diff --git a/hosts/dzwonek/modules/headscale.nix/default.nix b/hosts/dzwonek/modules/headscale.nix/default.nix index 6cdde1d..464d073 100644 --- a/hosts/dzwonek/modules/headscale.nix/default.nix +++ b/hosts/dzwonek/modules/headscale.nix/default.nix @@ -18,9 +18,10 @@ in address = "0.0.0.0"; port = 1111; acl = let - admin = "90008@klbr.net"; + me = "90008@klbr.net"; + owner = "ana@nekomimi.pet"; in { - groups.admin = [admin]; + groups.admin = [me]; tagOwners = { private-infra = [ "group:admin" ]; other-infra = [ "group:admin" ]; @@ -44,6 +45,14 @@ in "tag:other-infra:*" ]; } + { + src = [ owner ]; + dst = ["${me}:*" "tag:private-infra:*"]; + } + { + src = [ me ]; + dst = [ "${owner}:*" ]; + } { src = [ "tag:private-infra" ]; dst = [ "tag:other-infra:*" ]; @@ -62,7 +71,7 @@ in } { src = [ - admin + me owner "tag:private-infra" ]; dst = [ "autogroup:internet:*" ]; diff --git a/hosts/dzwonek/modules/nucleus.nix b/hosts/dzwonek/modules/nucleus.nix index 7bdfde6..c0913da 100644 --- a/hosts/dzwonek/modules/nucleus.nix +++ b/hosts/dzwonek/modules/nucleus.nix @@ -4,7 +4,7 @@ let domain = "nucleus.ptr.pet"; pkg = pkgs.callPackage "${inputs.nucleus}/nix" { nucleus-modules = (pkgs.callPackage "${inputs.nucleus}/nix/modules.nix" {}).overrideAttrs (old: { - outputHash = "sha256-ThVGlT5FlQaZb6fHp+LRQGLKea4GQfVmAl79LBfceDs="; + outputHash = "sha256-RbH5PfV4wa2lva49SbrDX5SI870nmY1IbgQjho6U2/0="; }); PUBLIC_DOMAIN = "https://${domain}"; }; diff --git a/users/mayer/default.nix b/users/mayer/default.nix index f461163..f1890af 100644 --- a/users/mayer/default.nix +++ b/users/mayer/default.nix @@ -129,6 +129,7 @@ in "git" "ssh" "atcr" + "tailscale" ] [ # "zen" @@ -209,5 +210,13 @@ in User git IdentityFile ~/.ssh/tangled-dev ''; + + services.tailscale = { + ana = { + enable = true; + controlServer = "https://headscale.nekomimi.pet"; + port = 1056; + }; + }; }; } diff --git a/users/modules/tailscale/default.nix b/users/modules/tailscale/default.nix index 77fb744..00a10da 100644 --- a/users/modules/tailscale/default.nix +++ b/users/modules/tailscale/default.nix @@ -7,69 +7,96 @@ let l = lib; t = l.types; - cfg = config.services.tailscale; - proxychainsCfg = pkgs.writers.writeText "proxychains.conf" '' - proxy_dns - quiet_mode - [ProxyList] - socks5 127.0.0.1 1055 - http 127.0.0.1 1055 - ''; - wrappedProxychains = pkgs.writers.writeBashBin "tailscale-proxychains" '' - ${pkgs.proxychains-ng}/bin/proxychains4 -f "${proxychainsCfg}" $@ - ''; - wrapped = pkgs.writers.writeBashBin "tailscale" '' - ${pkgs.tailscale}/bin/tailscale --socket $XDG_RUNTIME_DIR/tailscaled.sock $@ - ''; -in -{ - options = { - services.tailscale = { - enable = l.mkEnableOption "tailscale client"; - controlServer = l.mkOption { - type = t.str; - default = "https://controlplane.tailscale.com"; - description = "tailscale control server URL"; - }; - authKeyFile = l.mkOption { - type = t.nullOr t.str; - default = null; - description = "Path to the auth key file"; - }; - extraUpFlags = l.mkOption { - type = t.listOf t.str; - default = [ ]; - description = "Extra flags to pass to tailscale up"; + + instanceModule = { name, config, ... }: + let + proxychainsCfg = pkgs.writers.writeText "proxychains-${name}.conf" '' + proxy_dns + quiet_mode + [ProxyList] + socks5 127.0.0.1 ${toString config.port} + http 127.0.0.1 ${toString config.port} + ''; + proxyScript' = pkgs.writers.writeBashBin "tailscale-${name}-proxychains" '' + ${pkgs.proxychains-ng}/bin/proxychains4 -f "${proxychainsCfg}" "$@" + ''; + cli' = pkgs.writers.writeBashBin "tailscale-${name}" '' + ${pkgs.tailscale}/bin/tailscale --socket "$XDG_RUNTIME_DIR/tailscaled-${name}.sock" "$@" + ''; + in + { + options = { + enable = l.mkEnableOption "tailscale client"; + controlServer = l.mkOption { + type = t.str; + default = "https://controlplane.tailscale.com"; + description = "tailscale control server URL"; + }; + authKeyFile = l.mkOption { + type = t.nullOr t.str; + default = null; + description = "path to the auth key file"; + }; + extraUpFlags = l.mkOption { + type = t.listOf t.str; + default = [ ]; + description = "extra flags to pass to tailscale up"; + }; + port = l.mkOption { + type = t.port; + default = 1055; + description = "port for the SOCKS5/HTTP proxy — must be unique per instance"; + }; + proxyScript = l.mkOption { + type = t.package; + readOnly = true; + description = "proxychains-wrapped script for this instance"; + }; + cli = l.mkOption { + type = t.package; + readOnly = true; + description = "wrapped tailscale- binary for this instance"; + }; }; - proxyScript = l.mkOption { - type = t.package; - description = "path to a script that uses proxychains to proxy traffic"; - readOnly = true; + config = { + proxyScript = proxyScript'; + cli = cli'; }; }; + + cfg = config.services.tailscale; + enabled = l.filterAttrs (_: icfg: icfg.enable) cfg; +in +{ + options.services.tailscale = l.mkOption { + type = t.attrsOf (t.submodule instanceModule); + default = { }; + description = "tailscale instances keyed by name"; }; - config = l.mkIf cfg.enable { - home.packages = [ - wrapped - wrappedProxychains - ]; - services.tailscale.proxyScript = wrappedProxychains; - systemd.user.services.tailscaled = { - Unit = { - Description = "tailscaled"; - After = [ "network.target" ]; - }; - Service = { - ExecStart = "${pkgs.tailscale}/bin/tailscaled --tun=userspace-networking --socks5-server=localhost:1055 --outbound-http-proxy-listen=localhost:1055 --socket %t/tailscaled.sock"; - Restart = "on-failure"; - RestartSec = "5s"; - } - // l.optionalAttrs (cfg.authKeyFile != null) { - ExecStartPost = "${wrapped}/bin/tailscale up --reset --login-server=${cfg.controlServer} --auth-key=file:${cfg.authKeyFile} ${l.concatStringsSep " " cfg.extraUpFlags}"; - }; + config = l.mkIf (enabled != { }) { + home.packages = l.concatLists ( + l.mapAttrsToList (_: icfg: [ icfg.cli icfg.proxyScript ]) enabled + ); - Install.WantedBy = [ "network.target" ]; - }; + systemd.user.services = l.mapAttrs' ( + name: icfg: + l.nameValuePair "tailscaled-${name}" { + Unit = { + Description = "tailscaled (${name})"; + After = [ "network.target" ]; + }; + Service = + { + ExecStart = "${pkgs.tailscale}/bin/tailscaled --tun=userspace-networking --socks5-server=localhost:${toString icfg.port} --outbound-http-proxy-listen=localhost:${toString icfg.port} --socket %t/tailscaled-${name}.sock"; + Restart = "on-failure"; + RestartSec = "5s"; + } + // l.optionalAttrs (icfg.authKeyFile != null) { + ExecStartPost = "${icfg.cli}/bin/tailscale-${name} up --reset --login-server=${icfg.controlServer} --auth-key=file:${icfg.authKeyFile} ${l.concatStringsSep " " icfg.extraUpFlags}"; + }; + Install.WantedBy = [ "network.target" ]; + } + ) enabled; }; -} +} \ No newline at end of file