main
 1# Generate the small set of host files Sakhalin needs outside Home Manager.
 2# Fedora manages packages, services, and networking.
 3{
 4  pkgs,
 5  globals,
 6  libx,
 7  ...
 8}:
 9let
10  machine = globals.machines.sakhalin;
11  hostsEntries = libx.hostConfigs globals.machines;
12  hosts = pkgs.writeText "hosts" ''
13    127.0.0.1 localhost sakhalin
14    ::1 localhost
15    ${pkgs.lib.concatStringsSep "\n" (
16      pkgs.lib.mapAttrsToList (ip: names: "${ip} ${pkgs.lib.concatStringsSep " " names}") hostsEntries
17    )}
18  '';
19
20  wgConf = pkgs.writeText "wg0.conf" ''
21    [Interface]
22    PostUp = wg set %i private-key /etc/wireguard/private.key
23    Address = ${builtins.head machine.net.vpn.ips}/24
24
25    [Peer]
26    PublicKey = ${globals.machines.carthage.net.vpn.pubkey}
27    AllowedIPs = 10.100.0.0/24
28    Endpoint = ${globals.net.vpn.endpoint}:51820
29    PersistentKeepalive = 25
30  '';
31
32  nixCustomConf = pkgs.writeText "nix.custom.conf" ''
33    trusted-users = root @wheel
34    connect-timeout = 5
35    download-attempts = 2
36    builders-use-substitutes = true
37  '';
38
39  deploy = pkgs.writeShellScript "deploy-sakhalin-configs" ''
40    set -euo pipefail
41    install -m 0644 ${hosts} /etc/hosts
42    install -d -m 0755 /etc/nix /etc/wireguard
43    install -m 0644 ${nixCustomConf} /etc/nix/nix.custom.conf
44    install -m 0600 ${wgConf} /etc/wireguard/wg0.conf
45  '';
46in
47pkgs.runCommand "sakhalin-configs" { } ''
48  mkdir -p "$out/etc/nix" "$out/etc/wireguard"
49  cp ${hosts} "$out/etc/hosts"
50  cp ${nixCustomConf} "$out/etc/nix/nix.custom.conf"
51  cp ${wgConf} "$out/etc/wireguard/wg0.conf"
52  cp ${deploy} "$out/deploy"
53''