diff options
Diffstat (limited to 'modules/xnet/net/default.nix')
| -rw-r--r-- | modules/xnet/net/default.nix | 69 |
1 files changed, 69 insertions, 0 deletions
diff --git a/modules/xnet/net/default.nix b/modules/xnet/net/default.nix new file mode 100644 index 0000000..143f189 --- /dev/null +++ b/modules/xnet/net/default.nix @@ -0,0 +1,69 @@ +{ config, lib, ... }: +let + cfg = config.xnet.net; + inherit (lib) mkOption mkIf types; + prefix = "10.26.4"; +in +{ + options.xnet.net = { + interface = mkOption { + type = types.str; + default = ""; + description = "Network interface connecting to xnet."; + }; + + addr = mkOption { + type = types.ints.between 0 255; + description = "Final octet for xnet address."; + example = 4; + }; + + sshd = mkOption { + type = types.bool; + default = false; + description = "Enable hardened SSH service."; + }; + }; + + # TODO: + # - Add assertion that each address is only used once across config + # - Add each host to each other hosts dns configuration + config = mkIf (builtins.stringLength cfg.interface > 0) { + networking.vlans = { + "${cfg.interface}.4" = { + inherit (cfg) interface; + id = 4; + }; + }; + + networking.interfaces = { + "${cfg.interface}.4".ipv4.addresses = [{ + address = "${prefix}.${toString cfg.addr}"; + prefixLength = 24; + }]; + }; + + services.openssh = { + enable = cfg.sshd; + startWhenNeeded = true; + settings = { + X11Forwarding = false; + UsePAM = false; + PermitRootLogin = "prohibit-password"; + }; + extraConfig = + let + p = [ + "sk-ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519" + ]; + in + "PubkeyAcceptedKeyTypes ${lib.strings.concatStringsSep "," p}"; + hostKeys = [{ + path = "/certs/ssh/ssh_host_ed25519_key"; + type = "ed25519"; + }]; + }; + }; +} |
