2016-10-20 20:54:38 +02:00
|
|
|
with import <stockholm/lib>;
|
2017-10-03 18:40:44 +02:00
|
|
|
{ config, pkgs, ... }:
|
2015-07-24 11:22:21 +02:00
|
|
|
let
|
|
|
|
out = {
|
2016-07-20 10:06:04 +02:00
|
|
|
options.krebs.tinc = api;
|
|
|
|
config = imp;
|
2015-07-24 11:22:21 +02:00
|
|
|
};
|
|
|
|
|
2016-07-20 10:06:04 +02:00
|
|
|
api = mkOption {
|
|
|
|
default = {};
|
|
|
|
description = ''
|
|
|
|
define a tinc network
|
|
|
|
'';
|
2017-10-03 18:40:44 +02:00
|
|
|
type = types.attrsOf (types.submodule (tinc: {
|
2016-07-26 14:02:04 +02:00
|
|
|
options = let
|
|
|
|
netname = tinc.config._module.args.name;
|
|
|
|
in {
|
2016-07-20 14:15:47 +02:00
|
|
|
|
2016-07-26 14:02:04 +02:00
|
|
|
enable = mkEnableOption "krebs.tinc.${netname}" // { default = true; };
|
2017-05-16 23:19:08 +02:00
|
|
|
enableLegacy = mkEnableOption "/etc/tinc/${netname}";
|
2016-07-20 14:15:47 +02:00
|
|
|
|
2017-05-16 22:03:42 +02:00
|
|
|
confDir = mkOption {
|
|
|
|
type = types.package;
|
|
|
|
default = pkgs.linkFarm "${netname}-etc-tinc"
|
|
|
|
(mapAttrsToList (name: path: { inherit name path; }) {
|
|
|
|
"hosts" = tinc.config.hostsPackage;
|
|
|
|
"tinc.conf" = pkgs.writeText "${netname}-tinc.conf" ''
|
|
|
|
Name = ${tinc.config.host.name}
|
|
|
|
Interface = ${netname}
|
2019-01-16 11:10:34 +01:00
|
|
|
Broadcast = no
|
2017-05-16 22:03:42 +02:00
|
|
|
${concatMapStrings (c: "ConnectTo = ${c}\n") tinc.config.connectTo}
|
2020-09-05 01:17:51 +02:00
|
|
|
${optionalString (tinc.config.privkey_ed25519 != null)
|
|
|
|
"Ed25519PrivateKeyFile = ${tinc.config.privkey_ed25519.path}"
|
|
|
|
}
|
2017-05-16 22:03:42 +02:00
|
|
|
PrivateKeyFile = ${tinc.config.privkey.path}
|
|
|
|
Port = ${toString tinc.config.host.nets.${netname}.tinc.port}
|
|
|
|
${tinc.config.extraConfig}
|
|
|
|
'';
|
|
|
|
"tinc-up" = pkgs.writeDash "${netname}-tinc-up" ''
|
|
|
|
${tinc.config.iproutePackage}/sbin/ip link set ${netname} up
|
|
|
|
${tinc.config.tincUp}
|
|
|
|
'';
|
|
|
|
});
|
|
|
|
};
|
|
|
|
|
2016-07-20 10:06:04 +02:00
|
|
|
host = mkOption {
|
|
|
|
type = types.host;
|
|
|
|
default = config.krebs.build.host;
|
|
|
|
};
|
|
|
|
|
|
|
|
netname = mkOption {
|
|
|
|
type = types.enum (attrNames tinc.config.host.nets);
|
2016-07-26 14:02:04 +02:00
|
|
|
default = netname;
|
2016-07-20 10:06:04 +02:00
|
|
|
description = ''
|
|
|
|
The tinc network name.
|
|
|
|
It is used to name the TUN device and to generate the default value for
|
|
|
|
<literal>config.krebs.tinc.retiolum.hosts</literal>.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
extraConfig = mkOption {
|
|
|
|
type = types.str;
|
|
|
|
default = "";
|
|
|
|
description = ''
|
|
|
|
Extra Configuration to be appended to tinc.conf
|
|
|
|
'';
|
|
|
|
};
|
2016-07-26 14:02:04 +02:00
|
|
|
tincUp = mkOption {
|
2020-01-14 20:39:30 +01:00
|
|
|
type = types.str;
|
2016-07-26 14:02:04 +02:00
|
|
|
default = let
|
|
|
|
net = tinc.config.host.nets.${netname};
|
|
|
|
iproute = tinc.config.iproutePackage;
|
|
|
|
in ''
|
|
|
|
${optionalString (net.ip4 != null) /* sh */ ''
|
|
|
|
${iproute}/sbin/ip -4 addr add ${net.ip4.addr} dev ${netname}
|
|
|
|
${iproute}/sbin/ip -4 route add ${net.ip4.prefix} dev ${netname}
|
|
|
|
''}
|
|
|
|
${optionalString (net.ip6 != null) /* sh */ ''
|
|
|
|
${iproute}/sbin/ip -6 addr add ${net.ip6.addr} dev ${netname}
|
|
|
|
${iproute}/sbin/ip -6 route add ${net.ip6.prefix} dev ${netname}
|
|
|
|
''}
|
2018-10-30 22:47:57 +01:00
|
|
|
${tinc.config.tincUpExtra}
|
2016-07-26 14:02:04 +02:00
|
|
|
'';
|
|
|
|
description = ''
|
|
|
|
tinc-up script to be used. Defaults to setting the
|
|
|
|
krebs.host.nets.<netname>.ip4 and ip6 for the new ips and
|
|
|
|
configures forwarding of the respecitive netmask as subnet.
|
|
|
|
'';
|
|
|
|
};
|
2016-07-20 10:06:04 +02:00
|
|
|
|
2018-10-30 22:47:57 +01:00
|
|
|
tincUpExtra = mkOption {
|
|
|
|
type = types.str;
|
|
|
|
default = "";
|
|
|
|
};
|
|
|
|
|
2016-07-20 10:06:04 +02:00
|
|
|
tincPackage = mkOption {
|
|
|
|
type = types.package;
|
|
|
|
default = pkgs.tinc;
|
|
|
|
description = "Tincd package to use.";
|
|
|
|
};
|
|
|
|
|
|
|
|
hosts = mkOption {
|
|
|
|
type = with types; attrsOf host;
|
|
|
|
default =
|
|
|
|
filterAttrs (_: h: hasAttr tinc.config.netname h.nets) config.krebs.hosts;
|
|
|
|
description = ''
|
2016-07-20 17:20:47 +02:00
|
|
|
Hosts to generate <literal>config.krebs.tinc.retiolum.hostsPackage</literal>.
|
2016-07-20 10:06:04 +02:00
|
|
|
Note that these hosts must have a network named
|
2016-07-20 17:20:47 +02:00
|
|
|
<literal>config.krebs.tinc.retiolum.netname</literal>.
|
2016-07-20 10:06:04 +02:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2016-10-27 22:04:21 +02:00
|
|
|
hostsArchive = mkOption {
|
|
|
|
type = types.package;
|
|
|
|
default = pkgs.runCommand "retiolum-hosts.tar.bz2" {} ''
|
2019-09-11 14:37:26 +02:00
|
|
|
cp \
|
|
|
|
--no-preserve=mode \
|
|
|
|
--recursive \
|
|
|
|
${tinc.config.hostsPackage} \
|
|
|
|
hosts
|
|
|
|
${pkgs.gnutar}/bin/tar -cjf $out hosts
|
2016-10-27 22:04:21 +02:00
|
|
|
'';
|
|
|
|
readOnly = true;
|
|
|
|
};
|
|
|
|
|
2016-07-20 10:06:04 +02:00
|
|
|
hostsPackage = mkOption {
|
|
|
|
type = types.package;
|
|
|
|
default = pkgs.stdenv.mkDerivation {
|
|
|
|
name = "${tinc.config.netname}-tinc-hosts";
|
|
|
|
phases = [ "installPhase" ];
|
|
|
|
installPhase = ''
|
|
|
|
mkdir $out
|
2017-10-03 18:40:44 +02:00
|
|
|
${concatStrings (mapAttrsToList (_: host: ''
|
2016-07-20 10:06:04 +02:00
|
|
|
echo ${shell.escape host.nets."${tinc.config.netname}".tinc.config} \
|
|
|
|
> $out/${shell.escape host.name}
|
|
|
|
'') tinc.config.hosts)}
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
description = ''
|
|
|
|
Package of tinc host configuration files. By default, a package will
|
|
|
|
be generated from <literal>config.krebs.${tinc.config.netname}.hosts</literal>. This
|
|
|
|
option's main purpose is to expose the generated hosts package to other
|
|
|
|
modules, like <literal>config.krebs.tinc_graphs</literal>. But it can
|
|
|
|
also be used to provide a custom hosts directory.
|
|
|
|
'';
|
|
|
|
example = literalExample ''
|
|
|
|
(pkgs.stdenv.mkDerivation {
|
|
|
|
name = "my-tinc-hosts";
|
|
|
|
src = /home/tv/my-tinc-hosts;
|
|
|
|
installPhase = "cp -R . $out";
|
|
|
|
})
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
iproutePackage = mkOption {
|
|
|
|
type = types.package;
|
|
|
|
default = pkgs.iproute;
|
|
|
|
description = "Iproute2 package to use.";
|
|
|
|
};
|
|
|
|
|
|
|
|
privkey = mkOption {
|
|
|
|
type = types.secret-file;
|
|
|
|
default = {
|
2020-08-04 22:22:43 +02:00
|
|
|
name = "${tinc.config.netname}.rsa_key.priv";
|
2016-07-20 10:06:04 +02:00
|
|
|
path = "${tinc.config.user.home}/tinc.rsa_key.priv";
|
|
|
|
owner = tinc.config.user;
|
|
|
|
source-path = toString <secrets> + "/${tinc.config.netname}.rsa_key.priv";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2020-09-05 01:17:51 +02:00
|
|
|
privkey_ed25519 = mkOption {
|
|
|
|
type = types.nullOr types.secret-file;
|
|
|
|
default =
|
|
|
|
if config.krebs.hosts.${tinc.config.host.name}.nets.${tinc.config.netname}.tinc.pubkey_ed25519 == null then null else {
|
|
|
|
name = "${tinc.config.netname}.ed25519_key.priv";
|
|
|
|
path = "${tinc.config.user.home}/tinc.ed25519_key.priv";
|
|
|
|
owner = tinc.config.user;
|
|
|
|
source-path = toString <secrets> + "/${tinc.config.netname}.ed25519_key.priv";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2016-07-20 10:06:04 +02:00
|
|
|
connectTo = mkOption {
|
|
|
|
type = types.listOf types.str;
|
2016-11-10 23:00:04 +01:00
|
|
|
${if tinc.config.netname == "retiolum" then "default" else null} = [
|
|
|
|
"gum"
|
|
|
|
"ni"
|
|
|
|
"prism"
|
|
|
|
];
|
2016-07-20 10:06:04 +02:00
|
|
|
description = ''
|
|
|
|
The list of hosts in the network which the client will try to connect
|
|
|
|
to. These hosts should have an 'Address' configured which points to a
|
|
|
|
routeable IPv4 or IPv6 address.
