Compare commits

...

2 commits

5 changed files with 6 additions and 5 deletions

View file

@ -37,7 +37,7 @@
onlyCleanRoots = true;
};
nebula.node.enable = true;
nebula.enable = true;
sshd.enable = true;
dns.enable = true;
};

View file

@ -41,7 +41,7 @@
onlyCleanRoots = true;
};
nebula.node.enable = true;
nebula.enable = true;
sshd.enable = true;
dns.enable = true;

View file

@ -36,7 +36,7 @@
onlyCleanRoots = true;
};
nebula.node.enable = true;
nebula.enable = true;
sshd.enable = true;
crowdsec = {

View file

@ -41,7 +41,7 @@ in
};
interface = lib.mkOption {
type = lib.types.nonEmptyStr;
default = "nebula.mesh";
default = "nebula";
};
systemdUnit = lib.mkOption {
type = lib.types.nonEmptyStr;

View file

@ -30,7 +30,7 @@ in
message = "'${netCfg.hostname}' is a Nebula lighthouse, but underlay.isPublic is not set. Lighthouses must be publicly reachable.";
};
meta.ports.udp = lib.optional (netCfg.underlay.isPublic) publicPort;
meta.ports.udp = lib.optional netCfg.underlay.isPublic publicPort;
sops.secrets."nebula/host-key" = {
owner = config.users.users.nebula-mesh.name;
@ -44,6 +44,7 @@ in
cert = cfg.certificatePath;
key = config.sops.secrets."nebula/host-key".path;
tun.device = netCfg.overlay.interface;
listen.port = lib.mkIf netCfg.underlay.isPublic publicPort;
inherit (netCfg) isLighthouse;