diff --git a/hosts/index/config/atmosphere/tangled-knot.nix b/hosts/index/config/atmosphere/tangled-knot.nix index 0365135..43aee13 100644 --- a/hosts/index/config/atmosphere/tangled-knot.nix +++ b/hosts/index/config/atmosphere/tangled-knot.nix @@ -1,4 +1,4 @@ -{ flakeRoot, ... }: +{ config, flakeRoot, ... }: let host = "knot.encrypted.group"; @@ -29,5 +29,9 @@ in owner = "did:plc:2uoarm26m6b24zqbq7h2kpqs"; }; + + openFirewall = true; }; + + services.openssh.settings.AllowUsers = [ config.services.tangled.knot.gitUser ]; } diff --git a/hosts/index/config/ssh.nix b/hosts/index/config/ssh.nix new file mode 100644 index 0000000..5a746e9 --- /dev/null +++ b/hosts/index/config/ssh.nix @@ -0,0 +1,8 @@ +{ + services.openssh = { + extraConfig = '' + Match Address 192.168.1.0/24 + AllowUsers * + ''; + }; +} diff --git a/hosts/index/default.nix b/hosts/index/default.nix index f64c4d5..4c06644 100644 --- a/hosts/index/default.nix +++ b/hosts/index/default.nix @@ -23,8 +23,9 @@ (flakeRoot + /packages/server/iperf.nix) ./config/netdata-agent.nix - ./config/zfs.nix ./config/nfs.nix + ./config/ssh.nix + ./config/zfs.nix ./config/atmosphere/bluesky-pds.nix ./config/atmosphere/tangled-knot.nix diff --git a/packages/server/atmosphere/tangled-knot.nix b/packages/server/atmosphere/tangled-knot.nix index 5200c23..7aeb542 100644 --- a/packages/server/atmosphere/tangled-knot.nix +++ b/packages/server/atmosphere/tangled-knot.nix @@ -20,7 +20,7 @@ in listenAddr = "0.0.0.0:${toString port}"; }; - openFirewall = false; + openFirewall = lib.mkDefault false; }; services.caddy.virtualHosts = flakeLib.mkProxies hosts ''