Wireguard: move host data in to a .toml file
Graham Christensen committed
Dec 19, 2021 at 14:51 UTC
999bd81b8c82d5e6657275652fa3fd7bcc7d6bb6
2 files changed
+113
-120
modules/wireguard-hosts.toml
new
+112
@@ -0,0 +1,112 @@
1
+network = 16
2
+
3
+[hosts.bastion]
4
+# wg won't retry resolution if it fails... so
5
+# hard-code the IP to bastion.nixos.org so we don't lock
6
+# ourselves out.
7
+endpoint = "34.254.208.229"
8
+ip = "10.254.1.1"
9
+port = 51820
10
+publicKey = "nG7I9gegJIynKOZ6tzpvmLdCZ/xScTgRZeFvYLFyil4="
11
+
12
+# tombstone: 10.254.1.2 chef
13
+
14
+[hosts.ceres]
15
+endpoint = "46.4.66.184"
16
+ip = "10.254.1.3"
17
+port = 51820
18
+publicKey = "wkUjkjJtJ9yC1xh2pSbTfyuPkeUnvgxGIHFKxVCGJT8="
19
+
20
+[hosts.eris]
21
+endpoint = "138.201.32.77"
22
+ip = "10.254.1.4"
23
+port = 51820
24
+publicKey = "H/Y+sbNETKZugxGFbOS0m5BSr28jRDL19U37wEw07D8="
25
+
26
+[hosts.haumea]
27
+endpoint = "46.4.89.205"
28
+ip = "10.254.1.9"
29
+port = 51820
30
+publicKey = "Fb41wGKT1TdC4MG5i2NRx6yduddmqm+N+UOtqtDuBG4="
31
+
32
+[hosts.mac1]
33
+ip = "10.254.2.1"
34
+publicKey = "ZIzROtHaFWjrhhdXAE8Tq+EhUsSIURLcwsISfudndTk="
35
+
36
+[hosts.mac2]
37
+ip = "10.254.2.2"
38
+publicKey = "m0xJg1OBZIqPu8maxpldLQ1Y39aPS3cnj7hqpVUSuFg="
39
+
40
+[hosts.mac3]
41
+ip = "10.254.2.3"
42
+publicKey = "6urTLKp3ihXw0fy4ImhpiQu/sOxrJYewtg2cbT3jv3g="
43
+
44
+[hosts.mac4]
45
+ip = "10.254.2.4"
46
+publicKey = "ojkldeD0xJw54nAeGSHQw7BMSXnc6c2e6GP4nJ/1xEo="
47
+
48
+[hosts.mac5]
49
+ip = "10.254.2.5"
50
+publicKey = "UgbjJz7BPlD5oDNPr1Bpr4XqeuoL9G5+oUDyU9EVYgg="
51
+
52
+[hosts.mac6]
53
+ip = "10.254.2.6"
54
+publicKey = "5t67sluyRwuDXeY17CG7sbpt0gZNybHzvJYd7NAESis="
55
+
56
+[hosts.mac7]
57
+ip = "10.254.2.7"
58
+publicKey = "q/8YvHa/M0Epyqflp+fEXvBmJuOBaBJPcaAkScCYvHA="
59
+
60
+[hosts.mac8]
61
+ip = "10.254.2.8"
62
+publicKey = "aw/8/5oEn0cZa/WnUE7E7MEukDvzUzaAUEL6PMhLFmE="
63
+
64
+[hosts.macofborg1]
65
+ip = "10.254.2.51"
66
+publicKey = "RPD07xoZYB3aq9hS4pX+qnCHwSbNunK69HGdf8pRtCQ="
67
+
68
+
69
+[hosts.mac-m1-1]
70
+ip = "10.254.2.101"
71
+publicKey = "r9EEig5zzGS+MlMqK1jCzXB4Rm11Q/c812i7dxGj8gQ="
72
+
73
+[hosts.mac-m1-2]
74
+ip = "10.254.2.102"
75
+publicKey = "J0JajIlwirjrry4QsuVzzyyWSGesQWHk16IR99rcwjY="
76
+
77
