@cryptotaxi247 / infra-1 / commits / 999bd81b

Wireguard: move host data in to a .toml file

Graham Christensen committed Dec 19, 2021 at 14:51 UTC 999bd81b8c82d5e6657275652fa3fd7bcc7d6bb6
2 files changed +113 -120
modules/wireguard-hosts.toml new
+112
@@ -0,0 +1,112 @@
1 +network = 16
2 +
3 +[hosts.bastion]
4 +# wg won't retry resolution if it fails... so
5 +# hard-code the IP to bastion.nixos.org so we don't lock
6 +# ourselves out.
7 +endpoint = "34.254.208.229"
8 +ip = "10.254.1.1"
9 +port = 51820
10 +publicKey = "nG7I9gegJIynKOZ6tzpvmLdCZ/xScTgRZeFvYLFyil4="
11 +
12 +# tombstone: 10.254.1.2 chef
13 +
14 +[hosts.ceres]
15 +endpoint = "46.4.66.184"
16 +ip = "10.254.1.3"
17 +port = 51820
18 +publicKey = "wkUjkjJtJ9yC1xh2pSbTfyuPkeUnvgxGIHFKxVCGJT8="
19 +
20 +[hosts.eris]
21 +endpoint = "138.201.32.77"
22 +ip = "10.254.1.4"
23 +port = 51820
24 +publicKey = "H/Y+sbNETKZugxGFbOS0m5BSr28jRDL19U37wEw07D8="
25 +
26 +[hosts.haumea]
27 +endpoint = "46.4.89.205"
28 +ip = "10.254.1.9"
29 +port = 51820
30 +publicKey = "Fb41wGKT1TdC4MG5i2NRx6yduddmqm+N+UOtqtDuBG4="
31 +
32 +[hosts.mac1]
33 +ip = "10.254.2.1"
34 +publicKey = "ZIzROtHaFWjrhhdXAE8Tq+EhUsSIURLcwsISfudndTk="
35 +
36 +[hosts.mac2]
37 +ip = "10.254.2.2"
38 +publicKey = "m0xJg1OBZIqPu8maxpldLQ1Y39aPS3cnj7hqpVUSuFg="
39 +
40 +[hosts.mac3]
41 +ip = "10.254.2.3"
42 +publicKey = "6urTLKp3ihXw0fy4ImhpiQu/sOxrJYewtg2cbT3jv3g="
43 +
44 +[hosts.mac4]
45 +ip = "10.254.2.4"
46 +publicKey = "ojkldeD0xJw54nAeGSHQw7BMSXnc6c2e6GP4nJ/1xEo="
47 +
48 +[hosts.mac5]
49 +ip = "10.254.2.5"
50 +publicKey = "UgbjJz7BPlD5oDNPr1Bpr4XqeuoL9G5+oUDyU9EVYgg="
51 +
52 +[hosts.mac6]
53 +ip = "10.254.2.6"
54 +publicKey = "5t67sluyRwuDXeY17CG7sbpt0gZNybHzvJYd7NAESis="
55 +
56 +[hosts.mac7]
57 +ip = "10.254.2.7"
58 +publicKey = "q/8YvHa/M0Epyqflp+fEXvBmJuOBaBJPcaAkScCYvHA="
59 +
60 +[hosts.mac8]
61 +ip = "10.254.2.8"
62 +publicKey = "aw/8/5oEn0cZa/WnUE7E7MEukDvzUzaAUEL6PMhLFmE="
63 +
64 +[hosts.macofborg1]
65 +ip = "10.254.2.51"
66 +publicKey = "RPD07xoZYB3aq9hS4pX+qnCHwSbNunK69HGdf8pRtCQ="
67 +
68 +
69 +[hosts.mac-m1-1]
70 +ip = "10.254.2.101"
71 +publicKey = "r9EEig5zzGS+MlMqK1jCzXB4Rm11Q/c812i7dxGj8gQ="
72 +
73 +[hosts.mac-m1-2]
74 +ip = "10.254.2.102"
75 +publicKey = "J0JajIlwirjrry4QsuVzzyyWSGesQWHk16IR99rcwjY="
