Compare commits
11
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
655c6331e9 | ||
|
|
0b8f1860fa | ||
|
|
17f3860f9b | ||
|
|
a97f3f82e5 | ||
|
|
a46b83cbc7 | ||
|
|
5642a0f6fc | ||
|
|
df389266f6 | ||
|
|
81626a75db | ||
|
|
8171207e9c | ||
|
|
53c03af2a0 | ||
|
|
1a56a2d24b |
@@ -1,3 +1,4 @@
|
|||||||
|
{ inputs, self, ... }:
|
||||||
let
|
let
|
||||||
hosts = import ./modules/hosts.nix;
|
hosts = import ./modules/hosts.nix;
|
||||||
|
|
||||||
@@ -17,83 +18,191 @@ let
|
|||||||
};
|
};
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
# Ensure this is unique among all clans you want to use.
|
clan = {
|
||||||
meta.name = "cnx-network-clan";
|
# Ensure this is unique among all clans you want to use.
|
||||||
meta.domain = "cnx-network.internal";
|
meta.name = "cnx-network-clan";
|
||||||
|
meta.domain = "cnx-network.internal";
|
||||||
|
|
||||||
inventory.machines = fleet;
|
specialArgs = { inherit inputs self; };
|
||||||
|
|
||||||
inventory.instances = {
|
# Customize nixpkgs
|
||||||
|
# pkgsForSystem =
|
||||||
|
# system:
|
||||||
|
# import nixpkgs {
|
||||||
|
# inherit system;
|
||||||
|
# config = {
|
||||||
|
# allowUnfree = true;
|
||||||
|
# };
|
||||||
|
# overlays = [];
|
||||||
|
# };
|
||||||
|
secrets.age.plugins = [
|
||||||
|
"age-plugin-yubikey"
|
||||||
|
"age-plugin-fido2-hmac"
|
||||||
|
];
|
||||||
|
|
||||||
# Admin SSH keys + root password, split per the clan-core migration off
|
inventory.machines = fleet;
|
||||||
# the deprecated `admin` service (sshd handles keys, users the password).
|
|
||||||
sshd = {
|
inventory.instances = {
|
||||||
roles.server.tags.all = { };
|
|
||||||
roles.server.settings.authorizedKeys = {
|
# Admin SSH keys + root password, split per the clan-core migration off
|
||||||
"berwn" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIENAjhGQGraQoAjJzsomKP8GAmQPeGL1rNRNHgRcLqtT";
|
# the deprecated `admin` service (sshd handles keys, users the password).
|
||||||
"kurogeek" =
|
sshd = {
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcZ/p1Ofa9liwIzPWzNtONhJ7+FUWd2lCz33r81t8+w kurogeek@kurogeek";
|
roles.server.tags.all = { };
|
||||||
|
roles.server.settings.authorizedKeys = {
|
||||||
|
"berwn" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIENAjhGQGraQoAjJzsomKP8GAmQPeGL1rNRNHgRcLqtT";
|
||||||
|
"kurogeek" =
|
||||||
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcZ/p1Ofa9liwIzPWzNtONhJ7+FUWd2lCz33r81t8+w kurogeek@kurogeek";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
gw-router = {
|
||||||
|
module = {
|
||||||
|
name = "gw-router";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines."gw-cnx-1" = {
|
||||||
|
settings = {
|
||||||
|
wan = {
|
||||||
|
interface = "enp1s0";
|
||||||
|
vlanId = null;
|
||||||
|
};
|
||||||
|
vlans = {
|
||||||
|
mgmt = {
|
||||||
|
id = 10;
|
||||||
|
address = "10.1.10.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.10.0/24";
|
||||||
|
dhcp.fixedIPs.storinator01 = {
|
||||||
|
hwAddress = "7c:c2:55:e0:d6:40";
|
||||||
|
ipAddress = "10.1.10.53";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
lan = {
|
||||||
|
id = 20;
|
||||||
|
address = "10.1.20.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.20.0/24";
|
||||||
|
};
|
||||||
|
iot = {
|
||||||
|
id = 40;
|
||||||
|
address = "10.1.40.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.40.0/24";
|
||||||
|
};
|
||||||
|
voip = {
|
||||||
|
id = 50;
|
||||||
|
address = "10.1.50.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.50.0/24";
|
||||||
|
};
|
||||||
|
dmz = {
|
||||||
|
id = 60;
|
||||||
|
address = "10.1.60.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.60.0/24";
