Something went wrong. Try again.
Tangled infrastructure definitions in Nix
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839404142434445{ config, pkgs, ...}: let hostname = config.networking.hostName;in { systemd.services."cloudflared-${hostname}" = { description = "Cloudflare Tunnel connector for ${hostname}"; wantedBy = ["multi-user.target"]; wants = ["network-online.target" "hydrant.service"]; after = ["network-online.target" "hydrant.service"];
serviceConfig = { Type = "simple"; LoadCredential = ["token:/etc/secrets/cloudflared-${hostname}.token"]; ExecStart = "${pkgs.cloudflared}/bin/cloudflared tunnel --no-autoupdate --protocol quic run --token-file %d/token"; Restart = "on-failure"; RestartSec = "5s"; DynamicUser = true; NoNewPrivileges = true; CapabilityBoundingSet = ""; DevicePolicy = "closed"; LockPersonality = true; MemoryDenyWriteExecute = true; PrivateDevices = true; PrivateTmp = true; ProtectClock = true; ProtectControlGroups = true; ProtectHome = true; ProtectHostname = true; ProtectKernelLogs = true; ProtectKernelModules = true; ProtectKernelTunables = true; ProtectSystem = "strict"; RestrictAddressFamilies = ["AF_INET" "AF_INET6"]; RestrictNamespaces = true; RestrictRealtime = true; RestrictSUIDSGID = true; SystemCallArchitectures = "native"; UMask = "0077"; }; };}