diff options
| author | adi <adikro@disroot.org> | 2026-07-29 17:09:58 +0200 |
|---|---|---|
| committer | adi <adikro@disroot.org> | 2026-07-29 17:09:58 +0200 |
| commit | 39a2b09c27bb74c9e59d1772764f901e3c8fb9e4 (patch) | |
| tree | 0ba58e6fbf086a85d875df1c10f6d23bc3bbc7da /os/srv/headscale.nix | |
| parent | 8a820cacee1ff07ae7397d053b26e66f7086a4a4 (diff) | |
revamped flake.nix, removed homelab specific modulesstaging
Diffstat (limited to 'os/srv/headscale.nix')
| -rw-r--r-- | os/srv/headscale.nix | 76 |
1 files changed, 0 insertions, 76 deletions
diff --git a/os/srv/headscale.nix b/os/srv/headscale.nix deleted file mode 100644 index 01fc06c..0000000 --- a/os/srv/headscale.nix +++ /dev/null @@ -1,76 +0,0 @@ -{ - config, - lib, - pkgs, - masterDomain, - ... -}: -let - cfg = config.os.srv.headscale; - aclPolicy = pkgs.writeText "headscale-policy.json" ( - builtins.toJSON { - groups = { - "group:admin" = [ "your-device-name" ]; - "group:friends" = [ "friend-device-name" ]; - }; - - hosts = { - "server" = "10.4.0.1"; - }; - - acls = [ - { - action = "accept"; - src = [ "group:admin" ]; - dst = [ "*:*" ]; - } - - { - action = "accept"; - src = [ "group:friends" ]; - dst = [ - "server:18080" - "server:18081" - "server:25565" - ]; - } - ]; - } - ); -in -{ - options.os.srv.headscale.enable = lib.mkEnableOption "enables headscales"; - - config = lib.mkIf cfg.enable { - services.headscale = { - enable = true; - address = "127.0.0.1"; - port = 8080; - - settings = { - server_url = "https://vpn.${masterDomain}"; - - policy.path = "${aclPolicy}"; - - dns = { - magic_dns = true; - base_domain = "vpn"; - nameservers = [ config.os.core.network.ips.vm2-gateway ]; - }; - - ip_prefixes = [ - "10.4.0.0/16" - ]; - }; - }; - - services.nginx.virtualHosts."vpn.${masterDomain}" = { - enableACME = true; - forceSSL = true; - locations."/" = { - proxyPass = "http://127.0.0.1:8080"; - proxyWebsockets = true; - }; - }; - }; -} |