76 +
77 +[hosts.mac-m1-3]
78 +ip = "10.254.2.103"
79 +publicKey = "E/eHbib8pEnPmT6nWjXlv3H5Ww1DfWxZdbz+Cn+jCX0="
80 +
81 +[hosts.mac-m1-4]
82 +ip = "10.254.2.104"
83 +publicKey = "qQ0LO8kU+zFPxCk7JBD9OrfGS3Ryl08ePyF+KQxGl2U="
84 +
85 +[hosts.mac-m1-5]
86 +ip = "10.254.2.105"
87 +publicKey = "5VWVUb/fiZmAJqCfqMPH2yIa8xze6hEU11ZKYPOtQyQ="
88 +
89 +[hosts.mac-m1-6]
90 +ip = "10.254.2.106"
91 +publicKey = "S20ha1NoMUgR67696vi7hmSdSxK/GJM550S0uR2odlA="
92 +
93 +[hosts.webserver]
94 +enpdoint = "54.217.220.47"
95 +ip = "10.254.3.1"
96 +port = 51_820
97 +publicKey = "/N5//y0elGZdeekUv+IzKZiZ9wcKSOHc2bHmPU8FaCM="
98 +
99 +
100 +[hosts.hyperchicken]
101 +# Graham's machine, for administrative access
102 +ip = "10.254.4.1"
103 +port = 51820
104 +publicKey = "sXj7LhGQBczgMhEvLewWgyHsmYMMg88vUsz1rrn7fWM="
105 +
106 +
107 +[hosts.scruffy]
108 +# Graham's machine, for administrative access
109 +ip = "10.254.4.2"
110 +port = 51820
111 +publicKey = "kamC5o3H6UhrfNZjxU6vqdHi3I1+KDOj9tMeuFjiIyk="
112 +
modules/wireguard.nix
+1 -120
@@ -1,125 +1,6 @@
1 { config, lib, ... }:
2 let
3 - network = 16;
4 - hosts = {
5 - bastion = {
6 - ip = "10.254.1.1";
7 -
8 - # wg won't retry resolution if it fails... so
9 - # hard-code the IP to bastion.nixos.org so we don't lock
10 - # ourselves out.
11 - endpoint = "34.254.208.229";
12 - port = 51820;
13 - publicKey = "nG7I9gegJIynKOZ6tzpvmLdCZ/xScTgRZeFvYLFyil4=";
14 - };
15 -
16 - # tombstone: 10.254.1.2 chef
17 -
18 - ceres = {
19 - ip = "10.254.1.3";
20 - endpoint = "46.4.66.184";
21 - port = 51820;
22 - publicKey = "wkUjkjJtJ9yC1xh2pSbTfyuPkeUnvgxGIHFKxVCGJT8=";
23 - };
24 -
25 - eris = {
26 - ip = "10.254.1.4";
27 - endpoint = "138.201.32.77";
28 - port = 51820;
29 - publicKey = "H/Y+sbNETKZugxGFbOS0m5BSr28jRDL19U37wEw07D8=";
30 - };
31 -
32 - haumea = {
33 - ip = "10.254.1.9";
34 - endpoint = "46.4.89.205";
35 - port = 51820;
36 - publicKey = "Fb41wGKT1TdC4MG5i2NRx6yduddmqm+N+UOtqtDuBG4=";
37 - };
38 -
39 - mac1 = {
40 - ip = "10.254.2.1";
41 - publicKey = "ZIzROtHaFWjrhhdXAE8Tq+EhUsSIURLcwsISfudndTk=";
42 - };
43 - mac2 = {
44 - ip = "10.254.2.2";
45 - publicKey = "m0xJg1OBZIqPu8maxpldLQ1Y39aPS3cnj7hqpVUSuFg=";
46 - };
47 - mac3 = {
48 - ip = "10.254.2.3";
