2024-05-21 21:23:56 +00:00
|
|
|
{
|
|
|
|
lib,
|
|
|
|
config,
|
|
|
|
pkgs,
|
|
|
|
inputs,
|
|
|
|
...
|
|
|
|
}:
|
|
|
|
let
|
|
|
|
clanDir = config.clanCore.clanDir;
|
|
|
|
machineDir = clanDir + "/machines/";
|
|
|
|
machinesFileSet = builtins.readDir machineDir;
|
|
|
|
machines = lib.mapAttrsToList (name: _: name) machinesFileSet;
|
|
|
|
|
|
|
|
zerotierNetworkIdPath = machines: machineDir + machines + "/facts/zerotier-network-id";
|
|
|
|
networkIdsUnchecked = builtins.map (
|
|
|
|
machine:
|
|
|
|
let
|
|
|
|
fullPath = zerotierNetworkIdPath machine;
|
|
|
|
in
|
|
|
|
if builtins.pathExists fullPath then builtins.readFile fullPath else null
|
|
|
|
) machines;
|
|
|
|
networkIds = lib.filter (machine: machine != null) networkIdsUnchecked;
|
2024-06-03 20:42:04 +00:00
|
|
|
networkId = if builtins.length networkIds == 0 then null else builtins.elemAt networkIds 0;
|
2024-05-21 21:23:56 +00:00
|
|
|
in
|
|
|
|
#TODO:trace on multiple found network-ids
|
|
|
|
#TODO:trace on no single found networkId
|
|
|
|
{
|
|
|
|
options.clan.zerotier-static-peers = {
|
|
|
|
excludeHosts = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.str;
|
|
|
|
default = [ config.clanCore.machineName ];
|
|
|
|
description = "Hosts that should be excluded";
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
config.systemd.services.zerotier-static-peers-autoaccept =
|
|
|
|
let
|
|
|
|
zerotierIpMachinePath = machines: machineDir + machines + "/facts/zerotier-ip";
|
2024-06-05 17:07:06 +00:00
|
|
|
networkIpsUnchecked = builtins.map (
|
|
|
|
machine:
|
|
|
|
let
|
|
|
|
fullPath = zerotierIpMachinePath machine;
|
|
|
|
in
|
|
|
|
if builtins.pathExists fullPath then machine else null
|
|
|
|
) machines;
|
|
|
|
networkIps = lib.filter (machine: machine != null) networkIpsUnchecked;
|
|
|
|
machinesWithIp = lib.filterAttrs (name: _: (lib.elem name networkIps)) machinesFileSet;
|
2024-05-21 21:23:56 +00:00
|
|
|
filteredMachines = lib.filterAttrs (
|
2024-06-03 20:53:44 +00:00
|
|
|
name: _: !(lib.elem name config.clan.zerotier-static-peers.excludeHosts)
|
2024-06-05 17:07:06 +00:00
|
|
|
) machinesWithIp;
|
2024-05-21 21:23:56 +00:00
|
|
|
hosts = lib.mapAttrsToList (host: _: host) (
|
|
|
|
lib.mapAttrs' (
|
|
|
|
machine: _:
|
|
|
|
let
|
|
|
|
fullPath = zerotierIpMachinePath machine;
|
|
|
|
in
|
2024-06-05 17:07:06 +00:00
|
|
|
lib.nameValuePair (builtins.readFile fullPath) [ machine ]
|
2024-05-21 21:23:56 +00:00
|
|
|
) filteredMachines
|
|
|
|
);
|
|
|
|
in
|
|
|
|
lib.mkIf (config.clan.networking.zerotier.controller.enable) {
|
|
|
|
wantedBy = [ "multi-user.target" ];
|
|
|
|
after = [ "zerotierone.service" ];
|
|
|
|
path = [ pkgs.zerotierone ];
|
|
|
|
serviceConfig.ExecStart = pkgs.writeScript "static-zerotier-peers-autoaccept" ''
|
|
|
|
#!/bin/sh
|
|
|
|
${lib.concatMapStringsSep "\n" (host: ''
|
|
|
|
${
|
|
|
|
inputs.clan-core.packages.${pkgs.system}.zerotier-members
|
|
|
|
}/bin/zerotier-members allow --member-ip ${host}
|
|
|
|
'') hosts}
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
config.clan.networking.zerotier.networkId = lib.mkDefault networkId;
|
|
|
|
}
|