+[hosts.mac-m1-3]
78
+ip = "10.254.2.103"
79
+publicKey = "E/eHbib8pEnPmT6nWjXlv3H5Ww1DfWxZdbz+Cn+jCX0="
80
+
81
+[hosts.mac-m1-4]
82
+ip = "10.254.2.104"
83
+publicKey = "qQ0LO8kU+zFPxCk7JBD9OrfGS3Ryl08ePyF+KQxGl2U="
84
+
85
+[hosts.mac-m1-5]
86
+ip = "10.254.2.105"
87
+publicKey = "5VWVUb/fiZmAJqCfqMPH2yIa8xze6hEU11ZKYPOtQyQ="
88
+
89
+[hosts.mac-m1-6]
90
+ip = "10.254.2.106"
91
+publicKey = "S20ha1NoMUgR67696vi7hmSdSxK/GJM550S0uR2odlA="
92
+
93
+[hosts.webserver]
94
+enpdoint = "54.217.220.47"
95
+ip = "10.254.3.1"
96
+port = 51_820
97
+publicKey = "/N5//y0elGZdeekUv+IzKZiZ9wcKSOHc2bHmPU8FaCM="
98
+
99
+
100
+[hosts.hyperchicken]
101
+# Graham's machine, for administrative access
102
+ip = "10.254.4.1"
103
+port = 51820
104
+publicKey = "sXj7LhGQBczgMhEvLewWgyHsmYMMg88vUsz1rrn7fWM="
105
+
106
+
107
+[hosts.scruffy]
108
+# Graham's machine, for administrative access
109
+ip = "10.254.4.2"
110
+port = 51820
111
+publicKey = "kamC5o3H6UhrfNZjxU6vqdHi3I1+KDOj9tMeuFjiIyk="
112
+
modules/wireguard.nix
+1
-120
@@ -1,125 +1,6 @@
1
{ config, lib, ... }:
2
let
3
- network = 16;
4
- hosts = {
5
- bastion = {
6
- ip = "10.254.1.1";
7
-
8
- # wg won't retry resolution if it fails... so
9
- # hard-code the IP to bastion.nixos.org so we don't lock
10
- # ourselves out.
11
- endpoint = "34.254.208.229";
12
- port = 51820;
13
- publicKey = "nG7I9gegJIynKOZ6tzpvmLdCZ/xScTgRZeFvYLFyil4=";
14
- };
15
-
16
- # tombstone: 10.254.1.2 chef
17
-
18
- ceres = {
19
- ip = "10.254.1.3";
20
- endpoint = "46.4.66.184";
21
- port = 51820;
22
- publicKey = "wkUjkjJtJ9yC1xh2pSbTfyuPkeUnvgxGIHFKxVCGJT8=";
23
- };
24
-
25
- eris = {
26
- ip = "10.254.1.4";
27
- endpoint = "138.201.32.77";
28
- port = 51820;
29
- publicKey = "H/Y+sbNETKZugxGFbOS0m5BSr28jRDL19U37wEw07D8=";
30
- };
31
-
32
- haumea = {
33
- ip = "10.254.1.9";
34
- endpoint = "46.4.89.205";
35
- port = 51820;
36
- publicKey = "Fb41wGKT1TdC4MG5i2NRx6yduddmqm+N+UOtqtDuBG4=";
37
- };
38
-
39
- mac1 = {
40
- ip = "10.254.2.1";
41
- publicKey = "ZIzROtHaFWjrhhdXAE8Tq+EhUsSIURLcwsISfudndTk=";
42
- };
43
- mac2 = {
44
- ip = "10.254.2.2";
45
- publicKey = "m0xJg1OBZIqPu8maxpldLQ1Y39aPS3cnj7hqpVUSuFg=";
46
- };
47
- mac3 = {
48
- ip = "10.254.2.3";
49
