diff --git a/dns/dnsconfig.js b/dns/dnsconfig.js index a41ca79..390b76c 100644 --- a/dns/dnsconfig.js +++ b/dns/dnsconfig.js @@ -94,8 +94,8 @@ D( "klbr.net", REG_NONE, DnsProvider(DSP_PRIMARY), - VOLSINII(["ci", "relay", "sl", "bobbin"]), - TRIMOUNTS(["api.compare.plc", "api.spool", "bsky", "drop", "plc"]), + VOLSINII(["relay", "sl", "bobbin"]), + TRIMOUNTS(["ci", "api.compare.plc", "api.spool", "bsky", "drop", "plc"]), DZWONEK(["vpn", "id"]), // VOLSINII(["bobbin", "plc", "relay", "sl"]), TXT("@", "data endpoint for services and projects that fall under klbr.net."), diff --git a/hosts/trimounts/modules/spindle.nix b/hosts/trimounts/modules/spindle.nix new file mode 100644 index 0000000..e0398fd --- /dev/null +++ b/hosts/trimounts/modules/spindle.nix @@ -0,0 +1,49 @@ +{ pkgs, ... }: +let + hostname = "ci.klbr.net"; + tunnelUser = "spindle-tunnel"; + tunnelKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGzBNOWZ9Ke2KsaN9LG5QZnUdES6ivRnJPcgyMG5GucS spindle-valefar-to-trimounts"; +in +{ + security.acme.certs.${hostname} = { }; + services.nginx.virtualHosts.${hostname} = { + useACMEHost = hostname; + forceSSL = true; + quic = true; + kTLS = true; + locations."/" = { + proxyPass = "http://127.0.0.1:17391"; + proxyWebsockets = true; + extraConfig = '' + proxy_buffering off; + proxy_read_timeout 3600s; + proxy_send_timeout 3600s; + ''; + }; + }; + + users.groups.${tunnelUser} = { }; + users.users.${tunnelUser} = { + isSystemUser = true; + group = tunnelUser; + home = "/var/empty"; + shell = pkgs.bashInteractive; + openssh.authorizedKeys.keys = [ + "restrict,port-forwarding,permitlisten=\"127.0.0.1:17391\" ${tunnelKey}" + ]; + }; + + services.openssh.extraConfig = '' + Match User ${tunnelUser} + AuthenticationMethods publickey + AllowTcpForwarding remote + AllowStreamLocalForwarding no + PermitListen 127.0.0.1:17391 + PermitOpen none + AllowAgentForwarding no + X11Forwarding no + PermitTTY no + ForceCommand ${pkgs.coreutils}/bin/false + Match all + ''; +}