Files
nix-dotfiles/hosts/vps/default.nix
T
emmatherockandClaude Sonnet 5 52c6a60404 feat(vps): enable IP forwarding for exit node support
Required so the host can route traffic as a Tailscale/Headscale exit node.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-01 15:43:17 -03:00

87 lines
2.3 KiB
Nix

{ config, pkgs, ... }:
{
imports = [
./hardware-configuration.nix
../../modules/profiles/server.nix
../../modules/system/home-profile.nix
../../modules/system/nix-ld.nix
../../modules/system/packages.nix
];
age.secrets.vps-wg.file = ../../secrets/vps-wg.age;
myHomeProfile.extraPrograms = [
../../home/emmatherock/agents.nix
../../home/emmatherock/neovim.nix
];
myNetworking = {
hostName = "vps";
useNetworkManager = false;
useNetworkd = true;
staticIp = {
interface = "ens3";
address = "23.175.41.196";
prefixLength = 27;
gateway = "23.175.41.225";
nameservers = [ "1.1.1.1" "1.0.0.1" ];
onlinkGateway = true;
};
extraTcpPorts = [ 80 443 ];
extraUdpPorts = [ 51822 ];
sshAllowUsers = [ "emmatherock" ];
wireguard = {
enable = true;
ips = [ "10.20.0.1/24" ];
privateKeyFile = config.age.secrets.vps-wg.path;
listenPort = 51822;
peers = [
{
publicKey = "bqxDHQNxOSFpTo3We9ujC2WljtaRBgiNEewW+Rlu10k=";
allowedIPs = [ "10.20.0.2/32" ];
}
];
};
};
myUsers = {
admins.emmatherock = {
description = "EmmaTheRock";
shell = pkgs.fish;
extraGroups = [ "wheel" ];
authorizedKeys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA8vfwM5g9RJXqHtqTgNqsYg9SxSm+UMvFqTjBoAsLJ6 emmatherock@MAIN-PC"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEUCpjAuJobymPPAoPjLdL1eD6g4v6wrquu3cyHP22Wj emmatherock@NixOS"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO6pnKpUEaeoNXqlenc8MAz1GG8P6BRILyIHMSLtvdeF termius"
];
};
};
myContainers = {
enable = true;
composeStacks.core = {
path = "/opt/containers/core";
after = [ "network-online.target" ];
};
};
boot.loader.systemd-boot.enable = true;
boot.loader.systemd-boot.configurationLimit = 10;
boot.loader.efi.canTouchEfiVariables = true;
# Required for this host to act as a Tailscale/Headscale exit node.
boot.kernel.sysctl = {
"net.ipv4.ip_forward" = 1;
"net.ipv6.conf.all.forwarding" = 1;
};
time.timeZone = "America/Argentina/Buenos_Aires";
i18n.defaultLocale = "en_US.UTF-8";
nix.settings.experimental-features = [ "nix-command" "flakes" ];
system.stateVersion = "26.05";
}