liminix-fork/examples/rotuer.nix

209 lines
5.3 KiB
Nix
Raw Normal View History

# This is not part of Liminix per se. This is my "scratchpad"
# configuration for the device I'm testing with.
#
# Parts of it do do things that Liminix eventually needs to do, but
# don't look in here for solutions - just for identifying the
# problems.
{ config, pkgs, lib, ... } :
let
secrets = {
domainName = "fake.liminix.org";
firewallRules = {};
} // (import ./rotuer-secrets.nix);
2023-09-25 00:29:30 +02:00
inherit (pkgs.liminix.services) oneshot longrun bundle;
2023-09-04 23:05:42 +02:00
inherit (pkgs) serviceFns;
2023-07-20 12:28:45 +02:00
svc = config.system.service;
2023-07-23 00:37:01 +02:00
wirelessConfig = {
country_code = "GB";
inherit (secrets) wpa_passphrase;
auth_algs = 1; # 1=wpa2, 2=wep, 3=both
wpa = 2; # 1=wpa, 2=wpa2, 3=both
wpa_key_mgmt = "WPA-PSK";
wpa_pairwise = "TKIP CCMP"; # auth for wpa (may not need this?)
rsn_pairwise = "CCMP"; # auth for wpa2
wmm_enabled = 1;
};
in rec {
boot = {
tftp = {
freeSpaceBytes = 3 * 1024 * 1024;
serverip = "10.0.0.1";
ipaddr = "10.0.0.8";
};
};
imports = [
2023-04-23 13:58:51 +02:00
../modules/wlan.nix
../modules/network
../modules/ppp
2023-07-14 23:53:25 +02:00
../modules/dnsmasq
2023-09-25 00:29:30 +02:00
../modules/dhcp6c
../modules/firewall
2023-07-16 18:50:06 +02:00
../modules/hostapd
../modules/bridge
2023-07-23 00:22:45 +02:00
../modules/ntp
../modules/schnapps
2023-08-10 23:53:21 +02:00
../modules/ssh
../modules/outputs/btrfs.nix
../modules/outputs/extlinux.nix
];
2023-05-20 23:34:57 +02:00
hostname = "rotuer";
rootfsType = "btrfs";
rootOptions = "subvol=@";
boot.loader.extlinux.enable = true;
2023-08-05 13:21:18 +02:00
services.hostap = svc.hostapd.build {
interface = config.hardware.networkInterfaces.wlan;
params = {
ssid = secrets.ssid;
hw_mode="g";
channel = "2";
ieee80211n = 1;
2023-07-23 00:37:01 +02:00
} // wirelessConfig;
};
2023-08-05 13:21:18 +02:00
services.hostap5 = svc.hostapd.build {
interface = config.hardware.networkInterfaces.wlan5;
2023-03-01 23:24:58 +01:00
params = rec {
ssid = "${secrets.ssid}5";
2023-03-01 23:24:58 +01:00
hw_mode="a";
channel = 36;
ht_capab = "[HT40+]";
vht_oper_chwidth = 1;
vht_oper_centr_freq_seg0_idx = channel + 6;
ieee80211n = 1;
2023-03-01 23:24:58 +01:00
ieee80211ac = 1;
2023-07-23 00:37:01 +02:00
} // wirelessConfig;
2023-03-01 23:24:58 +01:00
};
services.int = svc.network.address.build {
2023-09-01 18:57:22 +02:00
interface = svc.bridge.primary.build { ifname = "int"; };
family = "inet"; address ="${secrets.lan.prefix}.1"; prefixLength = 24;
};
services.bridge = svc.bridge.members.build {
primary = services.int;
members = with config.hardware.networkInterfaces;
[ wlan
wlan5
lan0
lan1
lan2
lan3
lan4
];
};
2023-03-01 23:24:58 +01:00
2023-08-05 15:16:54 +02:00
services.ntp = svc.ntp.build {
2023-07-23 00:22:45 +02:00
pools = { "pool.ntp.org" = ["iburst"]; };
makestep = { threshold = 1.0; limit = 3; };
};
2023-04-23 19:22:39 +02:00
2023-08-10 23:53:21 +02:00
services.sshd = svc.ssh.build { };
2023-05-20 23:48:30 +02:00
users.root = secrets.root;
services.dns =
let interface = services.int;
in svc.dnsmasq.build {
resolvconf = services.resolvconf;
inherit interface;
ranges = [
"${secrets.lan.prefix}.10,${secrets.lan.prefix}.240"
2023-09-05 00:07:13 +02:00
# ra-stateless: sends router advertisements with the O and A
# bits set, and provides a stateless DHCP service. The client
# will use a SLAAC address, and use DHCP for other
# configuration information.
"::,constructor:$(output ${interface} ifname),ra-stateless"
];
2023-09-05 00:07:13 +02:00
# You can add static addresses for the DHCP server here. I'm
# not putting my actual MAC addresses in a public git repo ...
hosts = { } // lib.optionalAttrs (builtins.pathExists ./static-leases.nix) (import ./static-leases.nix);
upstreams = [ "/${secrets.domainName}/" ];
domain = secrets.domainName;
};
2023-08-10 23:53:45 +02:00
services.wan = svc.pppoe.build {
2023-07-20 13:05:36 +02:00
interface = config.hardware.networkInterfaces.wan;
ppp-options = [
"debug" "+ipv6" "noauth"
"name" secrets.l2tp.name
"password" secrets.l2tp.password
];
};
services.resolvconf = oneshot rec {
dependencies = [ services.wan ];
name = "resolvconf";
up = ''
. ${serviceFns}
( in_outputs ${name}
echo "nameserver $(output ${services.wan} ns1)" > resolv.conf
echo "nameserver $(output ${services.wan} ns2)" >> resolv.conf
chmod 0444 resolv.conf
)
'';
};
2023-09-04 23:06:15 +02:00
2023-08-28 19:23:32 +02:00
filesystem =
let inherit (pkgs.pseudofile) dir symlink;
in dir {
etc = dir {
"resolv.conf" = symlink "${services.resolvconf}/.outputs/resolv.conf";
};
};
services.defaultroute4 = svc.network.route.build {
via = "$(output ${services.wan} address)";
target = "default";
dependencies = [ services.wan ];
};
services.defaultroute6 = svc.network.route.build {
via = "$(output ${services.wan} ipv6-peer-address)";
target = "default";
interface = services.wan;
};
services.firewall = svc.firewall.build {
ruleset =
let defaults = import ./demo-firewall.nix;
in lib.recursiveUpdate defaults secrets.firewallRules;
2023-07-16 18:04:01 +02:00
};
services.packet_forwarding = svc.network.forward.build { };
2023-09-25 00:29:30 +02:00
services.dhcp6c =
let client = svc.dhcp6c.client.build {
interface = services.wan;
};
in bundle {
name = "dhcp6c";
contents = [
(svc.dhcp6c.prefix.build {
inherit client;
interface = services.int;
})
(svc.dhcp6c.address.build {
inherit client;
interface = services.wan;
})
];
};
2023-06-20 21:13:59 +02:00
defaultProfile.packages = with pkgs; [
min-collect-garbage
2024-02-12 00:30:46 +01:00
nftables
strace
tcpdump
2023-06-20 21:13:59 +02:00
];
2023-12-13 22:54:15 +01:00
programs.busybox.applets = [
"fdisk" "sfdisk"
];
}