|
||||||
|
};
|
||||||
|
unit1 = {
|
||||||
|
id = 110;
|
||||||
|
address = "10.1.110.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.110.0/24";
|
||||||
|
};
|
||||||
|
unit2 = {
|
||||||
|
id = 120;
|
||||||
|
address = "10.1.120.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.120.0/24";
|
||||||
|
};
|
||||||
|
unit3 = {
|
||||||
|
id = 130;
|
||||||
|
address = "10.1.130.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.130.0/24";
|
||||||
|
};
|
||||||
|
unit4 = {
|
||||||
|
id = 140;
|
||||||
|
address = "10.1.140.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.140.0/24";
|
||||||
|
};
|
||||||
|
unit5 = {
|
||||||
|
id = 150;
|
||||||
|
address = "10.1.150.1";
|
||||||
|
prefixLength = 24;
|
||||||
|
subnet = "10.1.150.0/24";
|
||||||
|
dhcp.fixedIPs.newt = {
|
||||||
|
hwAddress = "7c:d3:0a:21:58:0b";
|
||||||
|
ipAddress = "10.1.150.22";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
trunkPorts = [ "enp2s0" ];
|
||||||
|
accessPorts = {
|
||||||
|
enp4s0.vlanId = 10;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
root-user = {
|
||||||
|
module = {
|
||||||
|
name = "users";
|
||||||
|
input = "clan-core";
|
||||||
|
};
|
||||||
|
roles.default.tags.all = { };
|
||||||
|
roles.default.settings = {
|
||||||
|
user = "root";
|
||||||
|
prompt = false; # auto-generate, like the old admin service
|
||||||
|
share = false; # per-machine password, not fleet-wide
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
zerotier = {
|
||||||
|
roles.controller.machines."control" = { };
|
||||||
|
roles.peer.tags.all = { };
|
||||||
|
# External members admitted by ZeroTier node id (stable per device).
|
||||||
|
# Inventory machines are auto-accepted; this is only for peers outside the
|
||||||
|
# clan. Node id comes from `zerotier-cli info` on the joining device.
|
||||||
|
roles.controller.settings.allowedIds = [
|
||||||
|
"8802c8d7e0" # alex-nixos
|
||||||
|
"2bd36db8cc" # kurogeek-thinkpad
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
tor = {
|
||||||
|
roles.server.tags.nixos = { };
|
||||||
|
};
|
||||||
|
|
||||||
|
# Direct SSH to public IPs — clan's priority-1 connection path, with the
|
||||||
|
# ZeroTier mesh and Tor kept as automatic fallbacks. Raw IPs (from
|
||||||
|
# modules/hosts.nix, not the ns1/ns2 DNS names) so reaching these hosts never
|
||||||
|
# depends on their own DNS being up.
|
||||||
|
internet.roles.default.machines = builtins.mapAttrs (_: h: {
|
||||||
|
settings.host = h.ipv4;
|
||||||
|
}) hosts;
|
||||||
|
|
||||||
|
# Recovery root password for console access when a machine fails to boot.
|
||||||
|
emergency-access = {
|
||||||
|
roles.default.tags.nixos = { };
|
||||||
|
};
|
||||||
|
|
||||||
|
# Encrypted, deduplicating backups. control hosts the repos; ns1 is the
|
||||||
|
# only client, backing up its declared clan.core.state (the Knot DNSSEC
|
||||||
|
# keystore) over the mesh. Repo lives at /var/lib/borgbackup/ns1 on control.
|
||||||
|
# Cross-host so an ns1 loss is recoverable; repokey encryption means control
|
||||||
|
# never holds plaintext. Run `clan vars generate ns1` (YubiKey) before deploy.
|
||||||
|
borgbackup = {
|
||||||
|
roles.server.machines.control = { };
|
||||||
|
roles.client.machines.ns1 = { };
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
root-user = {
|
# Fleet-wide baseline applied to every machine. Secrets minted by
|
||||||
module = {
|
# `clan vars generate` are encrypted for the admins group from the very
|
||||||
name = "users";
|
# first run — generating before this took effect is what forced the
|
||||||
input = "clan-core";
