summaryrefslogtreecommitdiff
path: root/hostnix/creep
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/creep')
-rw-r--r--hostnix/creep/configuration.nix105
-rw-r--r--hostnix/creep/hardware-configuration.nix41
-rw-r--r--hostnix/creep/wifi-vpn.nix101
3 files changed, 247 insertions, 0 deletions
diff --git a/hostnix/creep/configuration.nix b/hostnix/creep/configuration.nix
new file mode 100644
index 0000000..7fa748d
--- /dev/null
+++ b/hostnix/creep/configuration.nix
@@ -0,0 +1,105 @@
+# NetComm router (CG-NAT) - 192.168.20.1
+
+{ pkgs, ... }:
+
+{
+ imports = [
+ ./hardware-configuration.nix
+ ./wifi-vpn.nix
+ ];
+
+ nix.settings.experimental-features = [ "nix-command" "flakes" ];
+
+ boot.loader.systemd-boot.enable = true;
+ # Raspberry Pi has no NVRAM.
+ boot.loader.efi.canTouchEfiVariables = false;
+
+ boot.kernelPackages = pkgs.linuxPackages_rpi4;
+ # https://github.com/NixOS/nixpkgs/issues/122130#issuecomment-1568815007
+ # It's unclear if these are strictly necessary with the downstream kernel,
+ # but let's leave them in to keep working with mainline.
+ boot.initrd.availableKernelModules = [ "uas" "pcie-brcmstb" "reset-raspberrypi" ];
+
+ networking.hostName = "creep";
+ networking.domain = "mou.fo";
+
+ networking.wireless = {
+ enable = true;
+ interfaces = [ "wlan0" ];
+ networks = {
+ "Girls Gone Wireless".psk = "Paddlepops103!";
+ "Cali's internet".psk = "calibanthetempest2019";
+ };
+ };
+
+ time.timeZone = "Australia/Sydney";
+ users.users.joe = {
+ isNormalUser = true;
+ description = "Joe Mou";
+ extraGroups = [ "wheel" ];
+ openssh.authorizedKeys.keys = [
+ "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky"
+ ];
+ };
+
+ environment.systemPackages = with pkgs; [
+ dig
+ file
+ gitFull
+ libraspberrypi
+ psmisc
+ tmux
+ tree
+ ];
+
+ programs.vim.defaultEditor = true;
+ programs.nano.enable = false;
+
+ services.openssh.enable = true;
+
+ # Note: seems to leave stale connections open on server on dirty poweroff.
+ systemd.services.reverse-ssh = {
+ description = "SSH reverse tunnel";
+ wantedBy = [ "multi-user.target" ];
+ after = [ "network-online.target" ];
+ serviceConfig = {
+ RestartSec = 60;
+ Restart = "always";
+ };
+ script = ''
+ ${pkgs.openssh}/bin/ssh \
+ -o ServerAliveInterval=60 -o ExitOnForwardFailure=yes \
+ -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no \
+ -i /etc/ssh/ssh_host_ed25519_key \
+ -q -N -R 19422:localhost:22 joe@creepgw.mou.fo
+ '';
+ };
+
+ systemd.services.dyndns = {
+ description = "Dynamic DNS update";
+ after = [ "network-online.target" ];
+ serviceConfig = {
+ Type = "oneshot";
+ TimeoutStartSec = "60s";
+ };
+ script = ''
+ ${pkgs.curl}/bin/curl -4 -fsS https://dyn.dns.he.net/nic/update -d hostname=creep.he.mou.fo -d password=FriE83Y4HPWmwdYn
+ '';
+ };
+
+ systemd.timers.dyndns = {
+ wantedBy = [ "multi-user.target" ];
+ timerConfig = {
+ OnStartupSec = "10";
+ OnUnitActiveSec = "5min";
+ };
+ };
+
+ # This value determines the NixOS release from which the default
+ # settings for stateful data, like file locations and database versions
+ # on your system were taken. It's perfectly fine and recommended to leave
+ # this value at the release version of the first install of this system.
+ # Before changing this value read the documentation for this option
+ # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
+ system.stateVersion = "23.11"; # Did you read the comment?
+}
diff --git a/hostnix/creep/hardware-configuration.nix b/hostnix/creep/hardware-configuration.nix
new file mode 100644
index 0000000..0dce739
--- /dev/null
+++ b/hostnix/creep/hardware-configuration.nix
@@ -0,0 +1,41 @@
+# Do not modify this file! It was generated by ‘nixos-generate-config’
+# and may be overwritten by future invocations. Please make changes
+# to /etc/nixos/configuration.nix instead.
