feat(deploy): add WireGuard VPN tunnel to douro NixOS config

Configures wg0 interface (10.0.0.4/24) to VPS at 170.75.161.21:51820
for remote SSH access. Opens UDP 51820 in firewall and adds activation
script to ensure key directory permissions.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-01 16:37:08 -05:00
commit a30a8773bd

View file

@ -18,7 +18,21 @@
firewall = { firewall = {
enable = true; enable = true;
allowedTCPPorts = [ ]; # ATM initiates all connections allowedTCPPorts = [ ]; # ATM initiates all connections
allowedUDPPorts = [ ]; allowedUDPPorts = [ 51820 ]; # WireGuard
};
# WireGuard VPN tunnel to VPS for remote SSH access
wireguard.interfaces.wg0 = {
ips = [ "10.0.0.4/24" ];
listenPort = 51820;
privateKeyFile = "/var/lib/wireguard/wg0.key";
peers = [{
publicKey = "R6uB4o5ELEKEHCvK+llRYbzdkZGDHegVmS0f08aRtWM=";
endpoint = "170.75.161.21:51820";
allowedIPs = [ "10.0.0.0/24" ];
persistentKeepalive = 25;
}];
}; };
}; };
@ -127,6 +141,15 @@
# Auto-updates (optional - disabled by default for stability) # Auto-updates (optional - disabled by default for stability)
# system.autoUpgrade.enable = false; # system.autoUpgrade.enable = false;
# Ensure WireGuard private key directory exists with correct permissions
system.activationScripts.wireguard-key = ''
mkdir -p /var/lib/wireguard
chmod 700 /var/lib/wireguard
if [ -f /var/lib/wireguard/wg0.key ]; then
chmod 600 /var/lib/wireguard/wg0.key
fi
'';
# Journal configuration # Journal configuration
services.journald = { services.journald = {
extraConfig = '' extraConfig = ''