From 3ccc7e784a0ed5b19910ab856f6d9774a6f27956 Mon Sep 17 00:00:00 2001 From: Kleidi Bujari Date: Sat, 23 Nov 2024 16:36:43 -0500 Subject: Initial scaffolding and layout Set up the modules of the flake. At this time, the flake is split into modules and machines. Considering that additional top-level sections -- such as packages and shells -- will also be added, it might make sense to keep all nix related things in one top-level directory, alongside the flake.nix file. This is all under the assumption that later amendments to the project will introduce other tech, such as terraform. --- modules/xnet/net/default.nix | 69 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 69 insertions(+) create mode 100644 modules/xnet/net/default.nix (limited to 'modules/xnet/net/default.nix') diff --git a/modules/xnet/net/default.nix b/modules/xnet/net/default.nix new file mode 100644 index 0000000..143f189 --- /dev/null +++ b/modules/xnet/net/default.nix @@ -0,0 +1,69 @@ +{ config, lib, ... }: +let + cfg = config.xnet.net; + inherit (lib) mkOption mkIf types; + prefix = "10.26.4"; +in +{ + options.xnet.net = { + interface = mkOption { + type = types.str; + default = ""; + description = "Network interface connecting to xnet."; + }; + + addr = mkOption { + type = types.ints.between 0 255; + description = "Final octet for xnet address."; + example = 4; + }; + + sshd = mkOption { + type = types.bool; + default = false; + description = "Enable hardened SSH service."; + }; + }; + + # TODO: + # - Add assertion that each address is only used once across config + # - Add each host to each other hosts dns configuration + config = mkIf (builtins.stringLength cfg.interface > 0) { + networking.vlans = { + "${cfg.interface}.4" = { + inherit (cfg) interface; + id = 4; + }; + }; + + networking.interfaces = { + "${cfg.interface}.4".ipv4.addresses = [{ + address = "${prefix}.${toString cfg.addr}"; + prefixLength = 24; + }]; + }; + + services.openssh = { + enable = cfg.sshd; + startWhenNeeded = true; + settings = { + X11Forwarding = false; + UsePAM = false; + PermitRootLogin = "prohibit-password"; + }; + extraConfig = + let + p = [ + "sk-ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519-cert-v01@openssh.com" + "ssh-ed25519" + ]; + in + "PubkeyAcceptedKeyTypes ${lib.strings.concatStringsSep "," p}"; + hostKeys = [{ + path = "/certs/ssh/ssh_host_ed25519_key"; + type = "ed25519"; + }]; + }; + }; +} -- cgit v1.3.1