|
# re-encryption dance (`clan vars fix`) on gw-cnx-1.
|
||||||
};
|
machines = builtins.mapAttrs (_: _: {
|
||||||
roles.default.tags.all = { };
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
roles.default.settings = {
|
}) fleet;
|
||||||
user = "root";
|
|
||||||
prompt = false; # auto-generate, like the old admin service
|
|
||||||
share = false; # per-machine password, not fleet-wide
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
zerotier = {
|
|
||||||
roles.controller.machines."control" = { };
|
|
||||||
roles.peer.tags.all = { };
|
|
||||||
# External members admitted by ZeroTier node id (stable per device).
|
|
||||||
# Inventory machines are auto-accepted; this is only for peers outside the
|
|
||||||
# clan. Node id comes from `zerotier-cli info` on the joining device.
|
|
||||||
roles.controller.settings.allowedIds = [
|
|
||||||
"8802c8d7e0" # alex-nixos
|
|
||||||
"2bd36db8cc" # kurogeek-thinkpad
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
tor = {
|
|
||||||
roles.server.tags.nixos = { };
|
|
||||||
};
|
|
||||||
|
|
||||||
# Direct SSH to public IPs — clan's priority-1 connection path, with the
|
|
||||||
# ZeroTier mesh and Tor kept as automatic fallbacks. Raw IPs (from
|
|
||||||
# modules/hosts.nix, not the ns1/ns2 DNS names) so reaching these hosts never
|
|
||||||
# depends on their own DNS being up.
|
|
||||||
internet.roles.default.machines = builtins.mapAttrs (_: h: {
|
|
||||||
settings.host = h.ipv4;
|
|
||||||
}) hosts;
|
|
||||||
|
|
||||||
# Recovery root password for console access when a machine fails to boot.
|
|
||||||
emergency-access = {
|
|
||||||
roles.default.tags.nixos = { };
|
|
||||||
};
|
|
||||||
|
|
||||||
# Encrypted, deduplicating backups. control hosts the repos; ns1 is the
|
|
||||||
# only client, backing up its declared clan.core.state (the Knot DNSSEC
|
|
||||||
# keystore) over the mesh. Repo lives at /var/lib/borgbackup/ns1 on control.
|
|
||||||
# Cross-host so an ns1 loss is recoverable; repokey encryption means control
|
|
||||||
# never holds plaintext. Run `clan vars generate ns1` (YubiKey) before deploy.
|
|
||||||
borgbackup = {
|
|
||||||
roles.server.machines.control = { };
|
|
||||||
roles.client.machines.ns1 = { };
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
|
|
||||||
# Fleet-wide baseline applied to every machine. Secrets minted by
|
|
||||||
# `clan vars generate` are encrypted for the admins group from the very
|
|
||||||
# first run — generating before this took effect is what forced the
|
|
||||||
# re-encryption dance (`clan vars fix`) on gw-cnx-1.
|
|
||||||
machines = builtins.mapAttrs (_: _: {
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
|
||||||
}) fleet;
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,32 +13,10 @@
|
|||||||
inputs@{
|
inputs@{
|
||||||
self,
|
self,
|
||||||
clan-core,
|
clan-core,
|
||||||
nixpkgs,
|
|
||||||
flake-parts,
|
flake-parts,
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
let
|
let
|
||||||
# Usage see: https://docs.clan.lol
|
|
||||||
clan = clan-core.lib.clan {
|
|
||||||
inherit self;
|
|
||||||
imports = [ ./clan.nix ];
|
|
||||||
specialArgs = { inherit inputs; };
|
|
||||||
|
|
||||||
# Customize nixpkgs
|
|
||||||
# pkgsForSystem =
|
|
||||||
# system:
|
|
||||||
# import nixpkgs {
|
|
||||||
# inherit system;
|
|
||||||
# config = {
|
|
||||||
# allowUnfree = true;
|
|
||||||
# };
|
|
||||||
# overlays = [];
|
|
||||||
# };
|
|
||||||
secrets.age.plugins = [
|
|
||||||
"age-plugin-yubikey"
|
|
||||||
"age-plugin-fido2-hmac"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
in
|
in
|
||||||
flake-parts.lib.mkFlake { inherit inputs; } {
|
flake-parts.lib.mkFlake { inherit inputs; } {
|
||||||
systems = [
|
systems = [
|
||||||
@@ -48,10 +26,12 @@
|
|||||||
"x86_64-darwin"
|
