stockholm/krebs/3modules/default.nix

258 lines
8.3 KiB
Nix
Raw Normal View History

2015-07-24 20:48:00 +02:00
{ config, lib, ... }:
2016-02-14 16:43:44 +01:00
with config.krebs.lib;
2015-07-24 20:48:00 +02:00
let
cfg = config.krebs;
out = {
imports = [
./apt-cacher-ng.nix
2015-12-28 19:43:31 +01:00
./backup.nix
./bepasty-server.nix
2015-12-22 19:36:19 +01:00
./buildbot/master.nix
./buildbot/slave.nix
./build.nix
2015-10-25 14:15:21 +01:00
./current.nix
2016-04-27 01:10:25 +02:00
./exim.nix
2015-08-13 11:46:09 +02:00
./exim-retiolum.nix
2015-08-14 15:48:17 +02:00
./exim-smarthost.nix
./fetchWallpaper.nix
2015-07-24 20:48:00 +02:00
./github-hosts-sync.nix
./git.nix
2015-11-13 01:16:15 +01:00
./go.nix
2015-10-01 22:10:21 +02:00
./iptables.nix
2016-02-14 13:38:47 +01:00
./lib.nix
2016-03-15 14:37:46 +01:00
./newsbot-js.nix
2015-07-24 20:48:00 +02:00
./nginx.nix
./nixpkgs.nix
2016-03-15 15:58:45 +01:00
./on-failure.nix
2016-03-05 12:40:20 +01:00
./os-release.nix
2015-11-06 21:37:58 +01:00
./per-user.nix
2016-07-26 21:36:47 +02:00
./power-action.nix
2015-08-31 14:22:21 +02:00
./Reaktor.nix
2015-10-05 14:49:36 +02:00
./realwallpaper.nix
./retiolum-bootstrap.nix
2015-07-24 20:48:00 +02:00
./retiolum.nix
2016-02-21 05:27:37 +01:00
./secret.nix
2016-02-14 13:26:37 +01:00
./setuid.nix
./tinc_graphs.nix
2015-07-24 20:48:00 +02:00
./urlwatch.nix
./repo-sync.nix
2015-07-24 20:48:00 +02:00
];
options.krebs = api;
2016-02-14 16:43:44 +01:00
config = lib.mkIf cfg.enable imp;
2015-07-24 20:48:00 +02:00
};
api = {
enable = mkEnableOption "krebs";
dns = {
providers = mkOption {
type = with types; attrsOf str;
};
};
2015-07-24 21:15:18 +02:00
hosts = mkOption {
type = with types; attrsOf host;
};
users = mkOption {
type = with types; attrsOf user;
};
# XXX is there a better place to define search-domain?
# TODO search-domains :: listOf hostname
search-domain = mkOption {
type = types.hostname;
default = "retiolum";
};
2015-08-16 23:58:02 +02:00
zone-head-config = mkOption {
type = with types; attrsOf str;
description = ''
The zone configuration head which is being used to create the
zone files. The string for each key is pre-pended to the zone file.
'';
# TODO: configure the default somewhere else,
# maybe use krebs.dns.providers
default = {
# github.io -> 192.30.252.154
2015-08-16 23:58:02 +02:00
"krebsco.de" = ''
$TTL 86400
@ IN SOA dns19.ovh.net. tech.ovh.net. (2015052000 86400 3600 3600000 86400)
IN NS ns19.ovh.net.
IN NS dns19.ovh.net.
IN A 192.30.252.154
IN A 192.30.252.153
'';
};
};
};
2016-02-14 16:43:44 +01:00
imp = lib.mkMerge [
{ krebs = import ./lass { inherit config lib; }; }
{ krebs = import ./makefu { inherit config lib; }; }
2016-07-23 13:29:39 +02:00
{ krebs = import ./mv { inherit config lib; }; }
2016-02-14 16:43:44 +01:00
{ krebs = import ./shared { inherit config lib; }; }
{ krebs = import ./tv { inherit config lib; }; }
{
krebs.dns.providers = {
"krebsco.de" = "zones";
2015-10-18 16:12:14 +02:00
gg23 = "hosts";
2015-11-17 22:15:07 +01:00
shack = "hosts";
2016-02-06 16:21:30 +01:00
i = "hosts";
internet = "hosts";
2016-02-06 16:21:30 +01:00
r = "hosts";
retiolum = "hosts";
};
2016-02-21 07:39:24 +01:00
krebs.users = {
krebs = {
home = "/krebs";
mail = "spam@krebsco.de";
};
root = {
home = "/root";
pubkey = config.krebs.build.host.ssh.pubkey;
uid = 0;
};
};
networking.extraHosts = let
domains = attrNames (filterAttrs (_: eq "hosts") cfg.dns.providers);
check = hostname: any (domain: hasSuffix ".${domain}" hostname) domains;
in concatStringsSep "\n" (flatten (
mapAttrsToList (hostname: host:
mapAttrsToList (netname: net:
let
aliases = longs ++ shorts;
longs = filter check net.aliases;
shorts = let s = ".${cfg.search-domain}"; in
map (removeSuffix s) (filter (hasSuffix s) longs);
in
map (addr: "${addr} ${toString aliases}") net.addrs
) (filterAttrs (name: host: host.aliases != []) host.nets)
) cfg.hosts
));
2015-08-13 22:28:21 +02:00
2015-08-16 23:58:02 +02:00
# Implements environment.etc."zones/<zone-name>"
environment.etc = let
stripEmptyLines = s: (concatStringsSep "\n"
(remove "\n" (remove "" (splitString "\n" s)))) + "\n";