- publicKey = "6urTLKp3ihXw0fy4ImhpiQu/sOxrJYewtg2cbT3jv3g=";
50
- };
51
- mac4 = {
52
- ip = "10.254.2.4";
53
- publicKey = "ojkldeD0xJw54nAeGSHQw7BMSXnc6c2e6GP4nJ/1xEo=";
54
- };
55
- mac5 = {
56
- ip = "10.254.2.5";
57
- publicKey = "UgbjJz7BPlD5oDNPr1Bpr4XqeuoL9G5+oUDyU9EVYgg=";
58
- };
59
- mac6 = {
60
- ip = "10.254.2.6";
61
- publicKey = "5t67sluyRwuDXeY17CG7sbpt0gZNybHzvJYd7NAESis=";
62
- };
63
- mac7 = {
64
- ip = "10.254.2.7";
65
- publicKey = "q/8YvHa/M0Epyqflp+fEXvBmJuOBaBJPcaAkScCYvHA=";
66
- };
67
- mac8 = {
68
- ip = "10.254.2.8";
69
- publicKey = "aw/8/5oEn0cZa/WnUE7E7MEukDvzUzaAUEL6PMhLFmE=";
70
- };
71
-
72
- macofborg1 = {
73
- ip = "10.254.2.51";
74
- publicKey = "RPD07xoZYB3aq9hS4pX+qnCHwSbNunK69HGdf8pRtCQ=";
75
- };
76
-
77
- mac-m1-1 = {
78
- ip = "10.254.2.101";
79
- publicKey = "r9EEig5zzGS+MlMqK1jCzXB4Rm11Q/c812i7dxGj8gQ=";
80
- };
81
- mac-m1-2 = {
82
- ip = "10.254.2.102";
83
- publicKey = "J0JajIlwirjrry4QsuVzzyyWSGesQWHk16IR99rcwjY=";
84
- };
85
- mac-m1-3 = {
86
- ip = "10.254.2.103";
87
- publicKey = "E/eHbib8pEnPmT6nWjXlv3H5Ww1DfWxZdbz+Cn+jCX0=";
88
- };
89
- mac-m1-4 = {
90
- ip = "10.254.2.104";
91
- publicKey = "qQ0LO8kU+zFPxCk7JBD9OrfGS3Ryl08ePyF+KQxGl2U=";
92
- };
93
- mac-m1-5 = {
94
- ip = "10.254.2.105";
95
- publicKey = "5VWVUb/fiZmAJqCfqMPH2yIa8xze6hEU11ZKYPOtQyQ=";
96
- };
97
- mac-m1-6 = {
98
- ip = "10.254.2.106";
99
- publicKey = "S20ha1NoMUgR67696vi7hmSdSxK/GJM550S0uR2odlA=";
100
- };
101
-
102
- webserver = {
103
- ip = "10.254.3.1";
104
- publicKey = "/N5//y0elGZdeekUv+IzKZiZ9wcKSOHc2bHmPU8FaCM=";
105
- enpdoint = "54.217.220.47";
106
- port = 51820;
107
- };
108
-
109
- hyperchicken = {
110
- # Graham's machine, since he's lost stable IPv4 addresses
111
- publicKey = "sXj7LhGQBczgMhEvLewWgyHsmYMMg88vUsz1rrn7fWM=";
112
- ip = "10.254.4.1";
113
- port = 51820;
114
- };
115
-
116
- scruffy = {
117
- # Graham's second machine, since he's lost stable IPv4 addresses
118
- publicKey = "kamC5o3H6UhrfNZjxU6vqdHi3I1+KDOj9tMeuFjiIyk=";
119
- ip = "10.254.4.2";
120
- port = 51820;
121
- };
122
- };
3
+ inherit (builtins.fromTOML (builtins.readFile ./wireguard-hosts.toml)) network hosts;
4
5
peerable = selfHost: lib.filterAttrs (hostname: hostcfg:
6
(hostname != selfHost)