \
141 --class=Rainbow \
142 --app="https://web.openrainbow.com" \
143 --user-data-dir=''${HOME}/.config/chromium-rainbow
144 '');
145 icon = pkgs.fetchurl {
146 url = "https://web.openrainbow.com/rb/2.174.21/assets/skins/rainbow/images/homepage/logo__rainbow.svg";
147 hash = "sha256-5fmo8rDqVDpzkGaPjk4Y+SsSZpAsY7VUQSFW6WdHwuU=";
148 };
149 settings = {
150 StartupWMClass = "Rainbow";
151 };
152 };
153 kimai = {
154 name = "Kimai";
155 exec = toString (pkgs.writeShellScript "kimai" ''
156 exec -- \
157 ${lib.getExe config.programs.chromium.package} \
158 --class=Kimai \
159 --app="https://kimai.yggdrasil.li" \
160 --user-data-dir=''${HOME}/.config/chromium-kimai
161 '');
162 icon = pkgs.fetchurl {
163 url = "https://www.kimai.org/images/kimai_logo.png";
164 hash = "sha256-lnlOttzR2SwXA70R+egJUkeKr4U5V0avqTk8uX4bqfs=";
165 };
166 settings = {
167 StartupWMClass = "Kimai";
168 StartupNotify = "true";
169 };
170 };
171 };
172
173 programs.zsh.dirHashes = {
174 u2w = "$HOME/projects/uni2work";
175 rz = "$HOME/projects/rz";
176 pro = "$HOME/projects/pro";
177 };
178
179 programs.ssh.settings = {
180 "repo-apt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
181 User = "root";
182 Hostname = "repo-apt01.mathinst.loc";
183 inherit (config.programs.ssh.autosshProxies."mgmt01") ProxyCommand;
184 };
185 "mgmt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
186 User = "root";
187 Hostname = "mgmt01.mathinst.loc";
188 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
189 };
190 "mathw0e" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
191 Hostname = "mathw0e.mathinst.loc";
192 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
193 };
194 "cip04" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
195 Hostname = "cip04.cipmath.loc";
196 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
197 };
198 "mathw0h" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
199 Hostname = "mathw0h.mathinst.loc";
200 inherit (config.programs.ssh.autosshProxies."ssh.math.lmu.de") ProxyCommand;
201 };
202 "math05" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
203 Hostname = "math05.mathinst.loc";
204 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
205 KexAlgorithms = "+diffie-hellman-group1-sha1";
206 };
207 "dhcp01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
208 Hostname = "dhcp01.mathinst.loc";
209 User = "root";
210 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
211 };
212 "dhcp02" = lib.hm.dag.entryBefore ["*.mathinst.loc"] {
213 Hostname = "dhcp02.mathinst.loc";
214 User = "root";
215 inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand;
216 };
217 "*.mathinst.loc" = {
218 header = "Match host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de";
219 IdentityFile = "~/.ssh/gkleen@mathinst.loc";
220 HostKeyAlgorithms = "+ssh-rsa";
221 PubkeyAcceptedAlgorithms = "+ssh-rsa";
222 PasswordAuthentication = "yes";
223 GlobalKnownHostsFile = toString (pkgs.writeText "ssh_known_hosts" ''
224 @cert-authority *.mathinst.loc,*.math.lmu.de,*.cipmath.loc ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUTFpVCdETCXiDSDl7YGbR1J4BLTsoBzjDtflHJGO/z ssh-pki@mgmt01
225 '');
226 };
227 };
228
229 programs.ssh.autosshProxies = {
230 "mgmt01" = { port = 8129; sshpassSecret = "root@mgmt01.mathinst.loc"; };
231 "mathw0e" = { port = 8125; sshpassSecret = "gkleen@mathw0e.mathinst.loc"; };
232 "mathw0h" = { port = 8123; sshpassSecret = "gkleen@mathw0h.mathinst.loc"; };
233 "cip04" = { port = 8127; sshpassSecret = "gkleen@cip04.cipmath.loc"; };
234 "ssh.math.lmu.de" = { port = 8119; sshpassSecret = "gkleen@ssh.math.lmu.de"; };
235 };
236
237 home.file = {
238 ".cups/client.conf".text = ''
239 ServerName cups.mathinst.loc
240 '';
241 };
242
243 home.packages = with pkgs; [
244 cups
245 ];
246 };
247 };
248}