fix(deploy): tejo had no WireGuard address, so it had no way back in
`networking.wireguard.interfaces.wg0.ips` was set in hardware/douro.nix and hardware/batm3.nix, but hardware/upboard.nix is shared by tejo and sintra — an address there would be claimed by both machines on the same /24, so neither got one. tejo therefore evaluated to `wg0.ips = [ ]`: the interface comes up with no IP and the tunnel is silently dead. On a machine with no other route in, that is how you lose a box. Replace the two per-hardware definitions with one `wireguardIpForModel` table in flake.nix, keyed on model like fiatCodeForModel / upgradeWindowForModel / nfcReaderForModel, and give tejo 10.0.0.3/24 — the address it answers on today under its factory Debian. douro (10.0.0.4/24) and batm3 (10.0.0.5/24) evaluate unchanged; sintra stays deliberately unlisted, since it is reachable on the LAN and has never had a tunnel address. The address is only half of it: the VPS maps peer pubkey to tunnel IP, so the machine still needs /var/lib/wireguard/wg0.key carried over from its previous install (or a fresh key added to the VPS peer list). Both wireguard units are ConditionPathExists-guarded on that key, so a keyless first boot is clean and the tunnel starts once it is dropped in. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
c3e01c9cd3
commit
6042d69356
3 changed files with 37 additions and 4 deletions
|
|
@ -93,8 +93,7 @@
|
|||
hybrid-sleep.enable = false;
|
||||
};
|
||||
|
||||
# WireGuard VPN address
|
||||
networking.wireguard.interfaces.wg0.ips = [ "10.0.0.4/24" ];
|
||||
# WireGuard VPN address → wireguardIpForModel in flake.nix.
|
||||
|
||||
# Serial port access for bill validator/dispenser
|
||||
services.udev.extraRules = lib.mkAfter ''
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue