mirror of
https://github.com/SebastianStork/nixos-config.git
synced 2026-03-22 16:39:07 +01:00
nebula: Switch to group-based firewall rules
This commit is contained in:
parent
ec0d5b839e
commit
dfdabfb5b1
9 changed files with 39 additions and 37 deletions
|
|
@ -28,14 +28,11 @@ in
|
|||
};
|
||||
};
|
||||
|
||||
nebula.networks.mesh.firewall.inbound =
|
||||
netCfg.peers
|
||||
|> lib.filter (node: node.overlay.role == "client")
|
||||
|> lib.map (client: {
|
||||
port = 22;
|
||||
proto = "tcp";
|
||||
host = client.hostName;
|
||||
});
|
||||
nebula.networks.mesh.firewall.inbound = lib.singleton {
|
||||
port = 22;
|
||||
proto = "tcp";
|
||||
group = "client";
|
||||
};
|
||||
};
|
||||
|
||||
systemd.services.sshd = {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue