diff options
| -rw-r--r-- | tv/3modules/default.nix | 1 | ||||
| -rw-r--r-- | tv/3modules/dnsmasq.nix | 57 | ||||
| -rw-r--r-- | tv/5pkgs/simple/disko.nix | 13 | 
3 files changed, 71 insertions, 0 deletions
| diff --git a/tv/3modules/default.nix b/tv/3modules/default.nix index 493cc8b72..6172feb03 100644 --- a/tv/3modules/default.nix +++ b/tv/3modules/default.nix @@ -1,6 +1,7 @@  {    imports = [      ./charybdis +    ./dnsmasq.nix      ./ejabberd      ./hosts.nix      ./iptables.nix diff --git a/tv/3modules/dnsmasq.nix b/tv/3modules/dnsmasq.nix new file mode 100644 index 000000000..ec927f98a --- /dev/null +++ b/tv/3modules/dnsmasq.nix @@ -0,0 +1,57 @@ +with import <stockholm/lib>; +{ config, ... }: let +  cfg = config.tv.dnsmasq; +in { + +  options.tv.dnsmasq = { +    enable = mkEnableOption "tv.dnsmasq"; +    dhcp-range = mkOption { +      type = types.str; +    }; +    interface = mkOption { +      type = types.str; +    }; +    address = mkOption { +      type = types.str; +    }; +    prefixLength = mkOption { +      type = types.addCheck types.int (x: x >= 0 && x <= 32); +    }; +  }; + +  config = mkIf cfg.enable (mkMerge [ +    { +      networking.dhcpcd.denyInterfaces = [ cfg.interface ]; +      services.dnsmasq.resolveLocalQueries = false; +      networking.interfaces.${cfg.interface} = { +        ipv4.addresses = singleton { +          address = cfg.address; +          prefixLength = cfg.prefixLength; +        }; +      }; +      services.dnsmasq.enable = true; +      services.dnsmasq.extraConfig = '' +        dhcp-range=${cfg.dhcp-range} +        interface=${cfg.interface} +      ''; +      tv.iptables.extra.filter.INPUT = [ +        "-i ${cfg.interface} -p tcp -m tcp --dport bootps -j ACCEPT" +        "-i ${cfg.interface} -p udp -m udp --dport bootps -j ACCEPT" +        "-i ${cfg.interface} -p tcp -m tcp --dport domain -j ACCEPT" +        "-i ${cfg.interface} -p udp -m udp --dport domain -j ACCEPT" +      ]; +    } +    { +      # enable forwarding +      boot.kernel.sysctl."net.ipv4.ip_forward" = true; +      tv.iptables.extra.filter.FORWARD = [ +        "-m state --state RELATED,ESTABLISHED -j ACCEPT" +        "-i ${cfg.interface} -j ACCEPT" +      ]; +      tv.iptables.extra.nat.POSTROUTING = [ +        "-j MASQUERADE" +      ]; +    } +  ]); + +} diff --git a/tv/5pkgs/simple/disko.nix b/tv/5pkgs/simple/disko.nix new file mode 100644 index 000000000..de8f1df22 --- /dev/null +++ b/tv/5pkgs/simple/disko.nix @@ -0,0 +1,13 @@ +{ fetchgit }: + +let +  src = fetchgit { +    url = https://cgit.krebsco.de/disko; +    rev = "16cd458af06d3caf687eb7d80ca3df26b71fe28c"; +    sha256 = "16cd458af06d3caf687eb7d80ca3df26b71fe28c"; +  }; +in + +{ +  lib = import "${src}/lib"; +} | 
