stockholm/krebs/3modules/default.nix

170 lines
4.6 KiB
Nix
Raw Normal View History

2015-07-24 18:48:00 +00:00
{ config, lib, ... }:
2016-10-20 18:54:38 +00:00
with import <stockholm/lib>;
2015-07-24 18:48:00 +00:00
let
cfg = config.krebs;
out = {
imports = [
2022-11-22 19:15:44 +00:00
../../kartei
2022-12-27 17:55:23 +00:00
../../submodules/disko/module.nix
2022-01-30 09:47:23 +00:00
./acl.nix
./airdcpp.nix
2017-09-05 20:58:25 +00:00
./announce-activation.nix
./apt-cacher-ng.nix
2015-12-28 18:43:31 +00:00
./backup.nix
./bepasty-server.nix
2021-01-24 10:26:39 +00:00
./bindfs.nix
2020-12-30 08:47:57 +00:00
./brockman.nix
./build.nix
2018-11-20 23:03:49 +00:00
./cachecache.nix
./ci
2015-10-25 13:15:21 +00:00
./current.nix
./dns.nix
2015-08-13 09:46:09 +00:00
./exim-retiolum.nix
2015-08-14 13:48:17 +00:00
./exim-smarthost.nix
2022-01-27 11:19:47 +00:00
./exim.nix
./fetchWallpaper.nix
2022-01-27 11:19:47 +00:00
./git.nix
2022-09-20 09:17:19 +00:00
./github
2015-11-13 00:16:15 +00:00
./go.nix
2017-04-15 16:04:19 +00:00
./hidden-ssh.nix
2019-01-21 10:04:37 +00:00
./hosts.nix
2017-03-16 19:56:28 +00:00
./htgen.nix
2017-09-21 18:59:38 +00:00
./iana-etc.nix
2015-10-01 20:10:21 +00:00
./iptables.nix
2017-02-07 16:21:25 +00:00
./kapacitor.nix
2018-08-25 14:54:13 +00:00
./konsens.nix
2022-12-09 14:50:25 +00:00
./krebs-pages.nix
2017-02-13 13:31:26 +00:00
./monit.nix
./nixpkgs.nix
2016-03-15 14:58:45 +00:00
./on-failure.nix
2016-03-05 11:40:20 +00:00
./os-release.nix
2015-11-06 20:37:58 +00:00
./per-user.nix
2022-01-27 11:19:47 +00:00
./permown.nix
2016-07-26 19:36:47 +00:00
./power-action.nix
2019-01-22 18:35:03 +00:00
./reaktor2.nix
2015-10-05 12:49:36 +00:00
./realwallpaper.nix
2022-01-27 11:19:47 +00:00
./repo-sync.nix
./retiolum-bootstrap.nix
2016-02-21 04:27:37 +00:00
./secret.nix
2016-02-14 12:26:37 +00:00
./setuid.nix
2019-04-19 14:32:00 +00:00
./shadow.nix
./sitemap.nix
2021-12-09 10:21:06 +00:00
./ssl.nix
2021-01-24 09:41:47 +00:00
./sync-containers.nix
./systemd.nix
2017-05-16 20:06:31 +00:00
./tinc.nix
./tinc_graphs.nix
2021-01-26 19:20:05 +00:00
./upstream
2015-07-24 18:48:00 +00:00
./urlwatch.nix
./users.nix
./xresources.nix
./zones.nix
2015-07-24 18:48:00 +00:00
];
options.krebs = api;
2016-02-14 15:43:44 +00:00
config = lib.mkIf cfg.enable imp;
2015-07-24 18:48:00 +00:00
};
api = {
enable = mkEnableOption "krebs";
2015-08-16 21:58:02 +00:00
zone-head-config = mkOption {
type = with types; attrsOf str;
description = ''
The zone configuration head which is being used to create the
zone files. The string for each key is pre-pended to the zone file.
2021-11-21 19:39:28 +00:00
'';
# TODO: configure the default somewhere else,
# maybe use krebs.dns.providers
2015-08-16 21:58:02 +00:00
default = {
# github.io -> 192.30.252.154
2015-08-16 21:58:02 +00:00
"krebsco.de" = ''
$TTL 86400
@ IN SOA dns19.ovh.net. tech.ovh.net. (2015052000 86400 3600 3600000 86400)
IN NS ns19.ovh.net.
IN NS dns19.ovh.net.
'';
2021-11-21 19:39:28 +00:00
};
2015-08-16 21:58:02 +00:00
};
};
2016-02-14 15:43:44 +00:00
imp = lib.mkMerge [
{
services.openssh.hostKeys =
let inherit (config.krebs.build.host.ssh) privkey; in
2019-04-30 17:12:00 +00:00
mkIf (privkey != null) [privkey];
services.openssh.knownHosts =
filterAttrs
(knownHostName: knownHost:
knownHost.publicKey != null &&
knownHost.hostNames != []
)
(mapAttrs
(hostName: host: {
hostNames =
concatLists
(mapAttrsToList
(netName: net:
let
aliases =
concatLists [
shortAliases
net.aliases
net.addrs
];
shortAliases =
optionals
(cfg.dns.search-domain != null)
(map (removeSuffix ".${cfg.dns.search-domain}")
(filter (hasSuffix ".${cfg.dns.search-domain}")
net.aliases));
addPort = alias:
if net.ssh.port != 22
then "[${alias}]:${toString net.ssh.port}"
else alias;
in
map addPort aliases
)
host.nets);
publicKey = host.ssh.pubkey;
})
(foldl' mergeAttrs {} [
cfg.hosts
{
localhost = {
nets.local = {
addrs = [ "127.0.0.1" "::1" ];
aliases = [ "localhost" ];
ssh.port = 22;
};
ssh.pubkey = config.krebs.build.host.ssh.pubkey;
};
}
]));
programs.ssh.extraConfig = concatMapStrings
(net: ''
Host ${toString (net.aliases ++ net.addrs)}
Port ${toString net.ssh.port}
'')
(filter
(net: net.ssh.port != 22)
(concatMap (host: attrValues host.nets)
(mapAttrsToList
(_: host: recursiveUpdate host
(optionalAttrs (cfg.dns.search-domain != null &&
hasAttr cfg.dns.search-domain host.nets) {
nets."" = host.nets.${cfg.dns.search-domain} // {
aliases = [host.name];
addrs = [];
};
}))
config.krebs.hosts)));
2015-08-16 21:58:02 +00:00
}
2015-07-24 19:38:41 +00:00
];
in out