feat(deploy): add WireGuard VPN tunnel to douro NixOS config
Configures wg0 interface (10.0.0.4/24) to VPS at 170.75.161.21:51820 for remote SSH access. Opens UDP 51820 in firewall and adds activation script to ensure key directory permissions. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
254fbd26f2
commit
a30a8773bd
1 changed files with 24 additions and 1 deletions
|
|
@ -18,7 +18,21 @@
|
|||
firewall = {
|
||||
enable = true;
|
||||
allowedTCPPorts = [ ]; # ATM initiates all connections
|
||||
allowedUDPPorts = [ ];
|
||||
allowedUDPPorts = [ 51820 ]; # WireGuard
|
||||
};
|
||||
|
||||
# WireGuard VPN tunnel to VPS for remote SSH access
|
||||
wireguard.interfaces.wg0 = {
|
||||
ips = [ "10.0.0.4/24" ];
|
||||
listenPort = 51820;
|
||||
privateKeyFile = "/var/lib/wireguard/wg0.key";
|
||||
|
||||
peers = [{
|
||||
publicKey = "R6uB4o5ELEKEHCvK+llRYbzdkZGDHegVmS0f08aRtWM=";
|
||||
endpoint = "170.75.161.21:51820";
|
||||
allowedIPs = [ "10.0.0.0/24" ];
|
||||
persistentKeepalive = 25;
|
||||
}];
|
||||
};
|
||||
};
|
||||
|
||||
|
|
@ -127,6 +141,15 @@
|
|||
# Auto-updates (optional - disabled by default for stability)
|
||||
# system.autoUpgrade.enable = false;
|
||||
|
||||
# Ensure WireGuard private key directory exists with correct permissions
|
||||
system.activationScripts.wireguard-key = ''
|
||||
mkdir -p /var/lib/wireguard
|
||||
chmod 700 /var/lib/wireguard
|
||||
if [ -f /var/lib/wireguard/wg0.key ]; then
|
||||
chmod 600 /var/lib/wireguard/wg0.key
|
||||
fi
|
||||
'';
|
||||
|
||||
# Journal configuration
|
||||
services.journald = {
|
||||
extraConfig = ''
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue