@cryptotaxi247 / infra / commits / aa528c76

Remove wireguard module

Martin Weinelt committed Sep 21, 2025 at 05:04 UTC aa528c76591b829a8a73e6348f9ce972b97d1b94
7 files changed -148
build/common.nix
-1
@@ -11,7 +11,6 @@
11 ../modules/nftables.nix
12 ../modules/prometheus
13 ../modules/rasdaemon.nix
14 - ../modules/wireguard.nix
14 ];
15
16 nixpkgs.config.allowUnfree = true;
build/haumea/postgresql.nix
-7
@@ -6,11 +6,6 @@
6 }:
7
8 {
9 - systemd.services.postgresql = {
10 - after = [ "wireguard-wg0.service" ];
11 - requires = [ "wireguard-wg0.service" ];
12 - };
13 -
9 services.prometheus.exporters.postgres = {
10 enable = true;
11 dataSourceName = "user=root database=hydra host=/run/postgresql sslmode=disable";
@@ -21,8 +16,6 @@
16 '';
17 };
18
24 - networking.firewall.interfaces.wg0.allowedTCPPorts = [ 5432 ];
25 -
19 networking.firewall.interfaces."vlan4000".allowedTCPPorts = [ 5432 ];
20
21 services.postgresql = {
build/hydra.nix
-2
@@ -136,11 +136,9 @@ in
136 systemd.services.hydra-init = {
137 wants = [
138 "network-online.target"
139 - "wireguard-wg0.target"
139 ];
140 after = [
141 "network-online.target"
143 - "wireguard-wg0.target"
142 ];
143 };
144
build/pluto/prometheus/alertmanager.nix
-2
@@ -1,8 +1,6 @@
1 { config, ... }:
2
3 {
4 - networking.firewall.interfaces.wg0.allowedTCPPorts = [ 9093 ];
5 -
4 services.prometheus = {
5 alertmanagers = [
6 {
build/pluto/prometheus/default.nix
-8
@@ -22,14 +22,6 @@
22 ./exporters/zfs.nix
23 ];
24
25 - networking.extraHosts = ''
26 - 10.254.1.6 pluto
27 -
28 - 10.254.1.9 haumea
29 -
30 - 10.254.3.1 webserver
31 - '';
32 -
25 networking.firewall.allowedTCPPorts = [ 9090 ];
26
27 services.backup.includesZfsDatasets = [ "/var/lib/prometheus2" ];
modules/wireguard-hosts.toml deleted
-91
@@ -1,91 +0,0 @@
1 -network = 16
2 -
3 -# IP Plan for 10.254.x.y
4 -#
5 -# 10.254.1.x: infrastructure services (not builders)
6 -# 10.254.2.x: macOS builders
7 -# 1 - 10: x86 mac minis running NixOS with macOS in a VM
8 -# 50 - 60: x86 mac minis reserved for ofborg
9 -# 100 - 110: m1 mac minis running macOS on the hardware
10 -# 10.254.3.x: (defunct) NixOS.org hosting infrastructure
11 -# 10.254.4.x: infra team administrator machines
12 -
13 -# tombstone: 10.254.1.2 chef
14 -# tomstone: 10.254.1.3 ceres
15 -# tombstone: 10.254.2.1 mac1 (host/guest)
16 -# tombstone: 10.254.2.2 mac2 (host/guest)
17 -# tombstone: 10.254.2.3 mac3 (host/guest)
18 -# tombstone: 10.254.2.4 mac4 (host/guest)
19 -# tombstone: 10.254.2.5 mac5 (host/guest)
20 -# tombstone: 10.254.2.6 mac6 (host/guest)
21 -# tombstone: 10.254.2.7 mac7 (host/guest)
22 -# tombstone: 10.254.2.8 mac8 (host/guest)
23 -# tombstone: 10.254.2.9 mac9 (host/guest)
24 -
25 -[hosts.mimas]
26 -endpoint = "157.90.104.34"
27 -ip = "10.254.1.1"
28 -port = 51820
29 -publicKey = "h54X0ACbziEspzsYV2/5nSdg5ptdCrIRgpe9KJxNlyY="
30 -
31 -[hosts.pluto]
32 -endpoint = "37.27.99.100"
33 -ip = "10.254.1.6"
34 -port = 51820
35 -publicKey = "1in1+AB8Jjpx9ag09dhoNBUJ/4C132dxibEBH+7kkxo="
