main
1{
2 globals,
3 lib,
4 libx,
5 ...
6}:
7{
8 imports = [
9 ../common/services/openssh.nix
10 ];
11
12 # Disable TPM2 (VPS has no TPM hardware)
13 security.tpm2.enable = lib.mkForce false;
14
15 # ── Travel exit node ───────────────────────────────────────────
16 # wg0 is the homelab mesh client (to carthage, auto-derived from globals).
17 # wg1 gives travel devices a French IP: they set AllowedIPs = 0.0.0.0/0 and
18 # everything exits here. The module's POSTROUTING masquerade has no output
19 # interface, so it covers both internet egress via eth0 and traffic forwarded
20 # into wg0 towards the homelab — which is why no other host needs a route for
21 # the travel subnet.
22 services.wireguard.server = {
23 enable = true;
24 interface = "wg1";
25 privateKeyFile = "/etc/wireguard/travel.key";
26 natSource = globals.net.travel.subnet;
27 ips = [ "10.101.0.1/24" ];
28 peers = lib.mapAttrsToList (name: ip: {
29 publicKey = globals.machines.${name}.net.vpn.pubkey;
30 allowedIPs = libx.wg-ips [ ip ];
31 }) globals.net.travel.peers;
32 };
33
34 networking.firewall = {
35 allowPing = true;
36 allowedTCPPorts = [
37 80 # HTTP
38 443 # HTTPS
39 ];
40 };
41
42 # TODO: once the WireGuard mesh is up, restrict SSH to the VPN interface like
43 # carthage does:
44 # services.openssh.listenAddresses = [ { addr = <vpn ip>; port = 22; } ];
45 # services.openssh.openFirewall = lib.mkForce false;
46}