main
 1{
 2  globals,
 3  lib,
 4  libx,
 5  ...
 6}:
 7{
 8  imports = [
 9    ../common/services/openssh.nix
10  ];
11
12  # Disable TPM2 (VPS has no TPM hardware)
13  security.tpm2.enable = lib.mkForce false;
14
15  # ── Travel exit node ───────────────────────────────────────────
16  # wg0 is the homelab mesh client (to carthage, auto-derived from globals).
17  # wg1 gives travel devices a French IP: they set AllowedIPs = 0.0.0.0/0 and
18  # everything exits here. The module's POSTROUTING masquerade has no output
19  # interface, so it covers both internet egress via eth0 and traffic forwarded
20  # into wg0 towards the homelab — which is why no other host needs a route for
21  # the travel subnet.
22  services.wireguard.server = {
23    enable = true;
24    interface = "wg1";
25    privateKeyFile = "/etc/wireguard/travel.key";
26    natSource = globals.net.travel.subnet;
27    ips = [ "10.101.0.1/24" ];
28    peers = lib.mapAttrsToList (name: ip: {
29      publicKey = globals.machines.${name}.net.vpn.pubkey;
30      allowedIPs = libx.wg-ips [ ip ];
31    }) globals.net.travel.peers;
32  };
33
34  networking.firewall = {
35    allowPing = true;
36    allowedTCPPorts = [
37      80 # HTTP
38      443 # HTTPS
39    ];
40  };
41
42  # TODO: once the WireGuard mesh is up, restrict SSH to the VPN interface like
43  # carthage does:
44  #   services.openssh.listenAddresses = [ { addr = <vpn ip>; port = 22; } ];
45  #   services.openssh.openFirewall = lib.mkForce false;
46}