"x86_64-darwin"
|
||||||
];
|
];
|
||||||
|
|
||||||
flake = {
|
imports = [
|
||||||
inherit (clan.config) nixosConfigurations nixosModules clanInternals;
|
inputs.clan-core.flakeModules.default
|
||||||
clan = clan.config;
|
|
||||||
};
|
./clan.nix
|
||||||
|
./modules/clan/flake-module.nix
|
||||||
|
];
|
||||||
|
|
||||||
perSystem =
|
perSystem =
|
||||||
{ system, ... }:
|
{ system, ... }:
|
||||||
|
|||||||
@@ -4,7 +4,7 @@
|
|||||||
{ config, lib, ... }:
|
{ config, lib, ... }:
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
../../modules/router
|
# ../../modules/router
|
||||||
../../modules/monitoring/exporters.nix
|
../../modules/monitoring/exporters.nix
|
||||||
(import ../../modules/dns/acme-gw-secret.nix "gw-cnx-1")
|
(import ../../modules/dns/acme-gw-secret.nix "gw-cnx-1")
|
||||||
];
|
];
|
||||||
@@ -20,60 +20,60 @@
|
|||||||
builtins.hashString "sha256" config.networking.hostName
|
builtins.hashString "sha256" config.networking.hostName
|
||||||
);
|
);
|
||||||
|
|
||||||
cnx.router = {
|
# cnx.router = {
|
||||||
enable = true;
|
# enable = true;
|
||||||
site = "cnx";
|
# site = "cnx";
|
||||||
siteId = 1;
|
# siteId = 1;
|
||||||
wan.interface = "enp1s0";
|
# wan.interface = "enp1s0";
|
||||||
wan.vlanId = null; # this ISP runs PPPoE untagged on the port
|
# wan.vlanId = null; # this ISP runs PPPoE untagged on the port
|
||||||
trunkPorts = [
|
# trunkPorts = [
|
||||||
"enp2s0"
|
# "enp2s0"
|
||||||
# "enp3s0" # STAGING: serves as the uplink below until cutover
|
# # "enp3s0" # STAGING: serves as the uplink below until cutover
|
||||||
];
|
# ];
|
||||||
# Dedicated on-site recovery port: untagged mgmt, always available even
|
# # Dedicated on-site recovery port: untagged mgmt, always available even
|
||||||
# if the switch config is broken.
|
# # if the switch config is broken.
|
||||||
accessPorts.enp4s0 = "mgmt";
|
# accessPorts.enp4s0 = "mgmt";
|
||||||
# Replaces the newedge.house OPNsense box; renumbered to the fleet
|
# # Replaces the newedge.house OPNsense box; renumbered to the fleet
|
||||||
# convention (10.1.<vlanId>.0/24, router .1, pool .100-.199). The old
|
# # convention (10.1.<vlanId>.0/24, router .1, pool .100-.199). The old
|
||||||
# untagged LAN becomes tagged mgmt — infra switch ports get PVID 10.
|
# # untagged LAN becomes tagged mgmt — infra switch ports get PVID 10.
|
||||||
vlans = {
|
# vlans = {
|
||||||
mgmt = {
|
# mgmt = {
|
||||||
id = 10; # 10.1.10.0/24 — servers, APs, switches, Omada, admin
|
# id = 10; # 10.1.10.0/24 — servers, APs, switches, Omada, admin
|
||||||
dhcp.reservations.storinator01 = {
|
# dhcp.reservations.storinator01 = {
|
||||||
hwAddress = "7c:c2:55:e0:d6:40";
|
# hwAddress = "7c:c2:55:e0:d6:40";
|
||||||
ipAddress = "10.1.10.53";
|
# ipAddress = "10.1.10.53";
|
||||||
};
|
# };
|
||||||
};
|
# };
|
||||||
lan.id = 20; # 10.1.20.0/24 — trusted clients
|
# lan.id = 20; # 10.1.20.0/24 — trusted clients
|
||||||
iot.id = 40; # 10.1.40.0/24
|
# iot.id = 40; # 10.1.40.0/24
|
||||||
voip.id = 50; # 10.1.50.0/24
|
# voip.id = 50; # 10.1.50.0/24
|
||||||
dmz.id = 60; # 10.1.60.0/24
|
# dmz.id = 60; # 10.1.60.0/24
|
||||||
unit1.id = 110; # 10.1.110.0/24
|
# unit1.id = 110; # 10.1.110.0/24
|
||||||
unit2.id = 120; # 10.1.120.0/24
|
# unit2.id = 120; # 10.1.120.0/24
|
||||||
unit3.id = 130; # 10.1.130.0/24
|
# unit3.id = 130; # 10.1.130.0/24
|
||||||
unit4.id = 140; # 10.1.140.0/24
|
# unit4.id = 140; # 10.1.140.0/24
|
||||||
unit5 = {
|
# unit5 = {
|
||||||
id = 150; # 10.1.150.0/24
|
# id = 150; # 10.1.150.0/24
|
||||||
dhcp.reservations.newt = {
|
# dhcp.reservations.newt = {
|
||||||
hwAddress = "7c:d3:0a:21:58:0b";
|
# hwAddress = "7c:d3:0a:21:58:0b";
|
||||||
ipAddress = "10.1.150.22";
|
# ipAddress = "10.1.150.22";
|
||||||
};
|
# };
|
||||||
};
|
# };
|
||||||
};
