main
1# Generate system config files for Fedora work hosts without system-manager.
2# Usage: nix build .#fedoraConfigs.<hostname>
3# Then: sudo ./result/deploy
4{
5 lib,
6 pkgs,
7 globals,
8 libx,
9 hostname,
10}:
11let
12 machine = globals.machines.${hostname};
13 isNagoyaBuilderClient = builtins.elem hostname [
14 "aomi"
15 "kyushu"
16 ];
17 nagoya = globals.machines.nagoya;
18 hostsEntries = libx.hostConfigs globals.machines;
19 hostsFile = lib.concatStringsSep "\n" (
20 lib.mapAttrsToList (ip: names: "${ip} ${lib.concatStringsSep " " names}") hostsEntries
21 );
22
23 hosts = pkgs.writeText "hosts" ''
24 127.0.0.1 localhost
25 ::1 localhost
26 ${hostsFile}
27 '';
28
29 wgConf = pkgs.writeText "wg0.conf" ''
30 [Interface]
31 PostUp = wg set %i private-key /etc/wireguard/private.key
32 Address = ${builtins.head machine.net.vpn.ips}/24
33
34 [Peer]
35 PublicKey = ${globals.machines.carthage.net.vpn.pubkey}
36 AllowedIPs = 10.100.0.0/24
37 Endpoint = ${globals.net.vpn.endpoint}:51820
38 PersistentKeepalive = 25
39 '';
40
41 nixCustomConf = pkgs.writeText "nix.custom.conf" ''
42 trusted-users = root @wheel
43 connect-timeout = 5
44 download-attempts = 2
45 ${lib.optionalString isNagoyaBuilderClient "builders-use-substitutes = true"}
46 '';
47
48 nixMachines = pkgs.writeText "nix-machines" ''
49 ssh-ng://vincent@nagoya.vpn aarch64-linux /etc/nix/keys/nagoya-builder 4 1
50 '';
51
52 sshKnownHosts = pkgs.writeText "ssh-known-hosts" ''
53 nagoya.home,nagoya.vpn,nagoya.sbr.pm,192.168.1.80,10.100.0.80 ${nagoya.ssh.hostKey}
54 '';
55
56 nmDispatcher = pkgs.writeScript "99-wireguard-route" ''
57 #!/bin/bash
58 INTERFACE="$1"
59 ACTION="$2"
60 if [[ "$INTERFACE" == "tun0" && "$ACTION" == "vpn-up" ]]; then
61 TABLE=$(ip rule show | grep -oP 'lookup \K[0-9]+' | head -1)
62 if [[ -n "$TABLE" && "$TABLE" != "local" ]]; then
63 ip route add 10.100.0.0/24 dev wg0 table "$TABLE" 2>/dev/null || true
64 fi
65 fi
66 '';
67
68 deployScript = pkgs.writeShellScript "deploy-configs" ''
69 set -euo pipefail
70 echo "Deploying system configs for ${hostname}..."
71 install -m 0644 ${hosts} /etc/hosts
72 mkdir -p /etc/wireguard
73 install -m 0600 ${wgConf} /etc/wireguard/wg0.conf
74 mkdir -p /etc/nix
75 touch /etc/nix/nix.custom.conf
76 if ! grep -q '^trusted-users[[:space:]]*=' /etc/nix/nix.custom.conf; then
77 echo 'trusted-users = root @wheel' >> /etc/nix/nix.custom.conf
78 fi
79 if ! grep -q '^connect-timeout[[:space:]]*=' /etc/nix/nix.custom.conf; then
80 echo 'connect-timeout = 5' >> /etc/nix/nix.custom.conf
81 fi
82 if ! grep -q '^download-attempts[[:space:]]*=' /etc/nix/nix.custom.conf; then
83 echo 'download-attempts = 2' >> /etc/nix/nix.custom.conf
84 fi
85 ${lib.optionalString isNagoyaBuilderClient ''
86 if ! grep -q '^builders-use-substitutes[[:space:]]*=' /etc/nix/nix.custom.conf; then
87 echo 'builders-use-substitutes = true' >> /etc/nix/nix.custom.conf
88 fi
89 ''}
90 mkdir -p /etc/NetworkManager/dispatcher.d
91 install -m 0755 ${nmDispatcher} /etc/NetworkManager/dispatcher.d/99-wireguard-route
92 ${lib.optionalString isNagoyaBuilderClient ''
93 install -m 0644 ${nixMachines} /etc/nix/machines
94 install -d -m 0755 /etc/ssh
95 install -m 0644 ${sshKnownHosts} /etc/ssh/ssh_known_hosts
96 ''}
97 echo "Done!"
98 '';
99in
100pkgs.runCommand "fedora-configs-${hostname}" { } ''
101 mkdir -p $out/etc/wireguard $out/etc/NetworkManager/dispatcher.d $out/etc/nix
102 cp ${hosts} $out/etc/hosts
103 cp ${wgConf} $out/etc/wireguard/wg0.conf
104 cp ${nixCustomConf} $out/etc/nix/nix.custom.conf
105 cp ${nmDispatcher} $out/etc/NetworkManager/dispatcher.d/99-wireguard-route
106 ${lib.optionalString isNagoyaBuilderClient ''
107 mkdir -p $out/etc/ssh
108 cp ${nixMachines} $out/etc/nix/machines
109 cp ${sshKnownHosts} $out/etc/ssh/ssh_known_hosts
110 ''}
111 cp ${deployScript} $out/deploy
112''