home-manager: update
[julm/julm-nix.git] / hosts / oignon / networking.nix
index cc308e31806ae0485565e73da1f19ff8f1ae74e1..281efebcd54ad48965264fab8a740efa9bcbceaa 100644 (file)
@@ -2,17 +2,29 @@
 {
   imports = [
     ../../nixos/profiles/dnscrypt-proxy2.nix
-    ../../nixos/profiles/wireguard/wg-intra.nix
     ../../nixos/profiles/networking/ssh.nix
     ../../nixos/profiles/networking/wifi.nix
-    ../../nixos/profiles/openvpn/calyx.nix
-    ./wireguard.nix
+    #../../nixos/profiles/openvpn/calyx.nix
     networking/nftables.nix
   ];
   install.substituteOnDestination = false;
   #networking.domain = "sourcephile.fr";
   networking.useDHCP = false;
 
+  services.tor = {
+    settings = {
+      HashedControlPassword = lib.readFile tor/HashedControlPassword.clear;
+      # https://metrics.torproject.org/rs.html#search/flag:exit%20country:be%20running:true
+      # https://nusenu.github.io/OrNetStats/w/relay/58B81035FC28AACA8F0E85E46C8EBAD7FCFA8404.html
+      MapAddress = [
+        "*.gcp.cloud.es.io *.gcp.cloud.es.io.58B81035FC28AACA8F0E85E46C8EBAD7FCFA8404.exit"
+        "*.redbee.live         *.redbee.live.58B81035FC28AACA8F0E85E46C8EBAD7FCFA8404.exit"
+        "*.rtbf.be                 *.rtbf.be.58B81035FC28AACA8F0E85E46C8EBAD7FCFA8404.exit"
+      ];
+      StrictNodes = true;
+    };
+  };
+
   networking.nftables.ruleset = lib.mkAfter ''
     table inet filter {
       chain input {
@@ -69,8 +81,8 @@
   };
 
   environment.systemPackages = [
-    pkgs.iw
     pkgs.modem-manager-gui
+    #pkgs.tor-ctrl # Not packaged yet
   ];
 
   systemd.services.sshd.serviceConfig.LoadCredentialEncrypted = [