diff options
Diffstat (limited to 'accounts/gkleen@skadhi/rzm')
| -rw-r--r-- | accounts/gkleen@skadhi/rzm/default.nix | 248 | ||||
| -rw-r--r-- | accounts/gkleen@skadhi/rzm/wgrz.priv | 18 |
2 files changed, 266 insertions, 0 deletions
diff --git a/accounts/gkleen@skadhi/rzm/default.nix b/accounts/gkleen@skadhi/rzm/default.nix new file mode 100644 index 00000000..a545bae9 --- /dev/null +++ b/accounts/gkleen@skadhi/rzm/default.nix | |||
| @@ -0,0 +1,248 @@ | |||
| 1 | { config, pkgs, lib, ... }: | ||
| 2 | let | ||
| 3 | mwnSubnetsPublic = | ||
| 4 | [ "129.187.0.0/16" "141.40.0.0/16" "141.84.0.0/16" | ||
| 5 | "192.68.211.0/24" "192.68.212.0/24" "192.68.213.0/24" "192.68.214.0/24" "192.68.215.0/24" | ||
| 6 | "193.174.96.0/22" | ||
| 7 | "194.95.59.0/24" | ||
| 8 | ]; | ||
| 9 | mwnSubnetsPrivate = | ||
| 10 | [ "10.153.0.0/16" "10.162.0.0/16" "10.156.0.0/16" | ||
| 11 | ]; | ||
| 12 | in { | ||
| 13 | config = { | ||
| 14 | systemd.network = { | ||
| 15 | config.routeTables.wgrz = 1025; | ||
| 16 | netdevs = { | ||
| 17 | wgrz = { | ||
| 18 | netdevConfig = { | ||
| 19 | Name = "wgrz"; | ||
| 20 | Kind = "wireguard"; | ||
| 21 | MTUBytes = "1558"; | ||
| 22 | }; | ||
| 23 | wireguardConfig = { | ||
| 24 | PrivateKeyFile = "/run/credentials/systemd-networkd.service/wgrz.priv"; | ||
| 25 | ListenPort = 51822; | ||
| 26 | # FirewallMark = 1; | ||
| 27 | }; | ||
| 28 | wireguardPeers = [ | ||
| 29 | { AllowedIPs = [ "10.200.116.1/32" "10.163.88.40/32" ] ++ mwnSubnetsPrivate ++ mwnSubnetsPublic; | ||
| 30 | PublicKey = "YlRFLc+rD2k2KXl7pIJbOKbcPgdJCl8ZTsv0xlK4VEI="; | ||
| 31 | PersistentKeepalive = 25; | ||
| 32 | Endpoint = "wg.math.lmu.de:51820"; | ||
| 33 | } | ||
| 34 | ]; | ||
| 35 | }; | ||
| 36 | }; | ||
| 37 | networks = { | ||
| 38 | wgrz = { | ||
| 39 | name = "wgrz"; | ||
| 40 | matchConfig = { | ||
| 41 | Name = "wgrz"; | ||
| 42 | }; | ||
| 43 | address = ["10.200.116.131/24"]; | ||
| 44 | routes = map (Destination: { | ||
| 45 | inherit Destination; | ||
| 46 | Gateway = "10.200.116.1"; | ||
| 47 | GatewayOnLink = true; | ||
| 48 | Table = "wgrz"; | ||
| 49 | }) (mwnSubnetsPrivate ++ mwnSubnetsPublic ++ ["10.163.88.40/32"]); | ||
| 50 | routingPolicyRules = [ | ||
| 51 | { Table = "main"; | ||
| 52 | # FirewallMark = 1; | ||
| 53 | To = "129.187.111.225"; | ||
| 54 | Priority = 100; | ||
| 55 | } | ||
| 56 | { Table = "main"; | ||
| 57 | To = "10.153.91.204"; | ||
| 58 | Priority = 100; | ||
| 59 | } | ||
| 60 | { Table = "wgrz"; | ||
| 61 | From = "10.200.116.131"; | ||
| 62 | Priority = 200; | ||
| 63 | } | ||
| 64 | { Table = "wgrz"; | ||
| 65 | To = "10.163.88.40"; | ||
| 66 | Priority = 200; | ||
| 67 | } | ||
| 68 | ] ++ map (To: { Table = "wgrz"; | ||
| 69 | inherit To; | ||
| 70 | Priority = 200; | ||
| 71 | }) (mwnSubnetsPrivate ++ mwnSubnetsPublic); | ||
| 72 | linkConfig = { | ||
| 73 | RequiredForOnline = false; | ||
| 74 | }; | ||
| 75 | networkConfig = { | ||
| 76 | LLMNR = false; | ||
| 77 | MulticastDNS = false; | ||
