stockholm/makefu/1systems/shoney.nix

61 lines
1.4 KiB
Nix
Raw Normal View History

2016-06-12 17:48:15 +00:00
{ config, pkgs, ... }:
let
tinc-siem-ip = "10.8.10.1";
2016-06-13 14:22:51 +00:00
ip = "64.137.234.215";
2016-07-11 18:46:09 +00:00
alt-ip = "64.137.234.210"; # honeydrive honeyd
extra-ip1 = "64.137.234.114"; # floating tinc.siem
extra-ip2 = "64.137.234.232"; # honeydrive
2016-06-13 14:22:51 +00:00
gw = "64.137.234.1";
2016-06-12 17:48:15 +00:00
in {
imports = [
../.
../2configs/save-diskspace.nix
2016-06-13 14:22:51 +00:00
../2configs/hw/CAC.nix
../2configs/fs/CAC-CentOS-7-64bit.nix
../2configs/tinc/retiolum.nix
2016-06-12 17:48:15 +00:00
];
2016-06-13 14:22:51 +00:00
2016-07-11 18:46:09 +00:00
environment.systemPackages = [ pkgs.honeyd ];
services.tinc.networks.siem.name = "sjump";
2016-06-12 17:48:15 +00:00
krebs = {
enable = true;
build.host = config.krebs.hosts.shoney;
nginx.enable = true;
tinc_graphs = {
enable = true;
network = "siem";
hostsPath = "/etc/tinc/siem/hosts";
nginx = {
enable = true;
# TODO: remove hard-coded hostname
complete = {
listen = [ "${tinc-siem-ip}:80" ];
server-names = [ "graphs.siem" ];
};
};
};
2016-06-12 17:48:15 +00:00
};
2016-07-11 18:46:09 +00:00
makefu.forward-journal = {
enable = true;
src = "10.8.10.1";
dst = "10.8.10.6";
};
networking = {
interfaces.enp2s1.ip4 = [
{ address = ip; prefixLength = 24; }
2016-07-11 18:46:09 +00:00
# { address = alt-ip; prefixLength = 24; }
];
2016-06-13 23:33:41 +00:00
defaultGateway = gw;
nameservers = [ "8.8.8.8" ];
firewall = {
trustedInterfaces = [ "tinc.siem" ];
allowedUDPPorts = [ 655 1655 ];
allowedTCPPorts = [ 655 1655 ];
};
};
2016-06-12 17:48:15 +00:00
}