From 060a8f28fa1fc648bdf66afb31a5d1efac868837 Mon Sep 17 00:00:00 2001 From: makefu Date: Fri, 28 Jul 2023 22:24:15 +0200 Subject: makefu: move out to own repo, add vacation-note --- makefu/2configs/vpn/vpnws/client.nix | 9 -------- makefu/2configs/vpn/vpnws/server.nix | 42 ------------------------------------ 2 files changed, 51 deletions(-) delete mode 100644 makefu/2configs/vpn/vpnws/client.nix delete mode 100644 makefu/2configs/vpn/vpnws/server.nix (limited to 'makefu/2configs/vpn/vpnws') diff --git a/makefu/2configs/vpn/vpnws/client.nix b/makefu/2configs/vpn/vpnws/client.nix deleted file mode 100644 index d06bc27d..00000000 --- a/makefu/2configs/vpn/vpnws/client.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ pkgs, ... }: -{ - users.users.makefu.packages = with pkgs; [ iproute vpn-ws ]; - # vpn-ws-client vpnws wss://localhost/vpn --no-verify --exec "ip link set vpnws up;ip addr add 10.244.1.2/24 dev vpnws" - networking.interfaces.vpnws = { - virtual = true; - virtualType = "tap"; - }; -} diff --git a/makefu/2configs/vpn/vpnws/server.nix b/makefu/2configs/vpn/vpnws/server.nix deleted file mode 100644 index 6baa5ff1..00000000 --- a/makefu/2configs/vpn/vpnws/server.nix +++ /dev/null @@ -1,42 +0,0 @@ -{pkgs, options, ... }: -let - pkg = pkgs.vpn-ws; - uid = "nginx"; - gid = "nginx"; - ip = "${pkgs.iproute}/bin/ip"; - socket = "/run/vpn.sock"; - htpasswd = (toString ) + "/vpn-ws-auth"; - nginx-prepared-secrets = "/var/spool/nginx/vpn-ws-auth"; -in { - systemd.services.vpn-ws-auth-prepare = { - wantedBy = [ "multi-user.target" ]; - before = [ "nginx.service" ]; - script = "install -m700 -o${uid} -g${gid} ${htpasswd} ${nginx-prepared-secrets}"; - }; - services.nginx.virtualHosts."euer.krebsco.de".locations."/vpn" = { - extraConfig = '' - auth_basic "please stand by..."; - auth_basic_user_file ${nginx-prepared-secrets}; - uwsgi_pass unix:${socket}; - include ${pkgs.nginx}/conf/uwsgi_params; - ''; - }; - - networking.interfaces.vpnws = { - virtual = true; - virtualType = "tap"; - }; - systemd.services.vpnws = { - wantedBy = [ "multi-user.target" ]; - after = [ "network.target" ]; - serviceConfig = { - Restart = "always"; - PrivateTmp = true; - ExecStartPre = pkgs.writeDash "vpnws-pre" '' - ${ip} link set vpnws up - ${ip} addr add 10.244.1.1/24 dev vpnws || : - ''; - ExecStart = "${pkg}/bin/vpn-ws --uid ${uid} --gid ${gid} --tuntap vpnws ${socket}"; - }; - }; -} -- cgit v1.2.3