diff options
Diffstat (limited to 'modules')
| -rw-r--r-- | modules/xnet/default.nix | 1 | ||||
| -rw-r--r-- | modules/xnet/net/default.nix | 128 | ||||
| -rw-r--r-- | modules/xnet/net/dns.nix | 38 | ||||
| -rw-r--r-- | modules/xnet/net/sshd.nix | 46 |
4 files changed, 0 insertions, 213 deletions
diff --git a/modules/xnet/default.nix b/modules/xnet/default.nix index d80952a..28edf60 100644 --- a/modules/xnet/default.nix +++ b/modules/xnet/default.nix @@ -31,7 +31,6 @@ in ./disk.nix ./nginx.nix ./persist.nix - # ./net ./gitserver # ./monitoring ]; diff --git a/modules/xnet/net/default.nix b/modules/xnet/net/default.nix deleted file mode 100644 index 7242855..0000000 --- a/modules/xnet/net/default.nix +++ /dev/null @@ -1,128 +0,0 @@ -{ config, lib, ... }: -let - cfg = config.xnet.net; - - inherit (builtins) - attrNames - attrValues - map - length - ; - - inherit (lib) - concatLines - genAttrs - mapAttrsToList - mergeAttrsList - mkOption - mkIf - types - ; - - # Networks are logical groupings of hosts wired together. This is - # accomplished using VLANS on the same layer 2 network. - # - # Hosts can hard code their spot on a network here. This module aims - # to generate network information for a host using this set of facts. - # The module should gracefully fall back to defaults if a given fact - # is not specified for the host consuming the module. - # - # A host will have it's /etc/hosts populated with all other hosts in - # a network to avoid a dynamic DNS server. - networks = { - - # Open network for xnet hosts - plaza = { - mask = 24; - vlan = 88; - hosts = { - t1 = "10.88.88.1"; - radon = "10.88.88.2"; - iridium = "10.88.88.3"; - }; - }; - - # Reserved network for kubernetes related nodes. A distinct network - # is created here for hosts that provide resources to workers. - # Generally, nodes on this network are spawned dynamically and are - # not a part of this NixOS config directly, although they may boot - # from assets served from a node here. - kubenet = { - mask = 24; - vlan = 42; - hosts = { - iridium = "10.88.42.254"; - }; - }; - }; -in -{ - imports = [ - ./sshd.nix - ./dns.nix - ]; - - options.xnet.net = { - join = mkOption { - type = types.listOf (types.enum (attrNames networks)); - default = [ ]; - description = "Available networks."; - }; - - interface = mkOption { - type = types.str; - default = ""; - description = "Network interface connecting to xnet."; - }; - }; - - config = mkIf ((length cfg.join) > 0) { - # networkd will handle this - networking.useDHCP = false; - - systemd.network = - let - name = config.networking.hostName; - - genConfig = net: { - netdevs."${toString networks.${net}.vlan}-${net}" = { - netdevConfig.Kind = "vlan"; - netdevConfig.Name = net; - vlanConfig.Id = networks.${net}.vlan; - }; - - networks."10-${cfg.interface}" = { - matchConfig.Name = cfg.interface; - vlan = cfg.join; - - # Accept DHCP on physical interface - DHCP = "ipv4"; - - # Network is up when xnet physical interface gets carrier - linkConfig.RequiredForOnline = "carrier"; - - # Allow resolved to resolve mDNS - networkConfig.MulticastDNS = true; - }; - - networks."${toString networks.${net}.vlan}-${net}" = { - matchConfig.Name = net; - - # Set up address for known host - address = [ "${networks.${net}.hosts.${name}}/${toString networks.${net}.mask}" ]; - }; - }; - - values = attrValues (genAttrs cfg.join genConfig); - in - { enable = true; } // mergeAttrsList values; - - networking.extraHosts = - let - genHosts = net: concatLines - (mapAttrsToList (name: value: "${value} ${name} ${name}.${net}.4kb.net") - networks.${net}.hosts); - in - concatLines (map (net: genHosts net) cfg.join); - }; -} diff --git a/modules/xnet/net/dns.nix b/modules/xnet/net/dns.nix deleted file mode 100644 index 0632fa9..0000000 --- a/modules/xnet/net/dns.nix +++ /dev/null @@ -1,38 +0,0 @@ -{ lib, ... }: -let - inherit (lib) - mkDefault - ; - - quad9 = [ - "9.9.9.9#dns.quad9.net" - "149.112.112.112#dns.quad9.net" - "2620:fe::fe#dns.quad9.net" - "2620:fe::9#dns.quad9.net" - ]; - - cloudflare = [ - "1.1.1.1#one.one.one.one" - "1.0.0.1#one.one.one.one" - "2606:4700:4700::1111#one.one.one.one" - "2606:4700:4700::1001#one.one.one.one" - ]; -in -{ - - networking.nameservers = mkDefault quad9; - - services.resolved = { - enable = true; - llmnr = "false"; - dnssec = "false"; - dnsovertls = mkDefault "opportunistic"; - fallbackDns = quad9 ++ cloudflare; - extraConfig = '' - MulticastDNS=yes - ''; - }; - - # Allow mDNS resolution - networking.firewall.allowedTCPPorts = [ 5353 ]; -} diff --git a/modules/xnet/net/sshd.nix b/modules/xnet/net/sshd.nix deleted file mode 100644 index 9d7976e..0000000 --- a/modules/xnet/net/sshd.nix +++ /dev/null @@ -1,46 +0,0 @@ -{ config, lib, ... }: -let - cfg = config.xnet.net.sshd; - inherit (lib) mkOption mkIf types; -in -{ - options.xnet.net.sshd = { - enable = mkOption { - type = types.bool; - default = false; - description = "Enable hardened SSH service."; - }; - }; - - config = mkIf cfg.enable { - services.openssh = { - enable = true; - startWhenNeeded = true; - openFirewall = true; - hostKeys = [{ - path = "/persist/certs/ssh/ssh_host_ed25519_key"; - type = "ed25519"; - }]; - settings = { - UsePAM = false; - X11Forwarding = false; - PermitRootLogin = "prohibit-password"; - PasswordAuthentication = false; - Ciphers = [ "chacha20-poly1305@openssh.com" ]; - Macs = [ "hmac-sha2-512-etm@openssh.com" ]; - KexAlgorithms = [ "curve25519-sha256@libssh.org" ]; - }; - sftpServerExecutable = "internal-sftp"; - sftpFlags = [ "-f AUTHPRIV" "-l INFO" ]; - extraConfig = - let - pubkeyTypes = lib.strings.concatStringsSep "," [ - "sk-ssh-ed25519-cert-v01@openssh.com" - "ssh-ed25519-cert-v01@openssh.com" - "ssh-ed25519" - ]; - in - "PubkeyAcceptedKeyTypes ${pubkeyTypes}"; - }; - }; -} |