| 78 | DNS = ["10.153.88.9" "129.187.111.202" "10.156.33.53"]; | ||
| 79 | # Tunnel = "rz-gre-1"; | ||
| 80 | }; | ||
| 81 | }; | ||
| 82 | }; | ||
| 83 | }; | ||
| 84 | networking.networkmanager.unmanaged = ["wgrz"]; | ||
| 85 | sops.secrets.wgrz = { | ||
| 86 | format = "binary"; | ||
| 87 | sopsFile = ./wgrz.priv; | ||
| 88 | }; | ||
| 89 | systemd.services."systemd-networkd".serviceConfig.LoadCredential = [ | ||
| 90 | "wgrz.priv:${config.sops.secrets.wgrz.path}" | ||
| 91 | ]; | ||
| 92 | |||
| 93 | environment.etc."NetworkManager/dnsmasq.d/wgrz.conf" = { | ||
| 94 | text = '' | ||
| 95 | server=/mathinst.loc/10.153.88.9@wgrz | ||
| 96 | server=/cipmath.loc/10.153.88.9@wgrz | ||
| 97 | ''; | ||
| 98 | }; | ||
| 99 | |||
| 100 | home-manager.users.gkleen = { sysConfig, config, lib, ... }: { | ||
| 101 | home.persistence."/persistent" = { | ||
| 102 | files = [ | ||
| 103 | "rz.kdbx" | ||
| 104 | ]; | ||
| 105 | directories = [ | ||
| 106 | ".config/Element-lmu" ".config/worktime" | ||
| 107 | ".config/chromium-kimai" ".config/chromium-rainbow" | ||
| 108 | ]; | ||
| 109 | }; | ||
| 110 | |||
| 111 | xdg.desktopEntries = { | ||
| 112 | element-lmu = { | ||
| 113 | name = "Element (LMU)"; | ||
| 114 | exec = "element-desktop --profile=lmu %u"; | ||
| 115 | icon = "element"; | ||
| 116 | genericName = "Matrix Client"; | ||
| 117 | categories = [ "Network" "InstantMessaging" "Chat" ]; | ||
| 118 | settings = { | ||
| 119 | StartupWMClass = "Element"; | ||
| 120 | }; | ||
| 121 | }; | ||
| 122 | thunderbird-lmu = { | ||
| 123 | name = "Thunderbird (LMU)"; | ||
| 124 | exec = "thunderbird --name thunderbird -P lmu %U"; | ||
| 125 | icon = "thunderbird"; | ||
| 126 | genericName = "Email Client"; | ||
| 127 | categories = [ "Network" "Chat" "Email" "Feed" "GTK" "News" ]; | ||
| 128 | settings = { | ||
| 129 | StartupWMClass = "thunderbird"; | ||
| 130 | StartupNotify = "true"; | ||
| 131 | }; | ||
| 132 | }; | ||
| 133 | rainbow = { | ||
| 134 | name = "Rainbow"; | ||
| 135 | exec = toString (pkgs.writeShellScript "rainbow" '' | ||
| 136 | exec -- \ | ||
| 137 | ${lib.getExe' sysConfig.systemd.package "systemd-run"} --wait --user --slice-inherit \ | ||
| 138 | --property 'CPUAccounting=yes' --property 'CPUQuotaPeriodSec=50ms' \ | ||
| 139 | -E DSCP=46 -E NIXOS_OZONE_WL \ | ||
| 140 | -- ${lib.getExe pkgs.dscp} ${lib.getExe config.programs.chromium.package} \ | ||
| 141 | --class=Rainbow \ | ||
| 142 | --app="https://web.openrainbow.com" \ | ||
| 143 | --user-data-dir=''${HOME}/.config/chromium-rainbow | ||
| 144 | ''); | ||
| 145 | icon = pkgs.fetchurl { | ||
| 146 | url = "https://web.openrainbow.com/rb/2.174.21/assets/skins/rainbow/images/homepage/logo__rainbow.svg"; | ||
| 147 | hash = "sha256-5fmo8rDqVDpzkGaPjk4Y+SsSZpAsY7VUQSFW6WdHwuU="; | ||
| 148 | }; | ||
| 149 | settings = { | ||
| 150 | StartupWMClass = "Rainbow"; | ||
| 151 | }; | ||
| 152 | }; | ||
| 153 | kimai = { | ||
| 154 | name = "Kimai"; | ||
| 155 | exec = toString (pkgs.writeShellScript "kimai" '' | ||
| 156 | exec -- \ | ||
| 157 | ${lib.getExe config.programs.chromium.package} \ | ||
| 158 | --class=Kimai \ | ||
| 159 | --app="https://kimai.yggdrasil.li" \ | ||
| 160 | --user-data-dir=''${HOME}/.config/chromium-kimai | ||
| 161 | ''); | ||
| 162 | icon = pkgs.fetchurl { | ||
| 163 | url = "https://www.kimai.org/images/kimai_logo.png"; | ||
| 164 | hash = "sha256-lnlOttzR2SwXA70R+egJUkeKr4U5V0avqTk8uX4bqfs="; | ||
| 165 | }; | ||
| 166 | settings = { | ||
| 167 | StartupWMClass = "Kimai"; | ||
| 168 | StartupNotify = "true"; | ||
| 169 | }; | ||
| 170 | }; | ||
| 171 | }; | ||
| 172 | |||
| 173 | programs.zsh.dirHashes = { | ||
| 174 | u2w = "$HOME/projects/uni2work"; | ||
| 175 | rz = "$HOME/projects/rz"; | ||
| 176 | pro = "$HOME/projects/pro"; | ||
| 177 | }; | ||
| 178 | |||
| 179 | programs.ssh.settings = { | ||
| 180 | "repo-apt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | ||
| 181 | User = "root"; | ||
| 182 | Hostname = "repo-apt01.mathinst.loc"; | ||
| 183 | inherit (config.programs.ssh.autosshProxies."mgmt01") ProxyCommand; | ||
| 184 | }; | ||
| 185 | "mgmt01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | ||
| 186 | User = "root"; | ||
| 187 | Hostname = "mgmt01.mathinst.loc"; | ||
| 188 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; | ||
| 189 | }; | ||
| 190 | "mathw0e" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | ||
| 191 | Hostname = "mathw0e.mathinst.loc"; | ||
| 192 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; | ||
| 193 | }; | ||
| 194 | "cip04" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | ||
| 195 | Hostname = "cip04.cipmath.loc"; | ||
| 196 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; | ||
| 197 | }; | ||
| 198 | "mathw0h" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | ||
| 199 | Hostname = "mathw0h.mathinst.loc"; | ||
| 200 | inherit (config.programs.ssh.autosshProxies."ssh.math.lmu.de") ProxyCommand; | ||
| 201 | }; | ||
| 202 | "math05" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | ||
| 203 | Hostname = "math05.mathinst.loc"; | ||
| 204 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; | ||
| 205 | KexAlgorithms = "+diffie-hellman-group1-sha1"; | ||
| 206 | }; | ||
| 207 | "dhcp01" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | ||
| 208 | Hostname = "dhcp01.mathinst.loc"; | ||
| 209 | User = "root"; | ||
| 210 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; | ||
| 211 | }; | ||
| 212 | "dhcp02" = lib.hm.dag.entryBefore ["*.mathinst.loc"] { | ||
| 213 | Hostname = "dhcp02.mathinst.loc"; | ||
| 214 | User = "root"; | ||
| 215 | inherit (config.programs.ssh.autosshProxies."mathw0h") ProxyCommand; | ||
| 216 | }; | ||
| 217 | "*.mathinst.loc" = { | ||
| 218 | header = "Match host *.mathinst.loc,*.cipmath.loc,*.math.lmu.de"; | ||
| 219 | IdentityFile = "~/.ssh/gkleen@mathinst.loc"; | ||
| 220 | HostKeyAlgorithms = "+ssh-rsa"; | ||
| 221 | PubkeyAcceptedAlgorithms = "+ssh-rsa"; | ||
| 222 | PasswordAuthentication = "yes"; | ||
