# ZeroTier (clan mesh) addresses — the private IPv6 overlay every machine shares. # DNS zone transfers and metrics scraping ride this mesh, never the public net. # # Rather than hardcoding the addresses, we read them from the public clan vars # that clan-core's zerotier service writes. As of clan-core 26.05 these are # shared, instance-scoped generators: the per-machine IP lives at # vars/shared/zerotier-ip--/ip and the network id at # vars/shared/zerotier-network-/network-id (instance = "zerotier", # the inventory.instances.zerotier name in clan.nix). This keeps the mesh map in # lockstep with the actual identities: regenerate or re-key a node and its # address here follows automatically. Call as: import ../mesh-hosts.nix { inherit config lib; }. { config, lib }: let dir = config.clan.core.settings.directory; instance = "zerotier"; readIp = machine: builtins.readFile "${dir}/vars/shared/zerotier-ip-${machine}-${instance}/ip/value"; hosts = lib.genAttrs [ "control" "ns1" "ns2" "mx1" "web01" "gw-cnx-1" ] readIp; # RFC 4193 prefix of this ZeroTier network: fd + the 8-byte network id + the # 0x9993 marker. The network id is a public, shared var for the instance. # The /88 (11 bytes) covers fd + network id + 0x99 + 0x93, i.e. every mesh peer, # and is used to scope mesh-only firewall rules. networkId = builtins.readFile "${dir}/vars/shared/zerotier-network-${instance}/network-id/value"; full = "fd" + networkId + "9993"; # 22 hex chars = 11 bytes hextet = i: builtins.substring (i * 4) 4 full; subnet = "${hextet 0}:${hextet 1}:${hextet 2}:${hextet 3}:${hextet 4}:${builtins.substring 20 2 full}00::/88"; in { inherit hosts subnet; }