summaryrefslogtreecommitdiff
path: root/modules/xnet/net/default.nix
diff options
context:
space:
mode:
Diffstat (limited to 'modules/xnet/net/default.nix')
-rw-r--r--modules/xnet/net/default.nix69
1 files changed, 69 insertions, 0 deletions
diff --git a/modules/xnet/net/default.nix b/modules/xnet/net/default.nix
new file mode 100644
index 0000000..143f189
--- /dev/null
+++ b/modules/xnet/net/default.nix
@@ -0,0 +1,69 @@
+{ config, lib, ... }:
+let
+ cfg = config.xnet.net;
+ inherit (lib) mkOption mkIf types;
+ prefix = "10.26.4";
+in
+{
+ options.xnet.net = {
+ interface = mkOption {
+ type = types.str;
+ default = "";
+ description = "Network interface connecting to xnet.";
+ };
+
+ addr = mkOption {
+ type = types.ints.between 0 255;
+ description = "Final octet for xnet address.";
+ example = 4;
+ };
+
+ sshd = mkOption {
+ type = types.bool;
+ default = false;
+ description = "Enable hardened SSH service.";
+ };
+ };
+
+ # TODO:
+ # - Add assertion that each address is only used once across config
+ # - Add each host to each other hosts dns configuration
+ config = mkIf (builtins.stringLength cfg.interface > 0) {
+ networking.vlans = {
+ "${cfg.interface}.4" = {
+ inherit (cfg) interface;
+ id = 4;
+ };
+ };
+
+ networking.interfaces = {
+ "${cfg.interface}.4".ipv4.addresses = [{
+ address = "${prefix}.${toString cfg.addr}";
+ prefixLength = 24;
+ }];
+ };
+
+ services.openssh = {
+ enable = cfg.sshd;
+ startWhenNeeded = true;
+ settings = {
+ X11Forwarding = false;
+ UsePAM = false;
+ PermitRootLogin = "prohibit-password";
+ };
+ extraConfig =
+ let
+ p = [
+ "sk-ssh-ed25519-cert-v01@openssh.com"
+ "ssh-ed25519-cert-v01@openssh.com"
+ "ssh-ed25519"
+ ];
+ in
+ "PubkeyAcceptedKeyTypes ${lib.strings.concatStringsSep "," p}";
+ hostKeys = [{
+ path = "/certs/ssh/ssh_host_ed25519_key";
+ type = "ed25519";
+ }];
+ };
+ };
+}