feat(deploy): add WireGuard VPN tunnel to douro NixOS config

Configures wg0 interface (10.0.0.4/24) to VPS at 170.75.161.21:51820
for remote SSH access. Opens UDP 51820 in firewall and adds activation
script to ensure key directory permissions.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-01 16:37:08 -05:00
commit a30a8773bd

View file

@ -18,7 +18,21 @@
firewall = {
enable = true;
allowedTCPPorts = [ ]; # ATM initiates all connections
allowedUDPPorts = [ ];
allowedUDPPorts = [ 51820 ]; # WireGuard
};
# WireGuard VPN tunnel to VPS for remote SSH access
wireguard.interfaces.wg0 = {
ips = [ "10.0.0.4/24" ];
listenPort = 51820;
privateKeyFile = "/var/lib/wireguard/wg0.key";
peers = [{
publicKey = "R6uB4o5ELEKEHCvK+llRYbzdkZGDHegVmS0f08aRtWM=";
endpoint = "170.75.161.21:51820";
allowedIPs = [ "10.0.0.0/24" ];
persistentKeepalive = 25;
}];
};
};
@ -127,6 +141,15 @@
# Auto-updates (optional - disabled by default for stability)
# system.autoUpgrade.enable = false;
# Ensure WireGuard private key directory exists with correct permissions
system.activationScripts.wireguard-key = ''
mkdir -p /var/lib/wireguard
chmod 700 /var/lib/wireguard
if [ -f /var/lib/wireguard/wg0.key ]; then
chmod 600 /var/lib/wireguard/wg0.key
fi
'';
# Journal configuration
services.journald = {
extraConfig = ''