Benjamin Bädorf
67cc815acc
All checks were successful
continuous-integration/drone/push Build is passing
This was just failing on autostart, often because the network was not available yet.
49 lines
1.1 KiB
Nix
49 lines
1.1 KiB
Nix
{
|
|
config,
|
|
pkgs,
|
|
lib,
|
|
self,
|
|
...
|
|
}:
|
|
with lib; let
|
|
psCfg = config.pub-solar;
|
|
xdg = config.home-manager.users."${psCfg.user.name}".xdg;
|
|
in {
|
|
age.secrets."cat-test.ovpn" = {
|
|
file = "${self}/secrets/cat-test.ovpn";
|
|
mode = "700";
|
|
owner = psCfg.user.name;
|
|
};
|
|
|
|
age.secrets.".fwknoprc" = {
|
|
file = "${self}/secrets/.fwknoprc";
|
|
mode = "600";
|
|
};
|
|
|
|
services.openvpn.servers = {
|
|
catVPN = {
|
|
autoStart = false;
|
|
config = ''config ${config.age.secrets."cat-test.ovpn".path}'';
|
|
};
|
|
};
|
|
|
|
systemd.services.openvpn-catVPN.serviceConfig.ExecStartPre = "${pkgs.fwknop}/bin/fwknop --rc-file=${config.age.secrets.".fwknoprc".path} --no-save-args --no-home-dir --save-args-file=/dev/null -n hetzner_test_cloud --wget-cmd=${pkgs.wget}/bin/wget";
|
|
|
|
home-manager = pkgs.lib.setAttrByPath ["users" psCfg.user.name] {
|
|
programs.ssh = {
|
|
matchBlocks = {
|
|
"salt.base.test" = {
|
|
hostname = "10.0.0.2";
|
|
user = "bbaedorf";
|
|
};
|
|
|
|
"gateway.base.test" = {
|
|
hostname = "10.0.0.3";
|
|
user = "root";
|
|
proxyJump = "root@salt.base.test";
|
|
};
|
|
};
|
|
};
|
|
};
|
|
}
|