main
1# Generate the small set of host files Sakhalin needs outside Home Manager.
2# Fedora manages packages, services, and networking.
3{
4 pkgs,
5 globals,
6 libx,
7 ...
8}:
9let
10 machine = globals.machines.sakhalin;
11 hostsEntries = libx.hostConfigs globals.machines;
12 hosts = pkgs.writeText "hosts" ''
13 127.0.0.1 localhost sakhalin
14 ::1 localhost
15 ${pkgs.lib.concatStringsSep "\n" (
16 pkgs.lib.mapAttrsToList (ip: names: "${ip} ${pkgs.lib.concatStringsSep " " names}") hostsEntries
17 )}
18 '';
19
20 wgConf = pkgs.writeText "wg0.conf" ''
21 [Interface]
22 PostUp = wg set %i private-key /etc/wireguard/private.key
23 Address = ${builtins.head machine.net.vpn.ips}/24
24
25 [Peer]
26 PublicKey = ${globals.machines.carthage.net.vpn.pubkey}
27 AllowedIPs = 10.100.0.0/24
28 Endpoint = ${globals.net.vpn.endpoint}:51820
29 PersistentKeepalive = 25
30 '';
31
32 nixCustomConf = pkgs.writeText "nix.custom.conf" ''
33 trusted-users = root @wheel
34 connect-timeout = 5
35 download-attempts = 2
36 builders-use-substitutes = true
37 '';
38
39 deploy = pkgs.writeShellScript "deploy-sakhalin-configs" ''
40 set -euo pipefail
41 install -m 0644 ${hosts} /etc/hosts
42 install -d -m 0755 /etc/nix /etc/wireguard
43 install -m 0644 ${nixCustomConf} /etc/nix/nix.custom.conf
44 install -m 0600 ${wgConf} /etc/wireguard/wg0.conf
45 '';
46in
47pkgs.runCommand "sakhalin-configs" { } ''
48 mkdir -p "$out/etc/nix" "$out/etc/wireguard"
49 cp ${hosts} "$out/etc/hosts"
50 cp ${nixCustomConf} "$out/etc/nix/nix.custom.conf"
51 cp ${wgConf} "$out/etc/wireguard/wg0.conf"
52 cp ${deploy} "$out/deploy"
53''