retiolum: config which is working but not functioning (see TODO in retiolum.nix)
This commit is contained in:
parent
835ddb0de0
commit
24db6439c4
@ -37,7 +37,7 @@ let
|
|||||||
config =
|
config =
|
||||||
# This configuration makes only sense for retiolum-enabled hosts.
|
# This configuration makes only sense for retiolum-enabled hosts.
|
||||||
# TODO modular configuration
|
# TODO modular configuration
|
||||||
assert config.krebs.retiolum.enable;
|
assert (lib.hasAttr "retiolum" config.krebs.tinc);
|
||||||
''
|
''
|
||||||
keep_environment =
|
keep_environment =
|
||||||
|
|
||||||
|
@ -1,130 +1,164 @@
|
|||||||
{ config, pkgs, lib, ... }:
|
{ config, pkgs, lib, ... }:
|
||||||
with config.krebs.lib;
|
with config.krebs.lib;
|
||||||
let
|
let
|
||||||
cfg = config.krebs.retiolum;
|
|
||||||
|
|
||||||
out = {
|
out = {
|
||||||
options.krebs.retiolum = api;
|
options.krebs.tinc = api;
|
||||||
config = lib.mkIf cfg.enable imp;
|
config = imp;
|
||||||
};
|
};
|
||||||
|
|
||||||
api = {
|
api = mkOption {
|
||||||
enable = mkEnableOption "krebs.retiolum";
|
default = {};
|
||||||
|
description = ''
|
||||||
|
define a tinc network
|
||||||
|
'';
|
||||||
|
type = with types; attrsOf (submodule (tinc: {
|
||||||
|
options = {
|
||||||
|
host = mkOption {
|
||||||
|
type = types.host;
|
||||||
|
default = config.krebs.build.host;
|
||||||
|
};
|
||||||
|
|
||||||
host = mkOption {
|
netname = mkOption {
|
||||||
type = types.host;
|
type = types.enum (attrNames tinc.config.host.nets);
|
||||||
default = config.krebs.build.host;
|
default = tinc.config._module.args.name;
|
||||||
};
|
description = ''
|
||||||
|
The tinc network name.
|
||||||
|
It is used to name the TUN device and to generate the default value for
|
||||||
|
<literal>config.krebs.tinc.retiolum.hosts</literal>.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
netname = mkOption {
|
extraConfig = mkOption {
|
||||||
type = types.enum (attrNames cfg.host.nets);
|
type = types.str;
|
||||||
default = "retiolum";
|
default = "";
|
||||||
description = ''
|
description = ''
|
||||||
The tinc network name.
|
Extra Configuration to be appended to tinc.conf
|
||||||
It is used to name the TUN device and to generate the default value for
|
'';
|
||||||
<literal>config.krebs.retiolum.hosts</literal>.
|
};
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
extraConfig = mkOption {
|
tincPackage = mkOption {
|
||||||
type = types.str;
|
type = types.package;
|
||||||
default = "";
|
default = pkgs.tinc;
|
||||||
description = ''
|
description = "Tincd package to use.";
|
||||||
Extra Configuration to be appended to tinc.conf
|
};
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
tincPackage = mkOption {
|
hosts = mkOption {
|
||||||
type = types.package;
|
type = with types; attrsOf host;
|
||||||
default = pkgs.tinc;
|
default =
|
||||||
description = "Tincd package to use.";
|
filterAttrs (_: h: hasAttr tinc.config.netname h.nets) config.krebs.hosts;
|
||||||
};
|
description = ''
|
||||||
|
Hosts to generate <literal>config.krebs.retiolum.hostsPackage</literal>.
|
||||||
|
Note that these hosts must have a network named
|
||||||
|
<literal>config.krebs.retiolum.netname</literal>.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
hosts = mkOption {
|
hostsPackage = mkOption {
|
||||||
type = with types; attrsOf host;
|
type = types.package;
|
||||||
default =
|
default = pkgs.stdenv.mkDerivation {
|
||||||
filterAttrs (_: h: hasAttr cfg.netname h.nets) config.krebs.hosts;
|
name = "${tinc.config.netname}-tinc-hosts";
|
||||||
description = ''
|
phases = [ "installPhase" ];
|
||||||
Hosts to generate <literal>config.krebs.retiolum.hostsPackage</literal>.
