diff options
Diffstat (limited to 'hostnix/creep')
| -rw-r--r-- | hostnix/creep/configuration.nix | 105 | ||||
| -rw-r--r-- | hostnix/creep/hardware-configuration.nix | 41 | ||||
| -rw-r--r-- | hostnix/creep/wifi-vpn.nix | 101 |
3 files changed, 247 insertions, 0 deletions
diff --git a/hostnix/creep/configuration.nix b/hostnix/creep/configuration.nix new file mode 100644 index 0000000..7fa748d --- /dev/null +++ b/hostnix/creep/configuration.nix @@ -0,0 +1,105 @@ +# NetComm router (CG-NAT) - 192.168.20.1 + +{ pkgs, ... }: + +{ + imports = [ + ./hardware-configuration.nix + ./wifi-vpn.nix + ]; + + nix.settings.experimental-features = [ "nix-command" "flakes" ]; + + boot.loader.systemd-boot.enable = true; + # Raspberry Pi has no NVRAM. + boot.loader.efi.canTouchEfiVariables = false; + + boot.kernelPackages = pkgs.linuxPackages_rpi4; + # https://github.com/NixOS/nixpkgs/issues/122130#issuecomment-1568815007 + # It's unclear if these are strictly necessary with the downstream kernel, + # but let's leave them in to keep working with mainline. + boot.initrd.availableKernelModules = [ "uas" "pcie-brcmstb" "reset-raspberrypi" ]; + + networking.hostName = "creep"; + networking.domain = "mou.fo"; + + networking.wireless = { + enable = true; + interfaces = [ "wlan0" ]; + networks = { + "Girls Gone Wireless".psk = "Paddlepops103!"; + "Cali's internet".psk = "calibanthetempest2019"; + }; + }; + + time.timeZone = "Australia/Sydney"; + users.users.joe = { + isNormalUser = true; + description = "Joe Mou"; + extraGroups = [ "wheel" ]; + openssh.authorizedKeys.keys = [ + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky" + ]; + }; + + environment.systemPackages = with pkgs; [ + dig + file + gitFull + libraspberrypi + psmisc + tmux + tree + ]; + + programs.vim.defaultEditor = true; + programs.nano.enable = false; + + services.openssh.enable = true; + + # Note: seems to leave stale connections open on server on dirty poweroff. + systemd.services.reverse-ssh = { + description = "SSH reverse tunnel"; + wantedBy = [ "multi-user.target" ]; + after = [ "network-online.target" ]; + serviceConfig = { + RestartSec = 60; + Restart = "always"; + }; + script = '' + ${pkgs.openssh}/bin/ssh \ + -o ServerAliveInterval=60 -o ExitOnForwardFailure=yes \ + -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no \ + -i /etc/ssh/ssh_host_ed25519_key \ + -q -N -R 19422:localhost:22 joe@creepgw.mou.fo + ''; + }; + + systemd.services.dyndns = { + description = "Dynamic DNS update"; + after = [ "network-online.target" ]; + serviceConfig = { + Type = "oneshot"; + TimeoutStartSec = "60s"; + }; + script = '' + ${pkgs.curl}/bin/curl -4 -fsS https://dyn.dns.he.net/nic/update -d hostname=creep.he.mou.fo -d password=FriE83Y4HPWmwdYn + ''; + }; + + systemd.timers.dyndns = { + wantedBy = [ "multi-user.target" ]; + timerConfig = { + OnStartupSec = "10"; + OnUnitActiveSec = "5min"; + }; + }; + + # This value determines the NixOS release from which the default + # settings for stateful data, like file locations and database versions + # on your system were taken. It's perfectly fine and recommended to leave + # this value at the release version of the first install of this system. + # Before changing this value read the documentation for this option + # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). + system.stateVersion = "23.11"; # Did you read the comment? +} diff --git a/hostnix/creep/hardware-configuration.nix b/hostnix/creep/hardware-configuration.nix new file mode 100644 index 0000000..0dce739 --- /dev/null +++ b/hostnix/creep/hardware-configuration.nix @@ -0,0 +1,41 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "usb_storage" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/6457623e-7a80-41bc-8124-9aba2472a46d"; + fsType = "ext4"; + }; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/AD39-9DD6"; + fsType = "vfat"; + }; + + swapDevices = [ { + device = "/var/lib/swap"; + size = 4 * 1024; + randomEncryption.enable = true; + } ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.end0.useDHCP = lib.mkDefault true; + # networking.interfaces.wlan0.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "aarch64-linux"; +} diff --git a/hostnix/creep/wifi-vpn.nix b/hostnix/creep/wifi-vpn.nix new file mode 100644 index 0000000..ad94f4b --- /dev/null +++ b/hostnix/creep/wifi-vpn.nix @@ -0,0 +1,101 @@ +# TODO not working? + +{ pkgs, ... }: + +{ + boot.kernel.sysctl."net.ipv4.ip_forward" = 1; + + # Manual configuration on popfresh.mou.town: + # /etc/wireguard/wg0.conf + # # firewall-cmd --add-port=51820/udp + # # systemctl enable --now wg-quick@wg0 + networking.wg-quick.interfaces = { + wg0 = { + address = [ "172.28.89.2/24" ]; + privateKeyFile = "/root/wg0.key"; + # wg-quick normally adds routes for AllowedIPs to the default table. + # Specify a non-default table to instead use policy-based routing. + # Using netns may be an alternative. + table = "89"; + # IP masquerade (SNAT) anything from the WiFi AP. + postUp = '' + ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE + ${pkgs.iproute2}/bin/ip rule add iif wlp1s0u1u3 lookup 89 + ''; + preDown = '' + ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE + ${pkgs.iproute2}/bin/ip rule del iif wlp1s0u1u3 lookup 89 + ''; + peers = [ { + publicKey = "iIRCcLGBvo0LBCysJKa5sbTs/Y4VR4PUDHMkoaU6sgo="; + allowedIPs = [ "0.0.0.0/0" ]; + endpoint = "creepgw.mou.fo:51820"; + persistentKeepalive = 25; # keep NAT rules alive + } ]; + }; + }; + + services.hostapd = { + enable = true; + radios.wlp1s0u1u3 = { + band = "5g"; + # Wasn't able to get Auto Channel Selection working, so specify a band + # that should allow for High Throughput 40 MHz (HT40). + channel = 40; + countryCode = "AU"; + # The network must have the same name as the radio. + networks.wlp1s0u1u3 = { + ssid = "The Up Over"; + authentication = { + mode = "wpa3-sae-transition"; + wpaPassword = "comingtoamerica"; + saePasswords = [ { password = "comingtoamerica"; } ]; + }; + }; + }; + }; + + networking.interfaces.wlp1s0u1u3.ipv4.addresses = [ { + address = "172.16.175.1"; + prefixLength = 24; + } ]; + + services.kea.dhcp4 = { + enable = true; + settings = { + interfaces-config = { + interfaces = [ "wlp1s0u1u3" ]; + }; + lease-database = { + type = "memfile"; + persist = true; + name = "/var/lib/kea/dhcp4.leases"; + }; + subnet4 = [ + { + id = 1; + subnet = "172.16.175.0/24"; + pools = [ { pool = "172.16.175.100 - 172.16.175.240"; } ]; + option-data = [ { + name = "routers"; + data = "172.16.175.1"; + } { + name = "domain-name-servers"; + data = "1.1.1.1, 1.0.0.1"; + } ]; + } + ]; + }; + }; + # Ensure interface is available to serve DHCP. + systemd.services.kea-dhcp4-server = { + requires = [ "network-addresses-wlp1s0u1u3.service" ]; + }; + + # Generated entropy helps prevent WiFi AP from blocking. + services.haveged.enable = true; + + # Reverse path forwarding has complications with multiple interfaces, like + # connectivity issues when WiFi and wired are on the same network. + networking.firewall.checkReversePath = false; +} |