|
# };
|
||||||
# This site runs the Omada controller for its APs/switches.
|
# # This site runs the Omada controller for its APs/switches.
|
||||||
omada.enable = true;
|
# omada.enable = true;
|
||||||
|
#
|
||||||
# Internal reverse proxy: real wildcard cert *.cnx1.cnx.network; Blocky
|
# # Internal reverse proxy: real wildcard cert *.cnx1.cnx.network; Blocky
|
||||||
# resolves the names to the router's LAN address for mgmt+lan clients.
|
# # resolves the names to the router's LAN address for mgmt+lan clients.
|
||||||
proxy = {
|
# proxy = {
|
||||||
enable = true;
|
# enable = true;
|
||||||
services.omada = {
|
# services.omada = {
|
||||||
# Omada's UI is HTTPS with a self-signed cert on the host network.
|
# # Omada's UI is HTTPS with a self-signed cert on the host network.
|
||||||
backend = "https://127.0.0.1:8043";
|
# backend = "https://127.0.0.1:8043";
|
||||||
insecureSkipVerify = true;
|
# insecureSkipVerify = true;
|
||||||
};
|
# };
|
||||||
};
|
# };
|
||||||
};
|
# };
|
||||||
|
|
||||||
# STAGING (remove at cutover, and restore enp3s0 to trunkPorts): DHCP-client
|
# STAGING (remove at cutover, and restore enp3s0 to trunkPorts): DHCP-client
|
||||||
# uplink into the existing OPNsense LAN so the box has internet + mesh while
|
# uplink into the existing OPNsense LAN so the box has internet + mesh while
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
{
|
||||||
|
imports =
|
||||||
|
let
|
||||||
|
# Get all subdirectories in the current directory
|
||||||
|
dirContents = builtins.readDir ./.;
|
||||||
|
|
||||||
|
# Filter to include only directories that have a flake-module.nix file
|
||||||
|
# and exclude special directories like 'result'
|
||||||
|
validModuleDirs = builtins.filter (
|
||||||
|
name:
|
||||||
|
name != "result"
|
||||||
|
&& dirContents.${name} == "directory"
|
||||||
|
&& builtins.pathExists (./. + "/${name}/flake-module.nix")
|
||||||
|
) (builtins.attrNames dirContents);
|
||||||
|
|
||||||
|
# Create import paths for each valid directory
|
||||||
|
imports = (map (name: ./. + "/${name}/flake-module.nix") validModuleDirs) ++ [
|
||||||
|
inputs.clan-core.flakeModules.testModule
|
||||||
|
];
|
||||||
|
in
|
||||||
|
imports;
|
||||||
|
}
|
||||||
@@ -0,0 +1,285 @@
|
|||||||
|
{ ... }:
|
||||||
|
{
|
||||||
|
_class = "clan.service";
|
||||||
|
manifest.name = "gw-router";
|
||||||
|
manifest.description = "A gateway router service to configure most of a router features";
|
||||||
|
manifest.readme = "A gateway router service to configure most of a router features";
|
||||||
|
manifest.categories = [ "System" ];
|
||||||
|
|
||||||
|
roles.default = {
|
||||||
|
description = "Site gateway router role";
|
||||||
|
|
||||||
|
interface =
|
||||||
|
{ lib, config, ... }:
|
||||||
|
let
|
||||||
|
vlanModule =
|
||||||
|
{ ... }:
|
||||||
|
{
|
||||||
|
options = {
|
||||||
|
id = lib.mkOption {
|
||||||
|
type = lib.types.ints.between 1 4094;
|
||||||
|
description = "802.1Q VLAN id.";
|
||||||
|
};
|
||||||
|
address = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
example = "10.0.10.1";
|
||||||
|
description = "Router address on this VLAN.";
|
||||||
|
};
|
||||||
|
prefixLength = lib.mkOption {
|
||||||
|
type = lib.types.ints.between 8 30;
|
||||||
|
default = 24;
|
||||||
|
};
|
||||||
|
subnet = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
example = "10.0.10.0/24";
|
||||||
|
description = "The VLAN's network in CIDR form (must contain `address`).";
