1 { pkgs, lib, config, inputs, hostName, ... }:
3 domain = "sourcephile.fr";
4 port = toString config.services.nebula.networks.${domain}.listen.port;
5 iface = config.services.nebula.networks.${domain}.tun.device;
9 environment.systemPackages = with pkgs; [ nebula ];
10 systemd.services."nebula@${domain}" = {
11 stopIfChanged = false;
12 serviceConfig.LoadCredentialEncrypted = [
13 "${hostName}.key:${builtins.path { path = inputs.self + "/hosts/${hostName}/nebula/${hostName}.key.cred"; }}"
16 install.target = lib.mkDefault "\"\${NIXOS_TARGET:-root@${config.networking.hostName}.sp}\"";
18 "${IPv4Prefix}.1" = [ "mermet.sp" ];
19 "${IPv4Prefix}.2" = [ "losurdo.sp" ];
20 "${IPv4Prefix}.3" = [ "oignon.sp" ];
21 "${IPv4Prefix}.4" = [ "patate.sp" ];
22 "${IPv4Prefix}.5" = [ "carotte.sp" ];
23 "${IPv4Prefix}.6" = [ "aubergine.sp" ];
24 "${IPv4Prefix}.7" = [ "courge.sp" ];
25 "${IPv4Prefix}.8" = [ "blackberry.sp" ];
27 services.nebula.networks.${domain} = {
29 ca = lib.mkDefault (./. + "/${domain}/ca.crt");
30 cert = lib.mkDefault (builtins.path { path = inputs.self + "/share/nebula/${domain}/${hostName}.crt"; });
31 key = "/run/credentials/nebula@${domain}.service/${hostName}.key";
32 listen.host = lib.mkDefault "0.0.0.0";
33 tun.device = lib.mkDefault "neb-sourcephile";
35 "${IPv4Prefix}.1" = [ "mermet.${domain}:10001" ];
36 "${IPv4Prefix}.2" = [ "losurdo.${domain}:10002" ];
47 { port = "any"; proto = "icmp"; groups = [ "sourcephile" "intra" ]; }
50 { port = "any"; proto = "icmp"; groups = [ "sourcephile" "intra" ]; }
58 default_timeout = "10m";
62 level = lib.mkDefault "info";
64 pki.disconnect_invalid = true;
68 #cipher = "chachapoly";
72 listen = "127.0.0.1:8080";
74 namespace = "prometheusns";
77 message_metrics = false;
78 lighthouse_metrics = false;
83 networking.nftables.ruleset = ''
86 udp dport ${port} counter accept comment "Nebula ${domain}"
89 udp sport ${port} counter accept comment "Nebula ${domain}"
92 udp dport ${port} counter accept comment "Nebula ${domain}"
95 udp sport ${port} counter accept comment "Nebula ${domain}"
97 chain input-${iface} {
98 tcp dport ssh counter accept comment "SSH"
99 udp dport 60000-60100 counter accept comment "Mosh"
101 chain output-${iface} {
102 tcp dport ssh counter accept comment "SSH"
103 udp dport 60000-60100 counter accept comment "Mosh"
106 iifname ${iface} jump input-${iface}
107 iifname ${iface} log level warn prefix "input-${iface}: " counter drop
110 oifname ${iface} jump output-${iface}
111 oifname ${iface} log level warn prefix "output-${iface}: " counter drop
115 networking.networkmanager.unmanaged = [ iface ];
116 services.fail2ban.ignoreIP = [
117 "${IPv4Prefix}.1" # mermet.sp
118 "${IPv4Prefix}.2" # losurdo.sp
119 "${IPv4Prefix}.3" # oignon.sp