Remove wireguard module
Martin Weinelt committed
Sep 21, 2025 at 05:04 UTC
aa528c76591b829a8a73e6348f9ce972b97d1b94
7 files changed
-148
build/common.nix
-1
@@ -11,7 +11,6 @@
11
../modules/nftables.nix
12
../modules/prometheus
13
../modules/rasdaemon.nix
14
- ../modules/wireguard.nix
14
];
15
16
nixpkgs.config.allowUnfree = true;
build/haumea/postgresql.nix
-7
@@ -6,11 +6,6 @@
6
}:
7
8
{
9
- systemd.services.postgresql = {
10
- after = [ "wireguard-wg0.service" ];
11
- requires = [ "wireguard-wg0.service" ];
12
- };
13
-
9
services.prometheus.exporters.postgres = {
10
enable = true;
11
dataSourceName = "user=root database=hydra host=/run/postgresql sslmode=disable";
@@ -21,8 +16,6 @@
16
'';
17
};
18
24
- networking.firewall.interfaces.wg0.allowedTCPPorts = [ 5432 ];
25
-
19
networking.firewall.interfaces."vlan4000".allowedTCPPorts = [ 5432 ];
20
21
services.postgresql = {
build/hydra.nix
-2
@@ -136,11 +136,9 @@ in
136
systemd.services.hydra-init = {
137
wants = [
138
"network-online.target"
139
- "wireguard-wg0.target"
139
];
140
after = [
141
"network-online.target"
143
- "wireguard-wg0.target"
142
];
143
};
144
build/pluto/prometheus/alertmanager.nix
-2
@@ -1,8 +1,6 @@
1
{ config, ... }:
2
3
{
4
- networking.firewall.interfaces.wg0.allowedTCPPorts = [ 9093 ];
5
-
4
services.prometheus = {
5
alertmanagers = [
6
{
build/pluto/prometheus/default.nix
-8
@@ -22,14 +22,6 @@
22
./exporters/zfs.nix
23
];
24
25
- networking.extraHosts = ''
26
- 10.254.1.6 pluto
27
-
28
- 10.254.1.9 haumea
29
-
30
- 10.254.3.1 webserver
31
- '';
32
-
25
networking.firewall.allowedTCPPorts = [ 9090 ];
26
27
services.backup.includesZfsDatasets = [ "/var/lib/prometheus2" ];
modules/wireguard-hosts.toml
deleted
-91
@@ -1,91 +0,0 @@
1
-network = 16
2
-
3
-# IP Plan for 10.254.x.y
4
-#
5
-# 10.254.1.x: infrastructure services (not builders)
6
-# 10.254.2.x: macOS builders
7
-# 1 - 10: x86 mac minis running NixOS with macOS in a VM
8
-# 50 - 60: x86 mac minis reserved for ofborg
9
-# 100 - 110: m1 mac minis running macOS on the hardware
10
-# 10.254.3.x: (defunct) NixOS.org hosting infrastructure
11
-# 10.254.4.x: infra team administrator machines
12
-
13
-# tombstone: 10.254.1.2 chef
14
-# tomstone: 10.254.1.3 ceres
15
-# tombstone: 10.254.2.1 mac1 (host/guest)
16
-# tombstone: 10.254.2.2 mac2 (host/guest)
17
-# tombstone: 10.254.2.3 mac3 (host/guest)
18
-# tombstone: 10.254.2.4 mac4 (host/guest)
19
-# tombstone: 10.254.2.5 mac5 (host/guest)
20
-# tombstone: 10.254.2.6 mac6 (host/guest)
21
-# tombstone: 10.254.2.7 mac7 (host/guest)
22
-# tombstone: 10.254.2.8 mac8 (host/guest)
23
-# tombstone: 10.254.2.9 mac9 (host/guest)
24
-
25
-[hosts.mimas]
26
-endpoint = "157.90.104.34"
27
-ip = "10.254.1.1"
28
-port = 51820
29
-publicKey = "h54X0ACbziEspzsYV2/5nSdg5ptdCrIRgpe9KJxNlyY="
30
-
31
-[hosts.pluto]
32
-endpoint = "37.27.99.100"
33
-ip = "10.254.1.6"
34
-port = 51820
35
-publicKey = "1in1+AB8Jjpx9ag09dhoNBUJ/4C132dxibEBH+7kkxo="
36
-
37
