diff --git a/deploy/nixos/hardware/batm3.nix b/deploy/nixos/hardware/batm3.nix index ca57f0d..dcf8692 100644 --- a/deploy/nixos/hardware/batm3.nix +++ b/deploy/nixos/hardware/batm3.nix @@ -223,6 +223,5 @@ }; }; - # WireGuard VPN address - networking.wireguard.interfaces.wg0.ips = [ "10.0.0.5/24" ]; + # WireGuard VPN address → wireguardIpForModel in flake.nix. } diff --git a/deploy/nixos/hardware/douro.nix b/deploy/nixos/hardware/douro.nix index e2e138c..83a11cf 100644 --- a/deploy/nixos/hardware/douro.nix +++ b/deploy/nixos/hardware/douro.nix @@ -93,8 +93,7 @@ hybrid-sleep.enable = false; }; - # WireGuard VPN address - networking.wireguard.interfaces.wg0.ips = [ "10.0.0.4/24" ]; + # WireGuard VPN address → wireguardIpForModel in flake.nix. # Serial port access for bill validator/dispenser services.udev.extraRules = lib.mkAfter '' diff --git a/flake.nix b/flake.nix index f7554d9..4037d3d 100644 --- a/flake.nix +++ b/flake.nix @@ -159,6 +159,36 @@ sintra = true; # HID Global OMNIKEY 5022 }; + # WireGuard address on the 10.0.0.0/24 management tunnel to the VPS + # (peer + listenPort live in configuration.nix; only the address is + # per-machine). Same keying caveat as the three tables above. + # + # This cannot live in a hardware file for the UP Board models, and the + # reason it now lives here for ALL of them is tejo: hardware/upboard.nix + # is shared by tejo and sintra, so an address set there would be claimed + # by both machines on the same /24. tejo had no address at all as a + # result — `wg0.ips = [ ]` brings the interface up with no IP and the + # tunnel is dead, which is a silent way to lose remote access to a + # machine that has no other route in. Keeping douro's and batm3's + # addresses here too means there is one list to read when allocating the + # next one, rather than three files plus the VPS peer config. + # + # An unlisted model gets no address and no tunnel. That is deliberate for + # sintra, which is reachable on the LAN (192.168.0.252) and has never had + # a tunnel address. + # + # NOTE: the address is only half of it. The VPS maps peer PUBLIC KEY to + # pragma: allowlist secret + # tunnel IP, so a machine also needs its private key at + # /var/lib/wireguard/wg0.key — carried over from the machine's previous + # install, or newly generated with its pubkey added to the VPS peer list. + # The key is operator-provisioned and deliberately not in the image. + wireguardIpForModel = { + tejo = "10.0.0.3/24"; + douro = "10.0.0.4/24"; + batm3 = "10.0.0.5/24"; + }; + lib = nixpkgs.lib; # Helper to create a live USB NixOS config for a specific machine model @@ -218,6 +248,11 @@ nfc.enable = nfcReaderForModel.${machineModel} or false; }; + # Management-tunnel address; see wireguardIpForModel. + networking.wireguard.interfaces.wg0.ips = + lib.optional (wireguardIpForModel ? ${machineModel}) + wireguardIpForModel.${machineModel}; + # Operator TUI and CLI tools environment.systemPackages = [ atm-tui.packages.${system}.default