| 223 | GlobalKnownHostsFile = toString (pkgs.writeText "ssh_known_hosts" '' | ||
| 224 | @cert-authority *.mathinst.loc,*.math.lmu.de,*.cipmath.loc ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUTFpVCdETCXiDSDl7YGbR1J4BLTsoBzjDtflHJGO/z ssh-pki@mgmt01 | ||
| 225 | ''); | ||
| 226 | }; | ||
| 227 | }; | ||
| 228 | |||
| 229 | programs.ssh.autosshProxies = { | ||
| 230 | "mgmt01" = { port = 8129; sshpassSecret = "root@mgmt01.mathinst.loc"; }; | ||
| 231 | "mathw0e" = { port = 8125; sshpassSecret = "gkleen@mathw0e.mathinst.loc"; }; | ||
| 232 | "mathw0h" = { port = 8123; sshpassSecret = "gkleen@mathw0h.mathinst.loc"; }; | ||
| 233 | "cip04" = { port = 8127; sshpassSecret = "gkleen@cip04.cipmath.loc"; }; | ||
| 234 | "ssh.math.lmu.de" = { port = 8119; sshpassSecret = "gkleen@ssh.math.lmu.de"; }; | ||
| 235 | }; | ||
| 236 | |||
| 237 | home.file = { | ||
| 238 | ".cups/client.conf".text = '' | ||
| 239 | ServerName cups.mathinst.loc | ||
| 240 | ''; | ||
| 241 | }; | ||
| 242 | |||
| 243 | home.packages = with pkgs; [ | ||
| 244 | cups | ||
| 245 | ]; | ||
| 246 | }; | ||
| 247 | }; | ||
| 248 | } | ||
diff --git a/accounts/gkleen@skadhi/rzm/wgrz.priv b/accounts/gkleen@skadhi/rzm/wgrz.priv new file mode 100644 index 00000000..d34e96ee --- /dev/null +++ b/accounts/gkleen@skadhi/rzm/wgrz.priv | |||
| @@ -0,0 +1,18 @@ | |||
| 1 | { | ||
| 2 | "data": "ENC[AES256_GCM,data:HbX+Vd4IpVcWIH/llV3BWnuWwOzNw/bZfjisD38CFNbd/RCPEnuIb2XCNi+4,iv:at3CY0GIDSSQSmiXlnNgLMIGIT5V8CYOCuFyThjMmGE=,tag:ZAttUMhZV56G5A54a8YXbg==,type:str]", | ||
| 3 | "sops": { | ||
| 4 | "age": [ | ||
| 5 | { | ||
| 6 | "enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBRRU1GNkZtbXgwMjVvVlo2\nMXkvc24rcEgyVEpyMVZwL25QTGYrZzBjT25ZCldraUhhNkFveXhLQ09ibjNUOVJl\nSUkzL0MwbkVQQXgzZkNiQjEwM05BVTAKLS0tIE5rSFRJalJqbERwdzFGeHdrTXFG\nWFdPU21PUEtxbGdibXNVZnYxMUdPaTQKw83yVaRBy4d2YLchQJM5ucZrdTpe0PUZ\nM9SdUP1eGbOIWkeUttG/qsKrLfHT2+GDhydxU6gwKiAfwDr9I3IGCA==\n-----END AGE ENCRYPTED FILE-----\n", | ||
| 7 | "recipient": "age1rmmhetcmllq0ahl5qznlr0eya2zdxwl9h6y5wnl97d2wtyx5t99sm2u866" | ||
| 8 | }, | ||
| 9 | { | ||
| 10 | "enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBBMDVCaTFYZVpmeUg1dWZs\nRHNYM3BSL2liemlaSGRWRTcya3VJUDd2akNNCjQ0N0V1ZTI1ZDhOZTBYMlBWZDdY\nQU1WSVNoMUhrUkgxQVhwL2VNZFVIeTgKLS0tIFhONzNXOXJoUjhOVFYrZWRPeEZJ\ncnpvblRDMDBKbXJjL2JpVUEwZ2NaRTQKNGtFm9ObnEPUHKKsTJaaALHsqFLPr5oO\nlCYIucEMFOYkM7o5wJCtLs5fsigQT6pAkeI3+N/rSz1hhDWuBB+PrQ==\n-----END AGE ENCRYPTED FILE-----\n", | ||
| 11 | "recipient": "age1u6xegt79rarmyz8qy4pl7jh9lh90vx8fg0frmh4u2mzam7zydq4s4agz4e" | ||
| 12 | } | ||
| 13 | ], | ||
| 14 | "lastmodified": "2026-09-27T10:18:59Z", | ||
| 15 | "mac": "ENC[AES256_GCM,data:BIHCMFB0oMcaByiALqgTaKBd1cNJZlFu3FnB7U0oTtw3Q65mFqrsLsphesuPxZxtD8eAdubT/YIC2rZ5ZCAZz/9eM1nt8tvBkO6ZGXmHeWUGlTpA7K2EAEK4D+8Bo8Xgf8afaTCmbrfKjn64iNQjUrmv8NMoY2Od8sYfIfRdYSs=,iv:d/Jt+ub2VcnJd9n7qwO6/j044D1fNtAmEQtZQrCNeEg=,tag:R7TPkPXyVV5UDsl9x1pboA==,type:str]", | ||
| 16 | "version": "3.13.3" | ||
| 17 | } | ||
| 18 | } | ||
