blob: 79305e7275fdbc7aaa1c1f22aa7da782e6884ee8 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
|
{ config, ... }:
let
# TODO: dataDir is currently not provided by upstream
# data = config.services.dnscrypt-wrapper.dataDir;
data = "/var/lib/dnscrypt-wrapper";
sec = toString <secrets>;
port = 15251;
user = "dnscrypt-wrapper";
in {
services.dnscrypt-wrapper = {
enable = true;
address = "0.0.0.0";
upstream.address = "8.8.8.8";
providerName = "2.dnscrypt-cert.euer.krebsco.de";
inherit port;
};
networking.firewall.allowedUDPPorts = [ port ];
systemd.services.prepare-dnscrypt-wrapper-keys = {
wantedBy = [ "dnscrypt-wrapper.service" ];
before = [ "dnscrypt-wrapper.service" ];
script = ''
install -m700 -o ${user} -v ${sec}/dnscrypt-public.key ${data}/public.key
install -m700 -o ${user} -v ${sec}/dnscrypt-secret.key ${data}/secret.key
'';
};
}
|