summaryrefslogtreecommitdiffstats
path: root/makefu/2configs/vpn/vpnws
diff options
context:
space:
mode:
authormakefu <github@syntax-fehler.de>2023-07-28 22:24:15 +0200
committermakefu <github@syntax-fehler.de>2023-07-28 22:24:15 +0200
commit060a8f28fa1fc648bdf66afb31a5d1efac868837 (patch)
tree2b354eacc7897365ee45244fe7a51720e0d0333f /makefu/2configs/vpn/vpnws
parentcbfcc890e3b76d942b927809bf981a5fa7289e6a (diff)
makefu: move out to own repo, add vacation-note
Diffstat (limited to 'makefu/2configs/vpn/vpnws')
-rw-r--r--makefu/2configs/vpn/vpnws/client.nix9
-rw-r--r--makefu/2configs/vpn/vpnws/server.nix42
2 files changed, 0 insertions, 51 deletions
diff --git a/makefu/2configs/vpn/vpnws/client.nix b/makefu/2configs/vpn/vpnws/client.nix
deleted file mode 100644
index d06bc27d..00000000
--- a/makefu/2configs/vpn/vpnws/client.nix
+++ /dev/null
@@ -1,9 +0,0 @@
-{ pkgs, ... }:
-{
- users.users.makefu.packages = with pkgs; [ iproute vpn-ws ];
- # vpn-ws-client vpnws wss://localhost/vpn --no-verify --exec "ip link set vpnws up;ip addr add 10.244.1.2/24 dev vpnws"
- networking.interfaces.vpnws = {
- virtual = true;
- virtualType = "tap";
- };
-}
diff --git a/makefu/2configs/vpn/vpnws/server.nix b/makefu/2configs/vpn/vpnws/server.nix
deleted file mode 100644
index 6baa5ff1..00000000
--- a/makefu/2configs/vpn/vpnws/server.nix
+++ /dev/null
@@ -1,42 +0,0 @@
-{pkgs, options, ... }:
-let
- pkg = pkgs.vpn-ws;
- uid = "nginx";
- gid = "nginx";
- ip = "${pkgs.iproute}/bin/ip";
- socket = "/run/vpn.sock";
- htpasswd = (toString <secrets>) + "/vpn-ws-auth";
- nginx-prepared-secrets = "/var/spool/nginx/vpn-ws-auth";
-in {
- systemd.services.vpn-ws-auth-prepare = {
- wantedBy = [ "multi-user.target" ];
- before = [ "nginx.service" ];
- script = "install -m700 -o${uid} -g${gid} ${htpasswd} ${nginx-prepared-secrets}";
- };
- services.nginx.virtualHosts."euer.krebsco.de".locations."/vpn" = {
- extraConfig = ''
- auth_basic "please stand by...";
- auth_basic_user_file ${nginx-prepared-secrets};
- uwsgi_pass unix:${socket};
- include ${pkgs.nginx}/conf/uwsgi_params;
- '';
- };
-
- networking.interfaces.vpnws = {
- virtual = true;
- virtualType = "tap";
- };
- systemd.services.vpnws = {
- wantedBy = [ "multi-user.target" ];
- after = [ "network.target" ];
- serviceConfig = {
- Restart = "always";
- PrivateTmp = true;
- ExecStartPre = pkgs.writeDash "vpnws-pre" ''
- ${ip} link set vpnws up
- ${ip} addr add 10.244.1.1/24 dev vpnws || :
- '';
- ExecStart = "${pkg}/bin/vpn-ws --uid ${uid} --gid ${gid} --tuntap vpnws ${socket}";
- };
- };
-}