2015-08-16 23:58:02 +02:00
all-zones = foldAttrs (sum: current: sum + "\n" +current ) ""
2015-10-22 17:17:04 +02:00
([cfg.zone-head-config] ++ combined-hosts);
2015-08-16 23:58:02 +02:00
combined-hosts = (mapAttrsToList (name: value: value.extraZones) cfg.hosts );
2015-10-22 17:17:04 +02:00
in lib.mapAttrs' (name: value: nameValuePair
("zones/" + name)
{ text=(stripEmptyLines value); }) all-zones;
2015-10-05 03:01:21 +02:00
krebs.exim-smarthost.internet-aliases = let
2016-02-21 21:51:11 +01:00
format = from: to: {
inherit from;
2015-10-05 03:01:21 +02:00
# TODO assert is-retiolum-mail-address to;
2016-02-21 21:51:11 +01:00
to = concatMapStringsSep "," (getAttr "mail") (toList to);
};
2015-10-05 03:01:21 +02:00
in mapAttrsToList format (with config.krebs.users; let
spam-ml = [
lass
makefu
tv
];
2016-05-19 15:43:06 +02:00
ciko.mail = "wieczorek.stefan@gmail.com";
2016-05-19 15:05:16 +02:00
Mic92.mail = "joerg@higgsboson.tk";
2015-10-05 03:01:21 +02:00
in {
"*@eloop.org" = [{ mail = "eloop2016@krebsco.de"; }];
2016-05-19 15:05:16 +02:00
"eloop2016@krebsco.de" = spam-ml ++ [ ciko Mic92 ];
2015-10-05 03:03:51 +02:00
"postmaster@krebsco.de" = spam-ml; # RFC 822
2015-10-05 03:29:04 +02:00
"lass@krebsco.de" = lass;
"makefu@krebsco.de" = makefu;
2015-10-05 03:01:21 +02:00
"spam@krebsco.de" = spam-ml;
2015-10-05 03:29:04 +02:00
"tv@krebsco.de" = tv;
2015-10-05 03:06:04 +02:00
# XXX These are no internet aliases
# XXX exim-retiolum hosts should be able to relay to retiolum addresses
"lass@retiolum" = lass;
"makefu@retiolum" = makefu;
"spam@retiolum" = spam-ml;
"tv@retiolum" = tv;
2016-02-21 21:51:11 +01:00
"lass@r" = lass;
"makefu@r" = makefu;
"spam@r" = spam-ml;
"tv@r" = tv;
2015-10-05 03:01:21 +02:00
});
services.openssh.hostKeys =
let inherit (config.krebs.build.host.ssh) privkey; in
mkIf (privkey != null) (mkForce [privkey]);
2016-02-07 15:58:49 +01:00
# TODO use imports for merging
services.openssh.knownHosts =
2016-02-07 15:58:49 +01:00
(let inherit (config.krebs.build.host.ssh) pubkey; in
optionalAttrs (pubkey != null) {
localhost = {
hostNames = ["localhost" "127.0.0.1" "::1"];
publicKey = pubkey;
};
})
//
2015-10-09 13:18:21 +02:00
# GitHub's IPv4 address range is 192.30.252.0/22
# Refs https://help.github.com/articles/what-ip-addresses-does-github-use-that-i-should-whitelist/
# 192.30.252.0/22 = 192.30.252.0-192.30.255.255 (1024 addresses)
# Because line length is limited by OPENSSH_LINE_MAX (= 8192),
# we split each /24 into its own entry.
listToAttrs (map
(c: {
name = "github${toString c}";
value = {
hostNames = ["github.com"] ++
map (d: "192.30.${toString c}.${toString d}") (range 0 255);
publicKey = "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAq2A7hRGmdnm9tUDbO9IDSwBK6TbQa+PXYPCPy6rbTrTtw7PHkccKrpp0yVhp5HdEIcKr6pLlVDBfOLX9QUsyCOV0wzfjIJNlGEYsdlLJizHhbn2mUjvSAHQqZETYP81eFzLQNnPHt4EVVUh7VfDESU84KezmD5QlWpXLmvU31/yMf+Se8xhHTvKSCZIFImWwoG6mbUoWf9nzpIoaSjB+weqqUUmpaaasXVal72J+UX2B+2RPW3RcT0eOzQgqlJL3RKrTJvdsjE3JEAvGq3lGHSZXy28G3skua2SmVi/w4yCE6gbODqnTWlg7+wC604ydGXA8VJiS5ap43JXiUFFAaQ==";
};
})
(range 252 255))
//
mapAttrs
(name: host: {
hostNames =
concatLists
(mapAttrsToList
(net-name: net:
let
longs = net.aliases;
shorts =
map (removeSuffix ".${cfg.search-domain}")
(filter (hasSuffix ".${cfg.search-domain}")
longs);
add-port = a:
if net.ssh.port != 22
then "[${a}]:${toString net.ssh.port}"
else a;
in
2016-02-07 06:43:26 +01:00
map add-port (shorts ++ longs ++ net.addrs))
host.nets);
publicKey = host.ssh.pubkey;
})
(filterAttrs (_: host: host.ssh.pubkey != null) cfg.hosts);
programs.ssh.extraConfig = concatMapStrings
(net: ''
Host ${toString (net.aliases ++ net.addrs)}
Port ${toString net.ssh.port}
'')
(filter
(net: net.ssh.port != 22)
(concatMap (host: attrValues host.nets)
(mapAttrsToList
(_: host: recursiveUpdate host
(optionalAttrs (hasAttr config.krebs.search-domain host.nets) {
nets."" = host.nets.${config.krebs.search-domain} // {
aliases = [host.name];
addrs = [];
};
}))
config.krebs.hosts)));
2015-08-16 23:58:02 +02:00
}
2015-07-24 21:38:41 +02:00
];
in out