dotfiles-nix/modules/programs/wireguard/default.nix
2025-01-22 12:41:39 -05:00

31 lines
777 B
Nix

{ config, lib, pkgs, ... }:
{
config = lib.mkIf config.system.enable {
environment.systemPackages = with pkgs; [
wireguard-tools
];
# TODO: remove this!!!
environment.etc = {
"resolv.conf".text = "nameserver 10.1.1.1\n";
};
networking.wireguard.enable = true;
networking.wireguard.interfaces = {
freyanet = {
ips = [ "10.2.0.2/32" "fd:cafe:dead:bee::2/128" "fe80::2/128" ];
privateKeyFile = "${config.dotfilesPath}/secrets/freyanet.key";
peers = [{
publicKey = "x0ykwakpYCvI/pG+nR83lNUyeOE9m54thnX3bvZ+FUk=";
allowedIPs = [ "10.0.0.0/12" "fd:cafe::/32" "fe80::/64" ];
endpoint = "freya.cat:41111";
persistentKeepalive = 25;
}];
};
};
};
}