summaryrefslogtreecommitdiff
path: root/modules/yggdrasil-wg/default.nix
diff options
context:
space:
mode:
Diffstat (limited to 'modules/yggdrasil-wg/default.nix')
-rw-r--r--modules/yggdrasil-wg/default.nix69
1 files changed, 69 insertions, 0 deletions
diff --git a/modules/yggdrasil-wg/default.nix b/modules/yggdrasil-wg/default.nix
new file mode 100644
index 00000000..08665e33
--- /dev/null
+++ b/modules/yggdrasil-wg/default.nix
@@ -0,0 +1,69 @@
1{ config, hostName, lib, ... }:
2
3with lib;
4
5let
6 listenPort = 51820;
7 subnet = "2a03:4000:52:ada:1";
8
9 links = [
10 { from = "vidhar";
11 to = "surtr";
12 endpointHost = "surtr.yggdrasil.li";
13 persistentKeepalive = 25;
14 dynamicEndpointRefreshSeconds = 86400;
15 }
16 ];
17 hostIPs = {
18 surtr = ["${subnet}::/32"];
19 vidhar = ["${subnet}:1::/32"];
20 };
21
22 mkPublicKeyPath = host: ./hosts + "/${host}.pub";
23 mkPrivateKeyPath = host: ./hosts + "/${host}.priv";
24
25 publicKeyPath = mkPublicKeyPath hostName;
26 privateKeyPath = mkPrivateKeyPath hostName;
27 inNetwork = pathExists privateKeyPath && pathExists publicKeyPath;
28 hostLinks = filter ({ from, to, ... }: from == hostName || to == hostName) links;
29 linkToPeer = opts@{from, to, ...}:
30 let
31 other = if from == hostName then to else from;
32 in {
33 allowedIPs = hostIPs.${other};
34 publicKey = trim (readFile (mkPublicKeyPath other));
35 } // (optionalAttrs (from == hostName) (filterAttrs (n: _v: !(elem n ["from" "to" "endpointHost"])) opts // optionalAttrs (opts ? "endpointHost") { endpoint = "${opts.endpointHost}:${toString listenPort}"; }));
36
37 trim = str: if hasSuffix "\n" str then trim (removeSuffix "\n" str) else str;
38 stripSubnet = addr: let matchRes = builtins.match "^(.*)/[0-9]+$" addr; in if matchRes == null then addr else elemAt matchRes 0;
39in {
40 config = {
41 assertions = [
42 { assertion = inNetwork || !(pathExists privateKeyPath || pathExists publicKeyPath);
43 message = "yggdrasil-wg: Either both public and private keys must exist or neither.";
44 }
45 { assertion = !inNetwork || (hostIPs ? "${hostName}");
46 message = "yggdrasil-wg: Entry in hostIPs must exist.";
47 }
48 ] ++ map ({from, to, ...}: let other = if from == hostName then to else from; in { assertion = pathExists (mkPublicKeyPath other); message = "yggdrasil-wg: This host (${hostName}) has a link with ‘${other}’, but no public key is available for ‘${other}’."; }) hostLinks;
49
50 networking.wireguard.interfaces = mkIf inNetwork {
51 yggdrasil = {
52 allowedIPsAsRoutes = true;
53 inherit listenPort;
54 ips = hostIPs.${hostName};
55 peers = map linkToPeer hostLinks;
56 privateKeyFile = config.sops.secrets."yggdrasil-wg.priv".path;
57 };
58 };
59
60 sops.secrets = mkIf (pathExists privateKeyPath) {
61 "yggdrasil-wg.priv" = {
62 format = "binary";
63 sopsFile = privateKeyPath;
64 };
65 };
66
67 networking.hosts = mkIf inNetwork (listToAttrs (concatMap ({name, value}: map (ip: nameValuePair (stripSubnet ip) ["${name}.yggdrasil"]) value) (mapAttrsToList nameValuePair hostIPs)));
68 };
69}