49 - publicKey = "6urTLKp3ihXw0fy4ImhpiQu/sOxrJYewtg2cbT3jv3g=";
50 - };
51 - mac4 = {
52 - ip = "10.254.2.4";
53 - publicKey = "ojkldeD0xJw54nAeGSHQw7BMSXnc6c2e6GP4nJ/1xEo=";
54 - };
55 - mac5 = {
56 - ip = "10.254.2.5";
57 - publicKey = "UgbjJz7BPlD5oDNPr1Bpr4XqeuoL9G5+oUDyU9EVYgg=";
58 - };
59 - mac6 = {
60 - ip = "10.254.2.6";
61 - publicKey = "5t67sluyRwuDXeY17CG7sbpt0gZNybHzvJYd7NAESis=";
62 - };
63 - mac7 = {
64 - ip = "10.254.2.7";
65 - publicKey = "q/8YvHa/M0Epyqflp+fEXvBmJuOBaBJPcaAkScCYvHA=";
66 - };
67 - mac8 = {
68 - ip = "10.254.2.8";
69 - publicKey = "aw/8/5oEn0cZa/WnUE7E7MEukDvzUzaAUEL6PMhLFmE=";
70 - };
71 -
72 - macofborg1 = {
73 - ip = "10.254.2.51";
74 - publicKey = "RPD07xoZYB3aq9hS4pX+qnCHwSbNunK69HGdf8pRtCQ=";
75 - };
76 -
77 - mac-m1-1 = {
78 - ip = "10.254.2.101";
79 - publicKey = "r9EEig5zzGS+MlMqK1jCzXB4Rm11Q/c812i7dxGj8gQ=";
80 - };
81 - mac-m1-2 = {
82 - ip = "10.254.2.102";
83 - publicKey = "J0JajIlwirjrry4QsuVzzyyWSGesQWHk16IR99rcwjY=";
84 - };
85 - mac-m1-3 = {
86 - ip = "10.254.2.103";
87 - publicKey = "E/eHbib8pEnPmT6nWjXlv3H5Ww1DfWxZdbz+Cn+jCX0=";
88 - };
89 - mac-m1-4 = {
90 - ip = "10.254.2.104";
91 - publicKey = "qQ0LO8kU+zFPxCk7JBD9OrfGS3Ryl08ePyF+KQxGl2U=";
92 - };
93 - mac-m1-5 = {
94 - ip = "10.254.2.105";
95 - publicKey = "5VWVUb/fiZmAJqCfqMPH2yIa8xze6hEU11ZKYPOtQyQ=";
96 - };
97 - mac-m1-6 = {
98 - ip = "10.254.2.106";
99 - publicKey = "S20ha1NoMUgR67696vi7hmSdSxK/GJM550S0uR2odlA=";
100 - };
101 -
102 - webserver = {
103 - ip = "10.254.3.1";
104 - publicKey = "/N5//y0elGZdeekUv+IzKZiZ9wcKSOHc2bHmPU8FaCM=";
105 - enpdoint = "54.217.220.47";
106 - port = 51820;
107 - };
108 -
109 - hyperchicken = {
110 - # Graham's machine, since he's lost stable IPv4 addresses
111 - publicKey = "sXj7LhGQBczgMhEvLewWgyHsmYMMg88vUsz1rrn7fWM=";
112 - ip = "10.254.4.1";
113 - port = 51820;
114 - };
115 -
116 - scruffy = {
117 - # Graham's second machine, since he's lost stable IPv4 addresses
118 - publicKey = "kamC5o3H6UhrfNZjxU6vqdHi3I1+KDOj9tMeuFjiIyk=";
119 - ip = "10.254.4.2";
120 - port = 51820;
121 - };
122 - };
3 + inherit (builtins.fromTOML (builtins.readFile ./wireguard-hosts.toml)) network hosts;
4
5 peerable = selfHost: lib.filterAttrs (hostname: hostcfg:
6 (hostname != selfHost)