2024-12-08 09:39:51 +01:00
|
|
|
{ lib, config, ... }:
|
2024-12-13 14:37:43 +01:00
|
|
|
let
|
|
|
|
inherit (lib)
|
|
|
|
mkOption
|
|
|
|
splitString
|
|
|
|
length
|
|
|
|
hasPrefix
|
|
|
|
filter
|
|
|
|
concatStringsSep
|
|
|
|
;
|
|
|
|
inherit (lib.types)
|
|
|
|
str
|
|
|
|
listOf
|
|
|
|
enum
|
|
|
|
port
|
|
|
|
;
|
|
|
|
in
|
2024-12-08 09:39:51 +01:00
|
|
|
{
|
|
|
|
options = {
|
|
|
|
system = {
|
|
|
|
host-name = mkOption {
|
2024-12-13 14:37:43 +01:00
|
|
|
type = str;
|
2024-12-08 09:39:51 +01:00
|
|
|
description = "The hostname of the switch.";
|
|
|
|
};
|
|
|
|
root-authentication = {
|
|
|
|
hashedPasswd = mkOption {
|
2024-12-13 14:37:43 +01:00
|
|
|
type = str;
|
2024-12-08 09:39:51 +01:00
|
|
|
description = "Hashed password for root.";
|
|
|
|
};
|
|
|
|
ssh-keys = mkOption {
|
2024-12-13 14:37:43 +01:00
|
|
|
type = listOf str;
|
2024-12-08 09:39:51 +01:00
|
|
|
description = "ssh keys for root user.";
|
|
|
|
default = [ ];
|
|
|
|
};
|
|
|
|
};
|
|
|
|
services = {
|
|
|
|
ssh.root-login = mkOption {
|
2024-12-13 14:37:43 +01:00
|
|
|
type = enum [
|
2024-12-08 09:39:51 +01:00
|
|
|
"allow"
|
|
|
|
"deny"
|
|
|
|
"deny-password"
|
|
|
|
];
|
|
|
|
description = "Login policy to use for root.";
|
|
|
|
};
|
|
|
|
netconf.port = mkOption {
|
2024-12-13 14:37:43 +01:00
|
|
|
type = port;
|
2024-12-08 09:39:51 +01:00
|
|
|
description = "Port to use for netconf.";
|
|
|
|
default = 830;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
2024-12-13 16:03:36 +01:00
|
|
|
config.netconf.xml.system =
|
2024-12-08 09:39:51 +01:00
|
|
|
let
|
|
|
|
ssh-keys1 = map (splitString " ") config.system.root-authentication.ssh-keys;
|
|
|
|
ssh-keys2 = map (key: if length key < 3 then key ++ [ "foo@bar" ] else key) ssh-keys1;
|
|
|
|
ssh-keys = map (concatStringsSep " ") ssh-keys2;
|
2024-12-13 16:03:36 +01:00
|
|
|
ssh-edsca = map (name: { inherit name; }) (filter (hasPrefix "ssh-edsca ") ssh-keys);
|
|
|
|
ssh-rsa = map (name: { inherit name; }) (filter (hasPrefix "ssh-rsa ") ssh-keys);
|
|
|
|
ssh-ed25519 = map (name: { inherit name; }) (filter (hasPrefix "ssh-ed25519 ") ssh-keys);
|
2024-12-08 09:39:51 +01:00
|
|
|
in
|
2024-12-13 16:03:36 +01:00
|
|
|
{
|
|
|
|
host-name = {
|
|
|
|
"@operation" = "replace";
|
|
|
|
"#text" = config.system.host-name;
|
|
|
|
};
|
|
|
|
root-authentication = {
|
|
|
|
"@operation" = "replace";
|
|
|
|
encrypted-password = config.system.root-authentication.hashedPasswd;
|
|
|
|
inherit ssh-edsca ssh-rsa ssh-ed25519;
|
|
|
|
};
|
|
|
|
services = {
|
|
|
|
"@operation" = "replace";
|
|
|
|
ssh.root-login = config.system.services.ssh.root-login;
|
|
|
|
netconf = {
|
|
|
|
ssh.port = config.system.services.netconf.port;
|
|
|
|
rfc-compliant = {};
|
|
|
|
yang-compliant = {};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
2024-12-08 09:39:51 +01:00
|
|
|
}
|