|
|
|
|
|
|
|
|
In stockholm this can be done by configuring:
|
2016-07-28 13:03:09 +02:00
|
|
|
krebs.hosts.${connect-host}.nets.${netname?"retiolum"}.via.ip4.addr = external-ip
|
2016-07-28 10:55:34 +02:00
|
|
|
krebs.hosts.${connect-host}.nets.${netname?"retiolum"}.tinc.port = 1655;
|
2016-07-20 10:06:04 +02:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
user = mkOption {
|
|
|
|
type = types.user;
|
|
|
|
default = {
|
|
|
|
name = tinc.config.netname;
|
|
|
|
home = "/var/lib/${tinc.config.user.name}";
|
|
|
|
};
|
|
|
|
};
|
2016-02-11 23:16:08 +01:00
|
|
|
};
|
2016-07-20 10:06:04 +02:00
|
|
|
}));
|
|
|
|
};
|
2016-07-20 14:38:59 +02:00
|
|
|
|
2016-07-20 14:15:47 +02:00
|
|
|
imp = {
|
2016-07-20 14:38:59 +02:00
|
|
|
# TODO `environment.systemPackages = [ cfg.tincPackage cfg.iproutePackage ]` for each network,
|
|
|
|
# avoid conflicts in environment if the packages differ
|
|
|
|
|
2020-09-05 01:17:51 +02:00
|
|
|
krebs.secret.files =
|
|
|
|
let
|
|
|
|
ed25519_keys =
|
|
|
|
filterAttrs
|
|
|
|
(_: key: key != null)
|
|
|
|
(mapAttrs'
|
|
|
|
(netname: cfg:
|
|
|
|
nameValuePair "${netname}.ed25519_key.priv" cfg.privkey_ed25519
|
|
|
|
)
|
|
|
|
config.krebs.tinc);
|
|
|
|
|
|
|
|
rsa_keys =
|
|
|
|
mapAttrs'
|
|
|
|
(netname: cfg: nameValuePair "${netname}.rsa_key.priv" cfg.privkey)
|
|
|
|
config.krebs.tinc;
|
|
|
|
in
|
|
|
|
ed25519_keys // rsa_keys;
|
2016-07-26 14:02:04 +02:00
|
|
|
|
2016-07-20 14:24:58 +02:00
|
|
|
users.users = mapAttrs' (netname: cfg:
|
2016-07-20 14:15:47 +02:00
|
|
|
nameValuePair "${netname}" {
|
2016-07-20 14:38:59 +02:00
|
|
|
inherit (cfg.user) home name uid;
|
|
|
|
createHome = true;
|
|
|
|
}
|
|
|
|
) config.krebs.tinc;
|
2016-07-20 14:15:47 +02:00
|
|
|
|
2017-05-16 23:19:08 +02:00
|
|
|
environment.etc = mapAttrs' (netname: cfg:
|
|
|
|
nameValuePair "tinc/${netname}" (mkIf cfg.enableLegacy {
|
|
|
|
source = cfg.confDir;
|
|
|
|
})
|
|
|
|
) config.krebs.tinc;
|
|
|
|
|
2016-07-20 14:24:58 +02:00
|
|
|
systemd.services = mapAttrs (netname: cfg:
|
2016-07-20 14:15:47 +02:00
|
|
|
let
|
|
|
|
tinc = cfg.tincPackage;
|
|
|
|
iproute = cfg.iproutePackage;
|
|
|
|
in {
|
2016-07-20 14:38:59 +02:00
|
|
|
description = "Tinc daemon for ${netname}";
|
2020-08-04 20:28:04 +02:00
|
|
|
after = [
|
|
|
|
"network.target"
|
2020-09-05 01:17:51 +02:00
|
|
|
config.krebs.secret.files."${netname}.rsa_key.priv".service
|
|
|
|
] ++ optionals (cfg.privkey_ed25519 != null) [
|
|
|
|
config.krebs.secret.files."${netname}.ed25519_key.priv".service
|
2020-08-04 20:28:04 +02:00
|
|
|
];
|
2020-08-04 22:22:43 +02:00
|
|
|
partOf = [
|
2020-08-04 20:28:04 +02:00
|
|
|
config.krebs.secret.files."${netname}.rsa_key.priv".service
|
2020-09-05 01:17:51 +02:00
|
|
|
] ++ optionals (cfg.privkey_ed25519 != null) [
|
|
|
|
config.krebs.secret.files."${netname}.ed25519_key.priv".service
|
2020-08-04 20:28:04 +02:00
|
|
|
];
|
2016-07-20 14:38:59 +02:00
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
path = [ tinc iproute ];
|
|
|
|
serviceConfig = rec {
|
|
|
|
Restart = "always";
|
2017-05-16 22:03:42 +02:00
|
|
|
ExecStart = "${tinc}/sbin/tincd -c ${cfg.confDir} -d 0 -U ${cfg.user.name} -D --pidfile=/var/run/tinc.${SyslogIdentifier}.pid";
|
2016-07-20 14:38:59 +02:00
|
|
|
SyslogIdentifier = netname;
|
|
|
|
};
|
|
|
|
}
|
|
|
|
) config.krebs.tinc;
|
2016-07-20 14:15:47 +02:00
|
|
|
};
|
2015-07-24 12:41:41 +02:00
|
|
|
in out
|