summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2024-03-12 10:49:16 +1100
committerJoe Mou <dev@mou.fo>2024-03-12 10:49:55 +1100
commit98013be6ae76bc4f1d3d14f88ffcc8e5480a0430 (patch)
tree92160ce0a3ace3bce539a0e54a105ce7b1583393
parentc0b3feaa374954bb406e356b996e61ad88c4a607 (diff)
creep: reverse SSH tunnel and dynamic DNS
-rw-r--r--hostnix/creep/configuration.nix37
1 files changed, 37 insertions, 0 deletions
diff --git a/hostnix/creep/configuration.nix b/hostnix/creep/configuration.nix
index 89207a5..cc54ecf 100644
--- a/hostnix/creep/configuration.nix
+++ b/hostnix/creep/configuration.nix
@@ -47,6 +47,43 @@
services.openssh.enable = true;
+ systemd.services.reverse-ssh = {
+ description = "SSH reverse tunnel";
+ wantedBy = [ "multi-user.target" ];
+ after = [ "network-online.target" ];
+ serviceConfig = {
+ RestartSec = 60;
+ Restart = "always";
+ };
+ script = ''
+ ${pkgs.openssh}/bin/ssh \
+ -o ServerAliveInterval=60 -o ExitOnForwardFailure=yes \
+ -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no \
+ -i /etc/ssh/ssh_host_ed25519_key \
+ -N -R 19422:localhost:22 joe@popfresh.mou.fo
+ '';
+ };
+
+ systemd.services.dyndns = {
+ description = "Dynamic DNS update";
+ after = [ "network-online.target" ];
+ serviceConfig = {
+ Type = "oneshot";
+ TimeoutStartSec = "60s";
+ };
+ script = ''
+ ${pkgs.curl}/bin/curl -fsS https://dyn.dns.he.net/nic/update -d hostname=creep.he.mou.fo -d password=FriE83Y4HPWmwdYn
+ '';
+ };
+
+ systemd.timers.dyndns = {
+ wantedBy = [ "multi-user.target" ];
+ timerConfig = {
+ OnStartupSec = "10";
+ OnUnitActiveSec = "5min";
+ };
+ };
+
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It's perfectly fine and recommended to leave