summaryrefslogtreecommitdiff
path: root/modules/xnet/net
diff options
context:
space:
mode:
Diffstat (limited to 'modules/xnet/net')
-rw-r--r--modules/xnet/net/default.nix44
-rw-r--r--modules/xnet/net/sshd.nix46
2 files changed, 0 insertions, 90 deletions
diff --git a/modules/xnet/net/default.nix b/modules/xnet/net/default.nix
deleted file mode 100644
index 2255f53..0000000
--- a/modules/xnet/net/default.nix
+++ /dev/null
@@ -1,44 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.xnet.net;
- inherit (lib) mkOption mkIf types;
- prefix = "10.26.4";
-in
-{
- imports = [
- ./sshd.nix
- ];
-
- options.xnet.net = {
- interface = mkOption {
- type = types.str;
- default = "";
- description = "Network interface connecting to xnet.";
- };
-
- addr = mkOption {
- type = types.ints.between 0 255;
- description = "Final octet for xnet address.";
- example = 4;
- };
- };
-
- # TODO:
- # - Add assertion that each address is only used once across config
- # - Add each host to each other hosts dns configuration
- config = mkIf (builtins.stringLength cfg.interface > 0) {
- networking.vlans = {
- "${cfg.interface}.4" = {
- inherit (cfg) interface;
- id = 4;
- };
- };
-
- networking.interfaces = {
- "${cfg.interface}.4".ipv4.addresses = [{
- address = "${prefix}.${toString cfg.addr}";
- prefixLength = 24;
- }];
- };
- };
-}
diff --git a/modules/xnet/net/sshd.nix b/modules/xnet/net/sshd.nix
deleted file mode 100644
index ef225db..0000000
--- a/modules/xnet/net/sshd.nix
+++ /dev/null
@@ -1,46 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.xnet.net.sshd;
- inherit (lib) mkOption mkIf types;
-in
-{
- options.xnet.net.sshd = {
- enable = mkOption {
- type = types.bool;
- default = false;
- description = "Enable hardened SSH service.";
- };
- };
-
- config = mkIf cfg.enable {
- services.openssh = {
- enable = true;
- startWhenNeeded = true;
- openFirewall = true;
- hostKeys = [{
- path = "/persist/certs/ssh/ssh_host_ed25519_key";
- type = "ed25519";
- }];
- settings = {
- UsePAM = true;
- X11Forwarding = false;
- PermitRootLogin = "no";
- PasswordAuthentication = false;
- Ciphers = [ "chacha20-poly1305@openssh.com" ];
- Macs = [ "hmac-sha2-512-etm@openssh.com" ];
- KexAlgorithms = [ "curve25519-sha256@libssh.org" ];
- };
- sftpServerExecutable = "internal-sftp";
- sftpFlags = [ "-f AUTHPRIV" "-l INFO" ];
- extraConfig =
- let
- pubkeyTypes = lib.strings.concatStringsSep "," [
- "sk-ssh-ed25519-cert-v01@openssh.com"
- "ssh-ed25519-cert-v01@openssh.com"
- "ssh-ed25519"
- ];
- in
- "PubkeyAcceptedKeyTypes ${pubkeyTypes}";
- };
- };
-}