Merge pull request 'fix(deploy): guard the WireGuard peer units too, not just the interface' (#103) from fix/wg-peer-units-guard into dev
Reviewed-on: #103
This commit is contained in:
commit
ac27bc36e0
1 changed files with 23 additions and 3 deletions
|
|
@ -191,9 +191,29 @@
|
||||||
# activation over an interface that was never set up; a provisioned machine
|
# activation over an interface that was never set up; a provisioned machine
|
||||||
# is unaffected. Guarded on wg0 still being declared so the live image,
|
# is unaffected. Guarded on wg0 still being declared so the live image,
|
||||||
# which mkForce's the interfaces away, doesn't get a unit with no ExecStart.
|
# which mkForce's the interfaces away, doesn't get a unit with no ExecStart.
|
||||||
systemd.services = lib.mkIf (config.networking.wireguard.interfaces ? wg0) {
|
systemd.services = lib.mkIf (config.networking.wireguard.interfaces ? wg0) (
|
||||||
wireguard-wg0.unitConfig.ConditionPathExists = "/var/lib/wireguard/wg0.key";
|
let
|
||||||
};
|
iface = config.networking.wireguard.interfaces.wg0;
|
||||||
|
guard = { unitConfig.ConditionPathExists = "/var/lib/wireguard/wg0.key"; };
|
||||||
|
# The module emits one unit per peer alongside the interface unit, and a
|
||||||
|
# skipped interface is NOT a failed dependency, so the peer units still
|
||||||
|
# run and die on "Unable to modify interface: No such device" — same
|
||||||
|
# exit 4, different unit. Guard them too. Names come from the module's
|
||||||
|
# own `peers.*.name` option (whose default is the escaped public key)
|
||||||
|
# rather than re-deriving the escaping here; the `-refresh` suffix
|
||||||
|
# follows nixpkgs' peerUnitServiceName, where a peer's null refresh
|
||||||
|
# interval falls back to the interface's.
|
||||||
|
refreshes = peer:
|
||||||
|
(if peer.dynamicEndpointRefreshSeconds != null then
|
||||||
|
peer.dynamicEndpointRefreshSeconds
|
||||||
|
else
|
||||||
|
iface.dynamicEndpointRefreshSeconds) != 0;
|
||||||
|
peerUnit = peer:
|
||||||
|
"wireguard-wg0-peer-${peer.name}" + lib.optionalString (refreshes peer) "-refresh";
|
||||||
|
in
|
||||||
|
{ wireguard-wg0 = guard; }
|
||||||
|
// lib.listToAttrs (map (peer: lib.nameValuePair (peerUnit peer) guard) iface.peers)
|
||||||
|
);
|
||||||
|
|
||||||
# In-place rename migration: lamassu user → bitspire user.
|
# In-place rename migration: lamassu user → bitspire user.
|
||||||
# Runs after `users` activation so the bitspire user exists with its UID.
|
# Runs after `users` activation so the bitspire user exists with its UID.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue