36 lines
909 B
Nix
36 lines
909 B
Nix
{ pkgs, ... }:
|
|
{
|
|
imports = [
|
|
./hardware-configuration.nix
|
|
./networking.nix
|
|
./users.nix
|
|
./power-plan.nix
|
|
../../modules/common/incus.nix
|
|
];
|
|
|
|
networking.interfaces.eth0.wakeOnLan.enable = true;
|
|
|
|
# ── NetBird zero-trust VPN ─────────────────────────────────
|
|
services.netbird = {
|
|
enable = true;
|
|
login = {
|
|
enable = true;
|
|
setupKeyFile = "/run/secrets/netbird-setup-key";
|
|
};
|
|
};
|
|
|
|
# Decrypt the NetBird setup key from SOPS secrets before netbird starts
|
|
system.activationScripts.netbird-setup-key = {
|
|
text = ''
|
|
mkdir -p /run/secrets
|
|
${pkgs.sops}/bin/sops \
|
|
--decrypt \
|
|
--extract '["netbird_setup_key"]' \
|
|
${./secrets.yaml} \
|
|
> /run/secrets/netbird-setup-key
|
|
chmod 600 /run/secrets/netbird-setup-key
|
|
'';
|
|
deps = [ "etc" ];
|
|
};
|
|
}
|