36 -
37 -[hosts.haumea]
38 -endpoint = "46.4.89.205"
39 -ip = "10.254.1.9"
40 -port = 51820
41 -publicKey = "Fb41wGKT1TdC4MG5i2NRx6yduddmqm+N+UOtqtDuBG4="
42 -
43 -[hosts.macofborg1]
44 -ip = "10.254.2.51"
45 -publicKey = "RPD07xoZYB3aq9hS4pX+qnCHwSbNunK69HGdf8pRtCQ="
46 -
47 -[hosts.mac-m1-1]
48 -ip = "10.254.2.101"
49 -publicKey = "r9EEig5zzGS+MlMqK1jCzXB4Rm11Q/c812i7dxGj8gQ="
50 -
51 -[hosts.mac-m1-2]
52 -ip = "10.254.2.102"
53 -publicKey = "J0JajIlwirjrry4QsuVzzyyWSGesQWHk16IR99rcwjY="
54 -
55 -[hosts.mac-m1-3]
56 -ip = "10.254.2.103"
57 -publicKey = "E/eHbib8pEnPmT6nWjXlv3H5Ww1DfWxZdbz+Cn+jCX0="
58 -
59 -[hosts.mac-m1-4]
60 -ip = "10.254.2.104"
61 -publicKey = "qQ0LO8kU+zFPxCk7JBD9OrfGS3Ryl08ePyF+KQxGl2U="
62 -
63 -[hosts.mac-m1-5]
64 -ip = "10.254.2.105"
65 -publicKey = "5VWVUb/fiZmAJqCfqMPH2yIa8xze6hEU11ZKYPOtQyQ="
66 -
67 -[hosts.mac-m1-6]
68 -ip = "10.254.2.106"
69 -publicKey = "S20ha1NoMUgR67696vi7hmSdSxK/GJM550S0uR2odlA="
70 -
71 -[hosts.webserver]
72 -enpdoint = "54.217.220.47"
73 -ip = "10.254.3.1"
74 -port = 51820
75 -publicKey = "/N5//y0elGZdeekUv+IzKZiZ9wcKSOHc2bHmPU8FaCM="
76 -
77 -[hosts.nics22]
78 -# Vladimir's machine (@vcunat), for administrative access
79 -ip = "10.254.4.4"
80 -port = 51820
81 -publicKey = "pH2DCtTti9gbyYZ4jFHnhjwDGlWTGKlJ7HFl9ykYjz8="
82 -
83 -[hosts.hexa-helix]
84 -# hexa's machine (@mweinelt), for administrative access
85 -ip = "10.254.4.6"
86 -publicKey = "Aco4hlJFNYtSzZDT6O0TtopnBl76e7aoubI6QygNrGM="
87 -
88 -[hosts.hexa-io]
89 -# hexa's machine (@mweinelt), for administrative access
90 -ip = "10.254.4.7"
91 -publicKey = "s2UCtX+NEIkfEcLpgQZImQShABoMX6Xtog7cYtI2x2s="
modules/wireguard.nix deleted
-37
@@ -1,37 +0,0 @@
1 -{ config, lib, ... }:
2 -let
3 - inherit (builtins.fromTOML (builtins.readFile ./wireguard-hosts.toml)) network hosts;
4 -
5 - peerable =
6 - selfHost:
7 - lib.filterAttrs (hostname: hostcfg: (hostname != selfHost) && (hostcfg ? "publicKey")) hosts;
8 -in
9 -lib.mkMerge [
10 - (lib.mkIf (hosts."${config.networking.hostName}" ? "port") {
11 - networking.firewall.allowedUDPPorts = [ hosts."${config.networking.hostName}".port ];
12 - })
13 - {
14 - networking.wireguard.interfaces.wg0 = {
15 - ips = [ "${hosts."${config.networking.hostName}".ip}/${toString network}" ];
16 - privateKeyFile = "/etc/wireguard/private.key";
17 - generatePrivateKeyFile = true;
18 - listenPort = hosts."${config.networking.hostName}".port or null;
19 -
20 - peers = lib.mapAttrsToList (
21 - _hostname: hostcfg:
22 - {
23 - inherit (hostcfg) publicKey;
24 - allowedIPs = [ "${hostcfg.ip}/32" ];
25 - }
26 - // (lib.optionalAttrs (hostcfg ? "endpoint") {
27 - endpoint = "${hostcfg.endpoint}:${toString hostcfg.port}";
28 - persistentKeepalive = 60;
29 - })
30 - ) (peerable config.networking.hostName);
31 - };
32 -
33 - # networkd-wait-online sometimes fails to notice that the interface is up,
34 - # since it's not managing it.
35 - systemd.network.wait-online.ignoredInterfaces = [ "wg0" ];
36 - }
37 -]