From a30a8773bda46f956451ef01d9282e5c94313f76 Mon Sep 17 00:00:00 2001 From: Patrick Mulligan Date: Sun, 1 Mar 2026 16:37:08 -0500 Subject: [PATCH] feat(deploy): add WireGuard VPN tunnel to douro NixOS config Configures wg0 interface (10.0.0.4/24) to VPS at 170.75.161.21:51820 for remote SSH access. Opens UDP 51820 in firewall and adds activation script to ensure key directory permissions. Co-Authored-By: Claude Opus 4.6 --- deploy/nixos/configuration.nix | 25 ++++++++++++++++++++++++- 1 file changed, 24 insertions(+), 1 deletion(-) diff --git a/deploy/nixos/configuration.nix b/deploy/nixos/configuration.nix index dabb9af..678f658 100644 --- a/deploy/nixos/configuration.nix +++ b/deploy/nixos/configuration.nix @@ -18,7 +18,21 @@ firewall = { enable = true; allowedTCPPorts = [ ]; # ATM initiates all connections - allowedUDPPorts = [ ]; + allowedUDPPorts = [ 51820 ]; # WireGuard + }; + + # WireGuard VPN tunnel to VPS for remote SSH access + wireguard.interfaces.wg0 = { + ips = [ "10.0.0.4/24" ]; + listenPort = 51820; + privateKeyFile = "/var/lib/wireguard/wg0.key"; + + peers = [{ + publicKey = "R6uB4o5ELEKEHCvK+llRYbzdkZGDHegVmS0f08aRtWM="; + endpoint = "170.75.161.21:51820"; + allowedIPs = [ "10.0.0.0/24" ]; + persistentKeepalive = 25; + }]; }; }; @@ -127,6 +141,15 @@ # Auto-updates (optional - disabled by default for stability) # system.autoUpgrade.enable = false; + # Ensure WireGuard private key directory exists with correct permissions + system.activationScripts.wireguard-key = '' + mkdir -p /var/lib/wireguard + chmod 700 /var/lib/wireguard + if [ -f /var/lib/wireguard/wg0.key ]; then + chmod 600 /var/lib/wireguard/wg0.key + fi + ''; + # Journal configuration services.journald = { extraConfig = ''