diff options
| author | Kleidi Bujari <mail@4kb.net> | 2024-12-17 23:03:27 -0500 |
|---|---|---|
| committer | Kleidi Bujari <mail@4kb.net> | 2024-12-17 23:03:27 -0500 |
| commit | eb13a9a552f9e50a66faba985521ba8e3483c447 (patch) | |
| tree | 209193a91b0db20fb1bb30007e72e321f0293696 /machines/xnet/net | |
| parent | f5ed731abbc38d765333b005b9815a5f6d3e59c2 (diff) | |
| download | depot-eb13a9a552f9e50a66faba985521ba8e3483c447.tar.gz depot-eb13a9a552f9e50a66faba985521ba8e3483c447.tar.bz2 depot-eb13a9a552f9e50a66faba985521ba8e3483c447.zip | |
Push configuration out of flake
Projects are not necessarily all exported by the system flake, and
should freely support other derivations. The new "mod" directory will be
used for most projects, and it can be imported by machine
configurations.
That said, the tooling around flakes is pretty good and will still be
used until the dependency is lessened.
Diffstat (limited to 'machines/xnet/net')
| -rw-r--r-- | machines/xnet/net/default.nix | 44 | ||||
| -rw-r--r-- | machines/xnet/net/sshd.nix | 46 |
2 files changed, 90 insertions, 0 deletions
diff --git a/machines/xnet/net/default.nix b/machines/xnet/net/default.nix new file mode 100644 index 0000000..2255f53 --- /dev/null +++ b/machines/xnet/net/default.nix @@ -0,0 +1,44 @@ +{ config, lib, ... }: +let + cfg = config.xnet.net; + inherit (lib) mkOption mkIf types; + prefix = "10.26.4"; +in +{ + imports = [ + ./sshd.nix + ]; + + options.xnet.net = { + interface = mkOption { + type = types.str; + default = ""; + description = "Network interface connecting to xnet."; + }; + + addr = mkOption { + type = types.ints.between 0 255; + description = "Final octet for xnet address."; + example = 4; + }; + }; + + # TODO: + # - Add assertion that each address is only used once across config + # - Add each host to each other hosts dns configuration + config = mkIf (builtins.stringLength cfg.interface > 0) { + networking.vlans = { + "${cfg.interface}.4" = { + inherit (cfg) interface; + id = 4; + }; + }; + + networking.interfaces = { + "${cfg.interface}.4".ipv4.addresses = [{ + address = "${prefix}.${toString cfg.addr}"; + prefixLength = 24; + }]; + }; + }; +} diff --git a/machines/xnet/net/sshd.nix b/machines/xnet/net/sshd.nix new file mode 100644 index 0000000..ef225db --- /dev/null +++ b/machines/xnet/net/sshd.nix @@ -0,0 +1,46 @@ +{ config, lib, ... }: +let + cfg = config.xnet.net.sshd; + inherit (lib) mkOption mkIf types; +in +{ + options.xnet.net.sshd = { + enable = mkOption { + type = types.bool; + default = false; + description = "Enable hardened SSH service."; + }; + }; + + config = mkIf cfg.enable { + services.openssh = { + enable = true; + startWhenNeeded = true; + openFirewall = true; + hostKeys = [{ + path = "/persist/certs/ssh/ssh_host_ed25519_key"; + type = "ed25519"; + }]; + settings = { + UsePAM = true; + X11Forwarding = false; + PermitRootLogin = "no"; + PasswordAuthentication = false; + Ciphers = [ "chacha20-poly1305@openssh.com" ]; + Macs = [ "hmac-sha2-512-etm@openssh.com" ]; + KexAlgorithms = [ "curve25519-sha256@libssh.org" ]; + }; + sftpServerExecutable = "internal-sftp"; + sftpFlags = [ "-f AUTHPRIV" "-l INFO" ]; + extraConfig = + let + pubkeyTypes = lib.strings.concatStringsSep "," [ + "sk-ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519" + ]; + in + "PubkeyAcceptedKeyTypes ${pubkeyTypes}"; + }; + }; +} |
