diff --git a/deploy/nixos/configuration.nix b/deploy/nixos/configuration.nix index dabb9af..678f658 100644 --- a/deploy/nixos/configuration.nix +++ b/deploy/nixos/configuration.nix @@ -18,7 +18,21 @@ firewall = { enable = true; allowedTCPPorts = [ ]; # ATM initiates all connections - allowedUDPPorts = [ ]; + allowedUDPPorts = [ 51820 ]; # WireGuard + }; + + # WireGuard VPN tunnel to VPS for remote SSH access + wireguard.interfaces.wg0 = { + ips = [ "10.0.0.4/24" ]; + listenPort = 51820; + privateKeyFile = "/var/lib/wireguard/wg0.key"; + + peers = [{ + publicKey = "R6uB4o5ELEKEHCvK+llRYbzdkZGDHegVmS0f08aRtWM="; + endpoint = "170.75.161.21:51820"; + allowedIPs = [ "10.0.0.0/24" ]; + persistentKeepalive = 25; + }]; }; }; @@ -127,6 +141,15 @@ # Auto-updates (optional - disabled by default for stability) # system.autoUpgrade.enable = false; + # Ensure WireGuard private key directory exists with correct permissions + system.activationScripts.wireguard-key = '' + mkdir -p /var/lib/wireguard + chmod 700 /var/lib/wireguard + if [ -f /var/lib/wireguard/wg0.key ]; then + chmod 600 /var/lib/wireguard/wg0.key + fi + ''; + # Journal configuration services.journald = { extraConfig = ''