|
installPhase = ''
|
||||||
Note that these hosts must have a network named
|
mkdir $out
|
||||||
<literal>config.krebs.retiolum.netname</literal>.
|
${concatStrings (lib.mapAttrsToList (_: host: ''
|
||||||
'';
|
echo ${shell.escape host.nets."${tinc.config.netname}".tinc.config} \
|
||||||
};
|
> $out/${shell.escape host.name}
|
||||||
|
'') tinc.config.hosts)}
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
description = ''
|
||||||
|
Package of tinc host configuration files. By default, a package will
|
||||||
|
be generated from <literal>config.krebs.${tinc.config.netname}.hosts</literal>. This
|
||||||
|
option's main purpose is to expose the generated hosts package to other
|
||||||
|
modules, like <literal>config.krebs.tinc_graphs</literal>. But it can
|
||||||
|
also be used to provide a custom hosts directory.
|
||||||
|
'';
|
||||||
|
example = literalExample ''
|
||||||
|
(pkgs.stdenv.mkDerivation {
|
||||||
|
name = "my-tinc-hosts";
|
||||||
|
src = /home/tv/my-tinc-hosts;
|
||||||
|
installPhase = "cp -R . $out";
|
||||||
|
})
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
hostsPackage = mkOption {
|
iproutePackage = mkOption {
|
||||||
type = types.package;
|
type = types.package;
|
||||||
default = pkgs.stdenv.mkDerivation {
|
default = pkgs.iproute;
|
||||||
name = "${cfg.netname}-tinc-hosts";
|
description = "Iproute2 package to use.";
|
||||||
phases = [ "installPhase" ];
|
};
|
||||||
installPhase = ''
|
|
||||||
mkdir $out
|
privkey = mkOption {
|
||||||
${concatStrings (mapAttrsToList (_: host: ''
|
type = types.secret-file;
|
||||||
echo ${shell.escape host.nets.${cfg.netname}.tinc.config} \
|
default = {
|
||||||
> $out/${shell.escape host.name}
|
path = "${tinc.config.user.home}/tinc.rsa_key.priv";
|
||||||
'') cfg.hosts)}
|
owner = tinc.config.user;
|
||||||
'';
|
source-path = toString <secrets> + "/${tinc.config.netname}.rsa_key.priv";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
connectTo = mkOption {
|
||||||
|
type = types.listOf types.str;
|
||||||
|
default = [ "fastpoke" "cd" "prism" "gum" ];
|
||||||
|
description = ''
|
||||||
|
The list of hosts in the network which the client will try to connect
|
||||||
|
to. These hosts should have an 'Address' configured which points to a
|
||||||
|
routeable IPv4 or IPv6 address.
|
||||||
|
|
||||||
|
In stockholm this can be done by configuring:
|
||||||
|
krebs.hosts.${connect-host}.nets.${netname?"retiolum"}.via.addrs4 =
|
||||||
|
[ "${external-ip} ${external-port}" ]
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
user = mkOption {
|
||||||
|
type = types.user;
|
||||||
|
default = {
|
||||||
|
name = tinc.config.netname;
|
||||||
|
home = "/var/lib/${tinc.config.user.name}";
|
||||||
|
};
|
||||||
|
};
|
||||||
};
|
};
|
||||||
description = ''
|
}));
|
||||||
Package of tinc host configuration files. By default, a package will
|
|
||||||
be generated from <literal>config.krebs.retiolum.hosts</literal>. This
|
|
||||||
option's main purpose is to expose the generated hosts package to other
|
|
||||||
modules, like <literal>config.krebs.tinc_graphs</literal>. But it can
|
|
||||||
also be used to provide a custom hosts directory.
|
|
||||||
'';
|
|
||||||
example = literalExample ''
|
|
||||||
(pkgs.stdenv.mkDerivation {
|
|
||||||
name = "my-tinc-hosts";
|
|
||||||
src = /home/tv/my-tinc-hosts;
|
|
||||||
installPhase = "cp -R . $out";
|
|
||||||
})
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
iproutePackage = mkOption {
|
|
||||||
type = types.package;
|
|
||||||
default = pkgs.iproute;
|
|
||||||
description = "Iproute2 package to use.";
|
|
||||||
};
|
|
||||||
|
|
||||||
privkey = mkOption {
|
|
||||||
type = types.secret-file;
|
|
||||||
default = {
|
|
||||||
path = "${cfg.user.home}/tinc.rsa_key.priv";
|
|
||||||
owner = cfg.user;
|
|
||||||
source-path = toString <secrets> + "/${cfg.netname}.rsa_key.priv";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
connectTo = mkOption {
|
|
||||||
type = types.listOf types.str;
|
|
||||||
default = [ "fastpoke" "cd" "prism" "gum" ];
|
|
||||||
description = ''
|
|
||||||
The list of hosts in the network which the client will try to connect
|
|
||||||
to. These hosts should have an 'Address' configured which points to a
|
|
||||||
routeable IPv4 or IPv6 address.
|
|
||||||
|
|
||||||
In stockholm this can be done by configuring:
|
|
||||||
krebs.hosts.${connect-host}.nets.${netname?"retiolum"}.via.addrs4 =
|
|
||||||
[ "${external-ip} ${external-port}" ]
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
user = mkOption {
|
|
||||||
type = types.user;
|
|
||||||
default = {
|
|
||||||
name = cfg.netname;
|
|
||||||
home = "/var/lib/${cfg.user.name}";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
|
imp = lib.mkMerge ( lib.mapAttrsToList (netname: cfg:
|
||||||
|
let
|
||||||
|
net = cfg.host.nets.${netname};
|
||||||
|
|
||||||
imp = {
|
tinc = cfg.tincPackage;
|
||||||
krebs.secret.files."${cfg.netname}.rsa_key.priv" = cfg.privkey;
|
|
||||||
|
iproute = cfg.iproutePackage;
|
||||||
|
|
||||||
|
confDir = let
|
||||||
|
namePathPair = name: path: { inherit name path; };
|
||||||
|
in pkgs.linkFarm "${netname}-etc-tinc" (lib.mapAttrsToList namePathPair {
|
||||||
|
"hosts" = cfg.hostsPackage;
|
||||||
|
"tinc.conf" = pkgs.writeText "${cfg.netname}-tinc.conf" ''
|
||||||
|
Name = ${cfg.host.name}
|
||||||
|
Interface = ${netname}
|
||||||
|
${concatStrings (map (c: "ConnectTo = ${c}\n") cfg.connectTo)}
|
||||||
|
PrivateKeyFile = ${cfg.privkey.path}
|
||||||
|
${cfg.extraConfig}
|
||||||
|
'';
|
||||||
|
"tinc-up" = pkgs.writeDash "${netname}-tinc-up" ''
|
||||||
|
${iproute}/sbin/ip link set ${netname} up
|
||||||
|
${optionalString (net.ip4 != null) /* sh */ ''
|
||||||
|
${iproute}/sbin/ip -4 addr add ${net.ip4.addr} dev ${netname}
|
||||||
|
${iproute}/sbin/ip -4 route add ${net.ip4.prefix} dev ${netname}
|
||||||
|
''}
|
||||||
|
${optionalString (net.ip6 != null) /* sh */ ''
|
||||||
|
${iproute}/sbin/ip -6 addr add ${net.ip6.addr} dev ${netname}
|
||||||
|
${iproute}/sbin/ip -6 route add ${net.ip6.prefix} dev ${netname}
|
||||||
|
''}
|
||||||
|
'';
|
||||||
|
});
|
||||||
|
in {
|
||||||
|
krebs.secret.files."${netname}.rsa_key.priv" = cfg.privkey;
|
||||||
|
|
||||||
environment.systemPackages = [ tinc iproute ];
|
environment.systemPackages = [ tinc iproute ];
|
||||||
|
|
||||||
systemd.services.${cfg.netname} = {
|
systemd.services.${netname} = {
|
||||||
description = "Tinc daemon for Retiolum";
|
description = "Tinc daemon for ${netname}";
|
||||||
after = [ "network.target" ];
|
after = [ "network.target" ];
|
||||||
wantedBy = [ "multi-user.target" ];
|
wantedBy = [ "multi-user.target" ];
|
||||||
requires = [ "secret.service" ];
|
requires = [ "secret.service" ];
|
||||||
@ -132,7 +166,7 @@ let
|
|||||||
serviceConfig = rec {
|
serviceConfig = rec {
|
||||||
Restart = "always";
|
Restart = "always";
|
||||||
ExecStart = "${tinc}/sbin/tincd -c ${confDir} -d 0 -U ${cfg.user.name} -D --pidfile=/var/run/tinc.${SyslogIdentifier}.pid";
|
ExecStart = "${tinc}/sbin/tincd -c ${confDir} -d 0 -U ${cfg.user.name} -D --pidfile=/var/run/tinc.${SyslogIdentifier}.pid";
|
||||||
SyslogIdentifier = cfg.netname;
|
SyslogIdentifier = netname;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@ -140,36 +174,5 @@ let
|
|||||||
inherit (cfg.user) home name uid;
|
inherit (cfg.user) home name uid;
|
||||||
createHome = true;
|
createHome = true;
|
||||||
};
|
};
|
||||||
};
|
}) {} ); # TODO <<<< replace with the "config.krebs.tinc" and avoid infinite recursion
|
||||||
|
|
||||||
net = cfg.host.nets.${cfg.netname};
|
|
||||||
|
|
||||||
tinc = cfg.tincPackage;
|
|
||||||
|
|
||||||
iproute = cfg.iproutePackage;
|
|
||||||
|
|
||||||
confDir = let
|
|
||||||
namePathPair = name: path: { inherit name path; };
|
|
||||||
in pkgs.linkFarm "${cfg.netname}-etc-tinc" (mapAttrsToList namePathPair {
|
|
||||||
"hosts" = cfg.hostsPackage;
|
|
||||||
"tinc.conf" = pkgs.writeText "${cfg.netname}-tinc.conf" ''
|
|
||||||
Name = ${cfg.host.name}
|
|
||||||
Interface = ${cfg.netname}
|
|
||||||
${concatStrings (map (c: "ConnectTo = ${c}\n") cfg.connectTo)}
|
|
||||||
PrivateKeyFile = ${cfg.privkey.path}
|
|
||||||
${cfg.extraConfig}
|
|
||||||
'';
|
|
||||||
"tinc-up" = pkgs.writeDash "${cfg.netname}-tinc-up" ''
|
|
||||||
${iproute}/sbin/ip link set ${cfg.netname} up
|
|
||||||
${optionalString (net.ip4 != null) /* sh */ ''
|
|
||||||
${iproute}/sbin/ip -4 addr add ${net.ip4.addr} dev ${cfg.netname}
|
|
||||||
${iproute}/sbin/ip -4 route add ${net.ip4.prefix} dev ${cfg.netname}
|
|
||||||
''}
|
|
||||||
${optionalString (net.ip6 != null) /* sh */ ''
|
|
||||||
${iproute}/sbin/ip -6 addr add ${net.ip6.addr} dev ${cfg.netname}
|
|
||||||
${iproute}/sbin/ip -6 route add ${net.ip6.prefix} dev ${cfg.netname}
|
|
||||||
''}
|
|
||||||
'';
|
|
||||||
});
|
|
||||||
|
|
||||||
in out
|
in out
|
||||||
|
Loading…
Reference in New Issue
Block a user