summaryrefslogtreecommitdiffstats
path: root/makefu/1systems/shoney/config.nix
diff options
context:
space:
mode:
authorlassulus <git@lassul.us>2023-07-28 23:59:58 +0200
committerlassulus <git@lassul.us>2023-07-28 23:59:58 +0200
commit02e790c9fb6965e28f1573841181f610ff1599eb (patch)
tree5462ffe78c3708806821d893baa6a2c81137812f /makefu/1systems/shoney/config.nix
parentfd07efa9e97b0984856a97a44ad0b97130db92f7 (diff)
parent3f37acf6f9ea4af21195cd7b0a37ba359105a69d (diff)
Merge remote-tracking branch 'gum/master'
Diffstat (limited to 'makefu/1systems/shoney/config.nix')
-rw-r--r--makefu/1systems/shoney/config.nix62
1 files changed, 0 insertions, 62 deletions
diff --git a/makefu/1systems/shoney/config.nix b/makefu/1systems/shoney/config.nix
deleted file mode 100644
index 27d389b85..000000000
--- a/makefu/1systems/shoney/config.nix
+++ /dev/null
@@ -1,62 +0,0 @@
-{ config, pkgs, ... }:
-let
- tinc-siem-ip = "10.8.10.1";
-
- ip = "64.137.234.215";
- alt-ip = "64.137.234.210"; # honeydrive honeyd
- extra-ip1 = "64.137.234.114"; # floating tinc.siem
- extra-ip2 = "64.137.234.232"; # honeydrive
- gw = "64.137.234.1";
-in {
- imports = [
- <stockholm/makefu>
- <stockholm/makefu/2configs/save-diskspace.nix>
- <stockholm/makefu/2configs/hw/CAC.nix>
- <stockholm/makefu/2configs/fs/CAC-CentOS-7-64bit.nix>
- <stockholm/makefu/2configs/tinc/retiolum.nix>
- ];
-
-
- krebs = {
- enable = true;
- build.host = config.krebs.hosts.shoney;
- tinc_graphs = {
- enable = true;
- network = "siem";
- hostsPath = "/etc/tinc/siem/hosts";
- nginx = {
- enable = true;
- # TODO: remove hard-coded hostname
- anonymous-domain = "localhost.localdomain";
- anonymous.extraConfig = "return 403;";
- complete = {
- serverAliases = [ "graph.siem" ];
- extraConfig = ''
- if ( $server_addr = "${ip}" ) {
- return 403;
- }
- '';
- };
- };
- };
- };
- makefu.forward-journal = {
- enable = true;
- src = "10.8.10.1";
- dst = "10.8.10.6";
- };
- networking = {
- interfaces.enp2s1.ipv4.addresses = [
- { address = ip; prefixLength = 24; }
- # { address = alt-ip; prefixLength = 24; }
- ];
-
- defaultGateway = gw;
- nameservers = [ "8.8.8.8" ];
- firewall = {
- trustedInterfaces = [ "tinc.siem" ];
- allowedUDPPorts = [ 655 1655 ];
- allowedTCPPorts = [ 655 1655 ];
- };
- };
-}