2023-01-25 11:48:44 +00:00
|
|
|
/*
|
|
|
|
|
|
|
|
Name: https://masseffect.fandom.com/wiki/Vendetta
|
|
|
|
Why: Vendetta held troves of important data waiting for folks to request it.
|
2023-02-24 12:09:21 +00:00
|
|
|
Type: Physical
|
|
|
|
Hardware: PowerEdge r210
|
|
|
|
From: 2011 (?)
|
2023-01-25 11:48:44 +00:00
|
|
|
Role: DNS Server
|
2023-02-24 12:09:21 +00:00
|
|
|
Notes: Using the server that used to be called Earth
|
2023-01-25 11:48:44 +00:00
|
|
|
|
|
|
|
*/
|
|
|
|
|
|
|
|
{ pkgs, lib, nodes, ... }:
|
|
|
|
let
|
|
|
|
# name of the server, sets teh hostname and record for it
|
|
|
|
name = "vendetta";
|
|
|
|
ip_pub = "193.1.99.120";
|
|
|
|
ip_priv = "172.20.20.3";
|
2023-04-20 13:07:26 +00:00
|
|
|
hostname = "${name}.skynet.ie";
|
2023-01-25 11:48:44 +00:00
|
|
|
|
|
|
|
# sets which nameserver it is
|
|
|
|
ns = "ns1";
|
|
|
|
in {
|
|
|
|
imports = [
|
2023-02-24 12:09:21 +00:00
|
|
|
# the physical hardware for this
|
|
|
|
./hardware/RM002.nix
|
|
|
|
|
2023-01-25 11:48:44 +00:00
|
|
|
# applications for this particular server
|
|
|
|
../applications/firewall.nix
|
|
|
|
../applications/dns.nix
|
|
|
|
];
|
|
|
|
|
|
|
|
deployment = {
|
|
|
|
targetHost = hostname;
|
|
|
|
targetPort = 22;
|
|
|
|
targetUser = "root";
|
2023-04-20 13:09:36 +00:00
|
|
|
|
2023-04-20 22:15:59 +00:00
|
|
|
tags = [ "active" "dns" ];
|
2023-01-25 11:48:44 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
networking = {
|
2023-02-24 12:09:21 +00:00
|
|
|
# needs to have an address statically assigned
|
|
|
|
interfaces = {
|
|
|
|
eno1 = {
|
|
|
|
ipv4.addresses = [
|
|
|
|
{
|
|
|
|
address = "193.1.99.120";
|
|
|
|
prefixLength = 26;
|
|
|
|
}
|
|
|
|
];
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2023-01-25 11:48:44 +00:00
|
|
|
firewall = {
|
|
|
|
allowedTCPPorts = [22 53];
|
|
|
|
allowedUDPPorts = [53];
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
# open the firewall for this
|
|
|
|
skynet_firewall.forward = [
|
2023-01-28 15:31:16 +00:00
|
|
|
"ip daddr ${ip_pub} tcp dport 53 counter packets 0 bytes 0 accept"
|
|
|
|
"ip daddr ${ip_pub} udp dport 53 counter packets 0 bytes 0 accept"
|
2023-01-25 11:48:44 +00:00
|
|
|
];
|
|
|
|
|
|
|
|
skynet_dns = {
|
|
|
|
enable = true;
|
|
|
|
|
|
|
|
# this server will have to have dns records
|
|
|
|
own = {
|
|
|
|
nameserver = ns;
|
|
|
|
external = [
|
|
|
|
"${name} A ${ip_pub}"
|
|
|
|
"${ns} A ${ip_pub}"
|
|
|
|
|
|
|
|
# needs this, temporally
|
|
|
|
"mail A ${ip_pub}"
|
|
|
|
];
|
|
|
|
cname = [
|
|
|
|
#"misc CNAME vendetta"
|
|
|
|
];
|
|
|
|
};
|
|
|
|
|
|
|
|
records = {
|
|
|
|
# using the same logic as the firewall, comments there
|
|
|
|
external = builtins.concatLists (
|
|
|
|
lib.attrsets.mapAttrsToList (key: value:
|
|
|
|
if builtins.hasAttr "skynet_dns" value.config
|
|
|
|
then (
|
|
|
|
if value.config.skynet_dns.enable
|
|
|
|
then value.config.skynet_dns.own.external
|
|
|
|
else value.config.skynet_dns.records.external
|
|
|
|
)
|
|
|
|
else []
|
|
|
|
) nodes
|
|
|
|
);
|
|
|
|
|
|
|
|
cname = builtins.concatLists (
|
|
|
|
lib.attrsets.mapAttrsToList (key: value:
|
|
|
|
if builtins.hasAttr "skynet_dns" value.config
|
|
|
|
then (
|
|
|
|
if value.config.skynet_dns.enable
|
|
|
|
then value.config.skynet_dns.own.cname
|
|
|
|
else value.config.skynet_dns.records.cname
|
|
|
|
)
|
|
|
|
else []
|
|
|
|
) nodes
|
|
|
|
);
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
}
|