|
||||||
|
};
|
||||||
|
dhcp = {
|
||||||
|
enable = lib.mkOption {
|
||||||
|
type = lib.types.bool;
|
||||||
|
default = true;
|
||||||
|
};
|
||||||
|
pool = {
|
||||||
|
from = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
example = "10.0.10.100";
|
||||||
|
};
|
||||||
|
to = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
example = "10.0.10.199";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
leaseTime = lib.mkOption {
|
||||||
|
type = lib.types.ints.positive;
|
||||||
|
default = 86400;
|
||||||
|
description = ''
|
||||||
|
Lease validity in seconds. Lower it for high-churn networks,
|
||||||
|
e.g. public-WiFi guest VLANs (3600-7200), so the pool recycles.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
fixedIPs = lib.mkOption {
|
||||||
|
type = lib.types.attrsOf (
|
||||||
|
lib.types.submodule {
|
||||||
|
options = {
|
||||||
|
hwAddress = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
example = "aa:bb:cc:dd:ee:ff";
|
||||||
|
description = "Client MAC address.";
|
||||||
|
};
|
||||||
|
ipAddress = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
description = "Fixed address handed to this client (inside the VLAN's subnet, outside the pool).";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
);
|
||||||
|
default = { };
|
||||||
|
description = "Static DHCP leases; the attribute name becomes the client's hostname.";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
allowWAN = lib.mkOption {
|
||||||
|
type = lib.types.bool;
|
||||||
|
default = true;
|
||||||
|
description = "Whether clients on this VLAN may reach the internet.";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
in
|
||||||
|
{
|
||||||
|
options = {
|
||||||
|
wan = {
|
||||||
|
interface = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
description = "Physical WAN port the PPPoE session runs on.";
|
||||||
|
};
|
||||||
|
|
||||||
|
vlanId = lib.mkOption {
|
||||||
|
type = lib.types.nullOr (lib.types.ints.between 1 4094);
|
||||||
|
default = null;
|
||||||
|
description = ''
|
||||||
|
802.1Q tag the ISP requires for the PPPoE session (AIS Thailand: 10);
|
||||||
|
null for untagged PPPoE directly on the port. Unrelated to the LAN
|
||||||
|
VLANs — this tag exists only on the WAN port.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
macAddress = lib.mkOption {
|
||||||
|
type = lib.types.nullOr lib.types.str;
|
||||||
|
default = null;
|
||||||
|
example = "aa:bb:cc:dd:ee:ff";
|
||||||
|
description = ''
|
||||||
|
Spoofed MAC for the WAN port, e.g. to keep the MAC the ISP has
|
||||||
|
pinned (cloned from the old router). null keeps the hardware MAC.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
vlans = lib.mkOption {
|
||||||
|
type = lib.types.attrsOf (lib.types.submodule vlanModule);
|
||||||
|
description = "VLANs setup for this router";
|
||||||
|
};
|
||||||
|
|
||||||
|
trunkPorts = lib.mkOption {
|
||||||
|
type = lib.types.listOf lib.types.str;
|
||||||
|
description = "LAN ports carrying all VLANs tagged (incl. any 10G SFP+ ports).";
|
||||||
|
};
|
||||||
|
|
||||||
|
accessPorts = lib.mkOption {
|
||||||
|
type = lib.types.attrsOf (
|
||||||
|
lib.types.submodule {
|
||||||
|
options = {
|
||||||
|
vlanId = lib.mkOption {
|
||||||
|
type = lib.types.int;
|
||||||
|
description = "Untagged traffic in from the device gets tagged VLANs inside the bridge, and VLANs traffic going back out to the device gets untagged, so the device itself never has to know VLANs exist.";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
);
|
||||||
|
description = ''
|
||||||
|
Ports acting as untagged access ports on a single VLAN (port name ->
|
||||||
|
VLAN id). Frames are untagged on the wire; the bridge tags them with
|
||||||
|
the VLAN's PVID. Use for an always-available on-site mgmt port.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
perInstance =
|
||||||
|
{ settings, ... }:
|
||||||
|
{
|
||||||
|
nixosModule =
|
||||||
|
{
|
||||||
|
pkgs,
|
||||||
|
lib,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
vlanIf = name: "vlan=${name}";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
|
||||||
|
networking.useNetworkd = true;
|
||||||
|
networking.useDHCP = false;
|
||||||
|
systemd.network.enable = true;
|
||||||
|
|
||||||
|
systemd.network.netdevs = {
|
||||||
|
"20-br0" = {
|
||||||
|
netdevConfig = {
|
||||||
|
Name = "br0";
|
||||||
|
Kind = "bridge";
|
||||||
|
};
|
||||||
|
bridgeConfig = {
|
||||||
|
VLANFiltering = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
// lib.optionalAttrs (settings.wan.vlanId != null) {
|
||||||
|
"15-wan-lan" = {
|
||||||
|
netdevConfig = {
|
||||||
|
Name = "wan-vlan";
|
||||||
|
Kind = "vlan";
|
||||||
|
};
|
||||||
|
vlanConfig.Id = settings.wan.vlanId;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
// lib.mapAttrs' (
|
||||||
|
name: vlan:
|
||||||
|
lib.nameValuePair "30-${vlanIf name}" {
|
||||||
|
netdevConfig = {
|
||||||
|
Name = vlanIf name;
|
||||||
|
Kind = "vlan";
|
||||||
|
};
|
||||||
|
vlanConfig.Id = vlan.id;
|
||||||
|
}
|
||||||
|
) settings.vlans;
|
||||||
|
|
||||||
|
systemd.network.networks =
|
||||||
|
let
|
||||||
|
allVLANs = lib.mapAttrsToList (_: vlan: { VLAN = vlan.id; }) settings.vlans;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
"10-wan" = {
|
||||||
|
matchConfig.Name = settings.wan.interface;
|
||||||
|
networkConfig.LinkLocalAddressing = "no";
|
||||||
|
vlan = lib.optional (settings.wan.vlanId != null) "wan-wlan";
|
||||||
|
linkConfig = {
|
||||||
|
RequiredForOnline = "carrier";
|
||||||
|
}
|
||||||
|
// lib.optionalAttrs (settings.wan.macAddress != null) {
|
||||||
|
MACAddress = settings.wan.macAddress;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
// lib.optionalAttrs (settings.wan.vlanId != null) {
|
||||||
|
"15-wan-lan" = {
|
||||||
|
matchConfig.Name = "wan-vlan";
|
||||||
|
networkConfig.LinkLocalAddressing = "no";
|
||||||
|
linkConfig.RequiredForOnline = "no";
|
||||||
|
};
|
||||||
|
}
|
||||||
|
// {
|
||||||
|
"20-br0" = {
|
||||||
|
matchConfig.Name = "br0";
|
||||||
|
networkConfig.LinkLocalAddressing = "no";
|
||||||
|
vlan = lib.mapAttrsToList (name: _: vlanIf name) settings.vlans;
|
||||||
|
bridgeVLANs = allVLANs;
|
||||||
|
linkConfig.RequiredForOnline = "no";
|
||||||
|
};
|
||||||
|
}
|
||||||
|
// lib.listToAttrs (
|
||||||
|
map (port: {
|
||||||
|
name = "25-trunk-${port}";
|
||||||
|
value = {
|
||||||
|
matchConfig.Name = port;
|
||||||
|
networkConfig.Bridge = "br0";
|
||||||
|
bridgeVLANs = allVLANs;
|
||||||
|
linkConfig.RequiredForOnline = "no";
|
||||||
|
};
|
||||||
|
}) settings.trunkPorts
|
||||||
|
)
|
||||||
|
// lib.mapAttrs' (
|
||||||
|
iface: port:
|
||||||
|
lib.nameValuePair "25-access-${iface}" {
|
||||||
|
matchConfig.Name = port;
|
||||||
|
networkConfig.Bridge = "br0";
|
||||||
|
bridgeVLANs = [
|
||||||
|
{
|
||||||
|
VLAN = port.vlanId;
|
||||||
|
PVID = port.vlanId;
|
||||||
|
EgressUntagged = port.vlanId;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
linkConfig.RequiredForOnline = "no";
|
||||||
|
}
|
||||||
|
) settings.accessPorts
|
||||||
|
// lib.mapAttrs' (
|
||||||
|
name: vlan:
|
||||||
|
lib.nameValuePair "40-${vlanIf name}" {
|
||||||
|
matchConfig.Name = vlanIf name;
|
||||||
|
address = [ "${vlan.address}/${toString vlan.prefixLength}" ];
|
||||||
|
networkConfig = {
|
||||||
|
IPv6AcceptRA = false;
|
||||||
|
IPv6SendRA = true;
|
||||||
|
DHCPPrefixDelegation = true;
|
||||||
|
};
|
||||||
|
dhcpPrefixDelegationConfig.SubnetId = "auto";
|
||||||
|
linkConfig.RequiredForOnline = "no";
|
||||||
|
}
|
||||||
|
) settings.vlans;
|
||||||
|
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
tcpdump
|
||||||
|
mtr
|
||||||
|
ethtool
|
||||||
|
conntrack-tools
|
||||||
|
knot-dns
|
||||||
|
iftop
|
||||||
|
librespeed-cli
|
||||||
|
];
|
||||||
|
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
imports = [ ./pppoe.nix ];
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
{ self, inputs, ... }:
|
||||||
|
let
|
||||||
|
module = ./default.nix;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.modules = {
|
||||||
|
gw-router = module;
|
||||||
|
};
|
||||||
|
# perSystem =
|
||||||
|
# { ... }:
|
||||||
|
# {
|
||||||
|
# clan.nixosTests.service-headplane = {
|
||||||
|
# imports = [ ./tests/vm/default.nix ];
|
||||||
|
# _module.args = { inherit self inputs; };
|
||||||
|
#
|
||||||
|
# clan.modules."@clan/headplane" = module;
|
||||||
|
# };
|
||||||
|
# };
|
||||||
|
}
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
{
|
||||||
|
roles.default.perInstance = { settings, ... }: {
|
||||||
|
nixosModule =
|
||||||
|
{ config, ... }:
|
||||||
|
let
|
||||||
|
creds = config.clan.core.vars.generators.gw-router;
|
||||||
|
|
||||||
|
pppInterface = if settings.wan.vlanId == null then settings.wan.interface else "wan-vlan";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.core.vars.generators.gw-router = {
|
||||||
|
prompts.pppoe-username = {
|
||||||
|
description = "PPPoE username (from the ISP)";
|
||||||
|
type = "hidden";
|
||||||
|
};
|
||||||
|
prompts.pppoe-password = {
|
||||||
|
description = "PPPoE password (from the ISP)";
|
||||||
|
type = "hidden";
|
||||||
|
};
|
||||||
|
files."pppoe-username".secret = true;
|
||||||
|
files."pppoe-password".secret = true;
|
||||||
|
script = ''
|
||||||
|
user="$(cat "$prompts"/pppoe-username)"
|
||||||
|
pass="$(cat "$prompts"/pppoe-password)"
|
||||||
|
printf 'user "%s"\n' "$user" > "$out"/pppoe-username
|
||||||
|
printf '"%s" * "%s"\n' "$user" "$pass" > "$out"/pppoe-password
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
services.pppd = {
|
||||||
|
enable = true;
|
||||||
|
peers.wan = {
|
||||||
|
autostart = true;
|
||||||
|
config = ''
|
||||||
|
plugin pppoe.so ${pppInterface}
|
||||||
|
ifname ppp0
|
||||||
|
file ${creds.files."pppoe-username".path}
|
||||||
|
noipdefault
|
||||||
|
defaultroute
|
||||||
|
noauth
|
||||||
|
hide-password
|
||||||
|
persist
|
||||||
|
maxfail 0
|
||||||
|
holdoff 5
|
||||||
|
lcp-echo-interval 15
|
||||||
|
lcp-echo-failure 3
|
||||||
|
+ipv6
|
||||||
|
mtu 1492
|
||||||
|
mru 1492
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
environment.etc."ppp/chap-secrets".source = creds.files."pppoe-password".path;
|
||||||
|
environment.etc."ppp/pap-secrets".source = creds.files."pppoe-password".path;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user