mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-06 00:38:12 +09:00
tailscale
This commit is contained in:
@@ -1,38 +1,118 @@
|
||||
{ lib, config, ... }:
|
||||
|
||||
let
|
||||
cfg = config.my.applications.tailscale;
|
||||
|
||||
hasAdvertiseRoutes = cfg.advertiseRoutes != [ ];
|
||||
|
||||
computedRoutingFeatures =
|
||||
if cfg.routingFeatures != "auto" then
|
||||
cfg.routingFeatures
|
||||
else if hasAdvertiseRoutes && cfg.acceptRoutes then
|
||||
"both"
|
||||
else if hasAdvertiseRoutes then
|
||||
"server"
|
||||
else if cfg.acceptRoutes then
|
||||
"client"
|
||||
else
|
||||
"none";
|
||||
|
||||
computedOpenFirewall = if cfg.openFirewall != null then cfg.openFirewall else hasAdvertiseRoutes;
|
||||
|
||||
computedSetFlags = [
|
||||
"--accept-dns=${lib.boolToString cfg.acceptDns}"
|
||||
"--accept-routes=${lib.boolToString cfg.acceptRoutes}"
|
||||
]
|
||||
++ lib.optionals hasAdvertiseRoutes [
|
||||
"--advertise-routes=${lib.concatStringsSep "," cfg.advertiseRoutes}"
|
||||
]
|
||||
++ cfg.extraSetFlags;
|
||||
in
|
||||
{
|
||||
options.my.applications.tailscale = {
|
||||
enable = lib.mkEnableOption "Tailscale VPN";
|
||||
enable = lib.mkEnableOption "Tailscale";
|
||||
|
||||
acceptDns = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Accept DNS configuration from Tailscale";
|
||||
description = "Accept DNS configuration from Tailscale.";
|
||||
};
|
||||
|
||||
acceptRoutes = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = "Accept subnet routes from Tailscale";
|
||||
default = false;
|
||||
description = "Accept subnet routes advertised by other Tailscale nodes.";
|
||||
};
|
||||
|
||||
advertiseRoutes = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
example = [ "10.50.0.0/16" ];
|
||||
description = "Subnet routes to advertise through this Tailscale node.";
|
||||
};
|
||||
|
||||
routingFeatures = lib.mkOption {
|
||||
type = lib.types.enum [
|
||||
"auto"
|
||||
"none"
|
||||
"client"
|
||||
"server"
|
||||
"both"
|
||||
];
|
||||
default = "auto";
|
||||
description = ''
|
||||
Routing feature mode for Tailscale.
|
||||
|
||||
auto:
|
||||
- advertiseRoutes only -> server
|
||||
- acceptRoutes only -> client
|
||||
- both -> both
|
||||
- neither -> none
|
||||
'';
|
||||
};
|
||||
|
||||
openFirewall = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
description = ''
|
||||
Whether to open the firewall for Tailscale's UDP port.
|
||||
|
||||
null means automatic:
|
||||
- true when advertiseRoutes is non-empty
|
||||
- false otherwise
|
||||
'';
|
||||
};
|
||||
|
||||
extraSetFlags = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = "Additional flags to pass to `tailscale set`.";
|
||||
};
|
||||
|
||||
extraUpFlags = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = "Additional flags to pass to tailscale up";
|
||||
description = ''
|
||||
Additional flags to pass to `tailscale up`.
|
||||
|
||||
Note: on current NixOS this is only applied by the built-in
|
||||
autoconnect service when services.tailscale.authKeyFile is set.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
services.tailscale = {
|
||||
enable = true;
|
||||
extraUpFlags = [
|
||||
"--accept-dns=${if cfg.acceptDns then "true" else "false"}"
|
||||
]
|
||||
++ lib.optional cfg.acceptRoutes "--accept-routes"
|
||||
++ cfg.extraUpFlags;
|
||||
|
||||
openFirewall = computedOpenFirewall;
|
||||
useRoutingFeatures = computedRoutingFeatures;
|
||||
|
||||
# 常時反映したい設定は tailscale set に寄せる
|
||||
extraSetFlags = computedSetFlags;
|
||||
|
||||
# authKeyFile を使う場合だけ効くものとして残す
|
||||
inherit (cfg) extraUpFlags;
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -1,31 +1,75 @@
|
||||
{ lib, config, ... }:
|
||||
|
||||
let
|
||||
cfg = config.my.features.network.tailscale;
|
||||
in
|
||||
{
|
||||
options.my.features.network.tailscale = {
|
||||
enable = lib.mkEnableOption "Tailscale VPN";
|
||||
|
||||
acceptDns = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Accept DNS configuration from Tailscale";
|
||||
description = "Accept DNS configuration from Tailscale.";
|
||||
};
|
||||
|
||||
acceptRoutes = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = "Accept subnet routes from Tailscale";
|
||||
default = false;
|
||||
description = "Accept subnet routes from Tailscale.";
|
||||
};
|
||||
|
||||
advertiseRoutes = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
example = [ "10.50.0.0/16" ];
|
||||
description = "Subnet routes to advertise through this machine.";
|
||||
};
|
||||
|
||||
routingFeatures = lib.mkOption {
|
||||
type = lib.types.enum [
|
||||
"auto"
|
||||
"none"
|
||||
"client"
|
||||
"server"
|
||||
"both"
|
||||
];
|
||||
default = "auto";
|
||||
description = "Override Tailscale routing features. Usually leave this as auto.";
|
||||
};
|
||||
|
||||
openFirewall = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.bool;
|
||||
default = null;
|
||||
description = "Override Tailscale firewall opening. Usually leave this as null.";
|
||||
};
|
||||
|
||||
extraSetFlags = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = "Additional flags to pass to `tailscale set`.";
|
||||
};
|
||||
|
||||
extraUpFlags = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = "Additional flags to pass to tailscale up";
|
||||
description = "Additional flags to pass to `tailscale up`.";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
my.applications.tailscale = {
|
||||
enable = true;
|
||||
inherit (cfg) acceptDns acceptRoutes extraUpFlags;
|
||||
|
||||
inherit (cfg)
|
||||
acceptDns
|
||||
acceptRoutes
|
||||
advertiseRoutes
|
||||
routingFeatures
|
||||
openFirewall
|
||||
extraSetFlags
|
||||
extraUpFlags
|
||||
;
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user