depot/cluster/services/wireguard/default.nix

70 lines
1.7 KiB
Nix
Raw Permalink Normal View History

{ config, depot, lib, ... }:
2022-08-03 23:53:45 +03:00
let
2023-03-07 02:26:07 +02:00
inherit (depot.config) hours;
2022-08-03 23:53:45 +03:00
meshNet = rec {
netAddr = "10.1.1.0";
prefix = 24;
cidr = "${netAddr}/${toString prefix}";
};
2023-03-07 02:26:07 +02:00
getExtAddr = host: host.interfaces.primary.addrPublic;
2022-08-03 23:53:45 +03:00
in
{
vars = {
mesh = lib.genAttrs config.services.wireguard.nodes.mesh (node: config.hostLinks.${node}.mesh.extra);
inherit meshNet;
};
hostLinks = {
checkmate.mesh = {
2023-03-07 02:26:07 +02:00
ipv4 = getExtAddr hours.checkmate;
extra = {
meshIp = "10.1.1.32";
inherit meshNet;
pubKey = "fZMB9CDCWyBxPnsugo3Uxm/TIDP3VX54uFoaoC0bP3U=";
privKeyFile = ./mesh-keys/checkmate.age;
extraRoutes = [];
};
};
thunderskin.mesh = {
2023-03-20 20:52:07 +02:00
ipv4 = getExtAddr hours.thunderskin;
extra = {
meshIp = "10.1.1.4";
inherit meshNet;
pubKey = "xvSsFvCVK8h2wThZJ7E5K0fniTBIEIYOblkKIf3Cwy0=";
privKeyFile = ./mesh-keys/thunderskin.age;
extraRoutes = [];
};
};
VEGAS.mesh = {
2023-03-07 02:26:07 +02:00
ipv4 = getExtAddr hours.VEGAS;
2022-08-03 23:53:45 +03:00
extra = {
meshIp = "10.1.1.5";
inherit meshNet;
pubKey = "NpeB8O4erGTas1pz6Pt7qtY9k45YV6tcZmvvA4qXoFk=";
privKeyFile = ./mesh-keys/VEGAS.age;
2023-03-07 02:26:07 +02:00
extraRoutes = [ "${hours.VEGAS.interfaces.vstub.addr}/32" "10.10.0.0/16" ];
2022-08-03 23:53:45 +03:00
};
};
prophet.mesh = {
2023-03-07 02:26:07 +02:00
ipv4 = getExtAddr hours.prophet;
2022-08-03 23:53:45 +03:00
extra = {
meshIp = "10.1.1.9";
inherit meshNet;
pubKey = "MMZAbRtNE+gsLm6DJy9VN/Y39E69oAZnvOcFZPUAVDc=";
privKeyFile = ./mesh-keys/prophet.age;
extraRoutes = [];
2022-08-03 23:53:45 +03:00
};
};
};
services.wireguard = {
nodes = {
2023-03-20 20:52:07 +02:00
mesh = [ "checkmate" "thunderskin" "VEGAS" "prophet" ];
2022-08-03 23:53:45 +03:00
};
nixos = {
mesh = ./mesh.nix;
};
};
}