diff options
| -rw-r--r-- | hostnix/elmo/dyndns.nix | 19 | ||||
| -rw-r--r-- | hostnix/elmo/system.nix | 4 |
2 files changed, 14 insertions, 9 deletions
diff --git a/hostnix/elmo/dyndns.nix b/hostnix/elmo/dyndns.nix index bb396e2..3dc0144 100644 --- a/hostnix/elmo/dyndns.nix +++ b/hostnix/elmo/dyndns.nix @@ -1,23 +1,24 @@ { config, pkgs, ... }: { + systemd.tmpfiles.rules = [ + "d /var/secrets 0750 root wheel" + ]; + # Needs to be started manually, and the key added to nameservers. # Based on https://nixos.org/manual/nixos/stable/index.html#module-security-acme-config-dns systemd.services.sig0-keygen = { unitConfig = { - ConditionPathExists = "!/var/secrets/${config.networking.fqdn}.id"; + ConditionPathExists = "!/var/secrets/dyndns"; }; serviceConfig = { Type = "oneshot"; }; - path = [ pkgs.bind ]; scriptArgs = config.networking.fqdn; script = '' - mkdir -p /var/secrets - chmod 750 /var/secrets - chown :wheel /var/secrets - cd /var/secrets - dnssec-keygen -a RSASHA512 -b 2048 -n HOST -T KEY $1. > $1.id + mkdir /var/secrets/dyndns + cd /var/secrets/dyndns + ${pkgs.bind}/bin/dnssec-keygen -a RSASHA512 -b 2048 -n HOST -T KEY $1. > basename ''; }; @@ -25,7 +26,7 @@ requires = [ "network-online.target" ]; after = [ "network-online.target" ]; unitConfig = { - AssertPathExists = "/var/secrets/${config.networking.fqdn}.id"; + AssertPathExists = "/var/secrets/dyndns"; # Defer errors for ~45min, throttle e-mails to ~hourly. StartLimitIntervalSec = "1hr"; StartLimitBurst = "45"; @@ -57,7 +58,7 @@ exit 0 fi - nsupdate -v -k /var/secrets/`< /var/secrets/$1.id`.private <<. + nsupdate -v -k /var/secrets/dyndns/`< /var/secrets/dyndns/basename`.private <<. update delete $RR. A update add $RR. 300 A $IP4 update delete $RR. AAAA diff --git a/hostnix/elmo/system.nix b/hostnix/elmo/system.nix index b8d5682..4f6ddb7 100644 --- a/hostnix/elmo/system.nix +++ b/hostnix/elmo/system.nix @@ -11,7 +11,11 @@ networking.hostName = "elmo"; networking.domain = "mou.fo"; + # TODO switch to networkd networking.networkmanager.enable = true; + # Temp addresses are preferred for IPv6 source address selection (RFC 6724), + # which complicates dynamic DNS. + networking.tempAddresses = "disabled"; services.avahi = { enable = true; |