-[hosts.haumea]
38
-endpoint = "46.4.89.205"
39
-ip = "10.254.1.9"
40
-port = 51820
41
-publicKey = "Fb41wGKT1TdC4MG5i2NRx6yduddmqm+N+UOtqtDuBG4="
42
-
43
-[hosts.macofborg1]
44
-ip = "10.254.2.51"
45
-publicKey = "RPD07xoZYB3aq9hS4pX+qnCHwSbNunK69HGdf8pRtCQ="
46
-
47
-[hosts.mac-m1-1]
48
-ip = "10.254.2.101"
49
-publicKey = "r9EEig5zzGS+MlMqK1jCzXB4Rm11Q/c812i7dxGj8gQ="
50
-
51
-[hosts.mac-m1-2]
52
-ip = "10.254.2.102"
53
-publicKey = "J0JajIlwirjrry4QsuVzzyyWSGesQWHk16IR99rcwjY="
54
-
55
-[hosts.mac-m1-3]
56
-ip = "10.254.2.103"
57
-publicKey = "E/eHbib8pEnPmT6nWjXlv3H5Ww1DfWxZdbz+Cn+jCX0="
58
-
59
-[hosts.mac-m1-4]
60
-ip = "10.254.2.104"
61
-publicKey = "qQ0LO8kU+zFPxCk7JBD9OrfGS3Ryl08ePyF+KQxGl2U="
62
-
63
-[hosts.mac-m1-5]
64
-ip = "10.254.2.105"
65
-publicKey = "5VWVUb/fiZmAJqCfqMPH2yIa8xze6hEU11ZKYPOtQyQ="
66
-
67
-[hosts.mac-m1-6]
68
-ip = "10.254.2.106"
69
-publicKey = "S20ha1NoMUgR67696vi7hmSdSxK/GJM550S0uR2odlA="
70
-
71
-[hosts.webserver]
72
-enpdoint = "54.217.220.47"
73
-ip = "10.254.3.1"
74
-port = 51820
75
-publicKey = "/N5//y0elGZdeekUv+IzKZiZ9wcKSOHc2bHmPU8FaCM="
76
-
77
-[hosts.nics22]
78
-# Vladimir's machine (@vcunat), for administrative access
79
-ip = "10.254.4.4"
80
-port = 51820
81
-publicKey = "pH2DCtTti9gbyYZ4jFHnhjwDGlWTGKlJ7HFl9ykYjz8="
82
-
83
-[hosts.hexa-helix]
84
-# hexa's machine (@mweinelt), for administrative access
85
-ip = "10.254.4.6"
86
-publicKey = "Aco4hlJFNYtSzZDT6O0TtopnBl76e7aoubI6QygNrGM="
87
-
88
-[hosts.hexa-io]
89
-# hexa's machine (@mweinelt), for administrative access
90
-ip = "10.254.4.7"
91
-publicKey = "s2UCtX+NEIkfEcLpgQZImQShABoMX6Xtog7cYtI2x2s="
modules/wireguard.nix
deleted
-37
@@ -1,37 +0,0 @@
1
-{ config, lib, ... }:
2
-let
3
- inherit (builtins.fromTOML (builtins.readFile ./wireguard-hosts.toml)) network hosts;
4
-
5
- peerable =
6
- selfHost:
7
- lib.filterAttrs (hostname: hostcfg: (hostname != selfHost) && (hostcfg ? "publicKey")) hosts;
8
-in
9
-lib.mkMerge [
10
- (lib.mkIf (hosts."${config.networking.hostName}" ? "port") {
11
- networking.firewall.allowedUDPPorts = [ hosts."${config.networking.hostName}".port ];
12
- })
13
- {
14
- networking.wireguard.interfaces.wg0 = {
15
- ips = [ "${hosts."${config.networking.hostName}".ip}/${toString network}" ];
16
- privateKeyFile = "/etc/wireguard/private.key";
17
- generatePrivateKeyFile = true;
18
- listenPort = hosts."${config.networking.hostName}".port or null;
19
-
20
- peers = lib.mapAttrsToList (
21
- _hostname: hostcfg:
22
- {
23
- inherit (hostcfg) publicKey;
24
- allowedIPs = [ "${hostcfg.ip}/32" ];
25
- }
26
- // (lib.optionalAttrs (hostcfg ? "endpoint") {
27
- endpoint = "${hostcfg.endpoint}:${toString hostcfg.port}";
28
- persistentKeepalive = 60;
29
- })
30
- ) (peerable config.networking.hostName);
31
- };
32
-
33
- # networkd-wait-online sometimes fails to notice that the interface is up,
34
- # since it's not managing it.
35
- systemd.network.wait-online.ignoredInterfaces = [ "wg0" ];
36
- }
37
-]