diff options
| author | Joe Mou <dev@mou.fo> | 2023-09-27 15:20:22 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2023-09-27 15:20:22 -0400 |
| commit | 47bf819ddd819c3c859743d7b690662e2f9bc907 (patch) | |
| tree | b67451acaf9713b0e13c079ba35c5604b001d9b5 /hostnix | |
| parent | e0c7675a23aab2a6ee498e4b5828b46d7faa72a9 (diff) | |
Dynamic DNS with bootstrapped SIG(0) key
Diffstat (limited to 'hostnix')
| -rw-r--r-- | hostnix/weebnix/configuration.nix | 65 |
1 files changed, 65 insertions, 0 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix index e2ecf70..b36b6e4 100644 --- a/hostnix/weebnix/configuration.nix +++ b/hostnix/weebnix/configuration.nix @@ -69,6 +69,71 @@ # enableSSHSupport = true; # }; + # Needs to be started manually, and the key added to nameservers. + # Based on https://nixos.org/manual/nixos/stable/index.html#module-security-acme-config-dns + systemd.services.sig0-keygen = { + unitConfig = { + ConditionPathExists = "!/var/lib/secrets/${config.networking.fqdn}.id"; + }; + serviceConfig = { + Type = "oneshot"; + }; + path = [ pkgs.bind ]; + scriptArgs = config.networking.fqdn; + script = '' + mkdir -p /var/lib/secrets + chmod 755 /var/lib/secrets + cd /var/lib/secrets + dnssec-keygen -a RSASHA512 -b 2048 -n HOST -T KEY $1. > $1.id + ''; + }; + + systemd.services.dyndns = { + requires = [ "network-online.target" ]; + after = [ "network-online.target" ]; + unitConfig = { + AssertPathExists = "/var/lib/secrets/${config.networking.fqdn}.id"; + # Defer errors for ~45min, throttle e-mails to ~hourly. + StartLimitIntervalSec = "1hr"; + StartLimitBurst = "45"; + }; + serviceConfig = { + Type = "oneshot"; + Restart = "on-failure"; + RestartSec = "1min"; + }; + path = [ pkgs.dnsutils ]; + scriptArgs = config.networking.fqdn; + script = '' + RR=''${1%%.*}.dynamic.''${1#*.} + + IP=`dig +short @1.1.1.1 ch txt whoami.cloudflare | tr -d \"` + if [ -z "$IP" ]; then + echo "Missing IP: $IP" >&2 + exit 100 + fi + + OLDIP=`dig +short @popfresh.mou.fo $RR A 2> /dev/null` + [ "x$IP" = "x$OLDIP" ] && exit 0 # no update + + nsupdate -v -k /var/lib/secrets/`< /var/lib/secrets/$1.id`.private <<. + update delete $RR. A + update add $RR. 300 A $IP + update delete $RR. TXT + update add $RR. 300 TXT "v=spf1 include:_spf.mou.fo ~all" + send + . + ''; + }; + + systemd.timers.dyndns = { + wantedBy = [ "multi-user.target" ]; + timerConfig = { + OnStartupSec = "10"; + OnUnitActiveSec = "1min"; + }; + }; + services.avahi = { enable = true; nssmdns = true; |
