From cc109b2958fa22046395ba03d0814d03d2e432ce Mon Sep 17 00:00:00 2001 From: Patrick Mulligan Date: Sat, 4 Apr 2026 19:18:12 -0400 Subject: [PATCH] fix(deploy): assign unique WireGuard IPs per machine Move WireGuard IP from shared configuration.nix to per-machine hardware configs. douro = 10.0.0.4, batm3 = 10.0.0.5. Previously both machines shared 10.0.0.4 which caused routing conflicts on the VPS. Co-Authored-By: Claude Opus 4.6 (1M context) --- deploy/nixos/configuration.nix | 2 +- deploy/nixos/hardware/batm3.nix | 3 +++ deploy/nixos/hardware/douro.nix | 3 +++ 3 files changed, 7 insertions(+), 1 deletion(-) diff --git a/deploy/nixos/configuration.nix b/deploy/nixos/configuration.nix index 193a73a..e78fc68 100644 --- a/deploy/nixos/configuration.nix +++ b/deploy/nixos/configuration.nix @@ -22,8 +22,8 @@ }; # WireGuard VPN tunnel to VPS for remote SSH access + # IP address set per-machine in hardware/*.nix via networking.wireguard.interfaces.wg0.ips wireguard.interfaces.wg0 = { - ips = [ "10.0.0.4/24" ]; listenPort = 51820; privateKeyFile = "/var/lib/wireguard/wg0.key"; diff --git a/deploy/nixos/hardware/batm3.nix b/deploy/nixos/hardware/batm3.nix index 8873734..0f13dd2 100644 --- a/deploy/nixos/hardware/batm3.nix +++ b/deploy/nixos/hardware/batm3.nix @@ -136,4 +136,7 @@ ExecStart = "${pkgs.xorg.xinput}/bin/xinput set-prop 'eGalax Inc. USB TouchController' 'Coordinate Transformation Matrix' 0 -1.268 1.147 -1.224 0 1.118 0 0 1"; }; }; + + # WireGuard VPN address + networking.wireguard.interfaces.wg0.ips = [ "10.0.0.5/24" ]; } diff --git a/deploy/nixos/hardware/douro.nix b/deploy/nixos/hardware/douro.nix index 5c868a4..9080cb1 100644 --- a/deploy/nixos/hardware/douro.nix +++ b/deploy/nixos/hardware/douro.nix @@ -80,6 +80,9 @@ hybrid-sleep.enable = false; }; + # WireGuard VPN address + networking.wireguard.interfaces.wg0.ips = [ "10.0.0.4/24" ]; + # Serial port access for bill validator/dispenser services.udev.extraRules = lib.mkAfter '' KERNEL=="ttyS[0-9]*", MODE="0666"