2016-09-12 22:04:48 +00:00
|
|
|
{ pkgs, config, ... }:
|
|
|
|
|
|
|
|
let
|
|
|
|
# TODO: make this a parameter
|
|
|
|
domain = "io.lassul.us";
|
|
|
|
pw = import <secrets/iodinepw.nix>;
|
|
|
|
in {
|
|
|
|
|
2016-10-11 15:43:12 +00:00
|
|
|
services.iodine.server = {
|
2016-09-12 22:04:48 +00:00
|
|
|
enable = true;
|
|
|
|
domain = domain;
|
|
|
|
ip = "172.16.10.1/24";
|
2016-10-01 00:16:47 +00:00
|
|
|
extraConfig = "-c -P ${pw} -l ${config.krebs.build.host.nets.internet.ip4.addr}";
|
2016-09-12 22:04:48 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
krebs.iptables.tables.filter.INPUT.rules = [
|
2016-10-01 00:17:17 +00:00
|
|
|
{ predicate = "-p udp --dport 53"; target = "ACCEPT";}
|
2016-09-12 22:04:48 +00:00
|
|
|
];
|
|
|
|
|
|
|
|
}
|