nixos/machines/vigil.nix

83 lines
1.7 KiB
Nix
Raw Normal View History

2023-01-25 11:48:44 +00:00
/*
Name: https://masseffect.fandom.com/wiki/Vigil
Why: Counterpart to Vendetta
Type: VM
Hardware: -
From: 2023
Role: DNS Server
Notes:
*/
{ pkgs, lib, nodes, ... }:
let
name = "vigil";
ip_pub = "193.1.99.109";
ip_priv = "172.20.20.4";
hostname = "${name}.skynet.ie";
2023-01-25 11:48:44 +00:00
# sets which nameserver it is
ns = "ns2";
in {
imports = [
2023-06-15 21:02:30 +00:00
2023-01-25 11:48:44 +00:00
];
deployment = {
targetHost = ip_pub;
2023-01-25 11:48:44 +00:00
targetPort = 22;
targetUser = "root";
2023-04-20 13:09:36 +00:00
2023-04-20 22:15:59 +00:00
tags = [ "active" "dns" ];
2023-01-25 11:48:44 +00:00
};
skynet_dns = {
enable = true;
# this server will have to have dns records
own = {
nameserver = ns;
ip = ip_pub;
2023-01-25 11:48:44 +00:00
external = [
"${name} A ${ip_pub}"
"${ns} A ${ip_pub}"
];
cname = [
#"misc CNAME vendetta"
];
2023-05-21 18:05:47 +00:00
reverse = [
"${builtins.substring 9 3 ip_pub} IN PTR ${name}"
];
2023-01-25 11:48:44 +00:00
};
records = {
# using the same logic as the firewall, comments there
external = builtins.concatLists (
lib.attrsets.mapAttrsToList (key: value:
if builtins.hasAttr "skynet_dns" value.config
then (
if value.config.skynet_dns.enable
then value.config.skynet_dns.own.external
else value.config.skynet_dns.records.external
)
else []
) nodes
);
cname = builtins.concatLists (
lib.attrsets.mapAttrsToList (key: value:
if builtins.hasAttr "skynet_dns" value.config
then (
if value.config.skynet_dns.enable
then value.config.skynet_dns.own.cname
else value.config.skynet_dns.records.cname
)
else []
) nodes
);
};
};
}