summaryrefslogtreecommitdiffstats
path: root/makefu/1systems/shoney.nix
blob: 1fe8871d2a2cf5a2a576e9ce8e0f1a71cf7535bf (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
{ config, pkgs, ... }:
let
  tinc-siem-ip = "10.8.10.1";

  ip     = "64.137.234.215";
  alt-ip = "64.137.234.210";
  extra-ip = "64.137.234.114"; #currently unused
  gw = "64.137.234.1";
in {
  imports = [
    ../.
    ../2configs/save-diskspace.nix
    ../2configs/hw/CAC.nix
    ../2configs/fs/CAC-CentOS-7-64bit.nix
  ];



  services.tinc.networks.siem.name = "sjump";

  krebs = {
    enable = true;
    retiolum.enable = true;
    build.host = config.krebs.hosts.shoney;
    nginx.enable = true;
    tinc_graphs = {
      enable = true;
      network = "siem";
      hostsPath = "/etc/tinc/siem/hosts";
      nginx = {
        enable = true;
        # TODO: remove hard-coded hostname
        complete = {
          listen = [ "${tinc-siem-ip}:80" ];
          server-names = [ "graphs.siem" ];
        };
      };
    };
  };
  networking =  {
    interfaces.enp2s1.ip4 = [
      { address = ip; prefixLength = 24; }
      { address = alt-ip; prefixLength = 24; }
    ];

    defaultGateway = gw;
    nameservers = [ "8.8.8.8" ];
    firewall = {
      trustedInterfaces = [ "tinc.siem" ];
      allowedUDPPorts = [ 655 1655 ];
      allowedTCPPorts = [ 655 1655 ];
    };
  };
}