+{ config, lib, pkgs, modulesPath, ... }:
+
+{
+ imports =
+ [ (modulesPath + "/installer/scan/not-detected.nix")
+ ];
+
+ boot.initrd.availableKernelModules = [ "xhci_pci" "usb_storage" ];
+ boot.initrd.kernelModules = [ ];
+ boot.kernelModules = [ ];
+ boot.extraModulePackages = [ ];
+
+ fileSystems."/" =
+ { device = "/dev/disk/by-uuid/6457623e-7a80-41bc-8124-9aba2472a46d";
+ fsType = "ext4";
+ };
+
+ fileSystems."/boot" =
+ { device = "/dev/disk/by-uuid/AD39-9DD6";
+ fsType = "vfat";
+ };
+
+ swapDevices = [ {
+ device = "/var/lib/swap";
+ size = 4 * 1024;
+ randomEncryption.enable = true;
+ } ];
+
+ # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
+ # (the default) this is the recommended approach. When using systemd-networkd it's
+ # still possible to use this option, but it's recommended to use it in conjunction
+ # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
+ networking.useDHCP = lib.mkDefault true;
+ # networking.interfaces.end0.useDHCP = lib.mkDefault true;
+ # networking.interfaces.wlan0.useDHCP = lib.mkDefault true;
+
+ nixpkgs.hostPlatform = lib.mkDefault "aarch64-linux";
+}
diff --git a/hostnix/creep/wifi-vpn.nix b/hostnix/creep/wifi-vpn.nix
new file mode 100644
index 0000000..ad94f4b
--- /dev/null
+++ b/hostnix/creep/wifi-vpn.nix
@@ -0,0 +1,101 @@
+# TODO not working?
+
+{ pkgs, ... }:
+
+{
+ boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
+
+ # Manual configuration on popfresh.mou.town:
+ # /etc/wireguard/wg0.conf
+ # # firewall-cmd --add-port=51820/udp
+ # # systemctl enable --now wg-quick@wg0
+ networking.wg-quick.interfaces = {
+ wg0 = {
+ address = [ "172.28.89.2/24" ];
+ privateKeyFile = "/root/wg0.key";
+ # wg-quick normally adds routes for AllowedIPs to the default table.
+ # Specify a non-default table to instead use policy-based routing.
+ # Using netns may be an alternative.
+ table = "89";
+ # IP masquerade (SNAT) anything from the WiFi AP.
+ postUp = ''
+ ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE
+ ${pkgs.iproute2}/bin/ip rule add iif wlp1s0u1u3 lookup 89
+ '';
+ preDown = ''
+ ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE
+ ${pkgs.iproute2}/bin/ip rule del iif wlp1s0u1u3 lookup 89
+ '';
+ peers = [ {
+ publicKey = "iIRCcLGBvo0LBCysJKa5sbTs/Y4VR4PUDHMkoaU6sgo=";
+ allowedIPs = [ "0.0.0.0/0" ];
+ endpoint = "creepgw.mou.fo:51820";
+ persistentKeepalive = 25; # keep NAT rules alive
+ } ];
+ };
+ };
+
+ services.hostapd = {
+ enable = true;
+ radios.wlp1s0u1u3 = {
+ band = "5g";
+ # Wasn't able to get Auto Channel Selection working, so specify a band
+ # that should allow for High Throughput 40 MHz (HT40).
+ channel = 40;
+ countryCode = "AU";
+ # The network must have the same name as the radio.
+ networks.wlp1s0u1u3 = {
+ ssid = "The Up Over";
+ authentication = {
+ mode = "wpa3-sae-transition";
+ wpaPassword = "comingtoamerica";
+ saePasswords = [ { password = "comingtoamerica"; } ];
+ };
+ };
+ };
+ };
+
+ networking.interfaces.wlp1s0u1u3.ipv4.addresses = [ {
+ address = "172.16.175.1";
+ prefixLength = 24;
+ } ];
+
+ services.kea.dhcp4 = {
+ enable = true;
+ settings = {
+ interfaces-config = {
+ interfaces = [ "wlp1s0u1u3" ];
+ };
+ lease-database = {
+ type = "memfile";
+ persist = true;
+ name = "/var/lib/kea/dhcp4.leases";
+ };
+ subnet4 = [
+ {
+ id = 1;
+ subnet = "172.16.175.0/24";
+ pools = [ { pool = "172.16.175.100 - 172.16.175.240"; } ];
+ option-data = [ {
+ name = "routers";
+ data = "172.16.175.1";
+ } {
+ name = "domain-name-servers";
+ data = "1.1.1.1, 1.0.0.1";
+ } ];
+ }
+ ];
+ };
+ };
+ # Ensure interface is available to serve DHCP.
+ systemd.services.kea-dhcp4-server = {
+ requires = [ "network-addresses-wlp1s0u1u3.service" ];
+ };
+
+ # Generated entropy helps prevent WiFi AP from blocking.
+ services.haveged.enable = true;
+
+ # Reverse path forwarding has complications with multiple interfaces, like
+ # connectivity issues when WiFi and wired are on the same network.
+ networking.firewall.checkReversePath = false;
+}