This commit is contained in:
iFargle 2023-09-18 20:32:52 +09:00
parent 60aa664d26
commit 782414f1ce
3 changed files with 7 additions and 7 deletions

View file

@ -36,7 +36,7 @@
# Generic Tailscale configs are in /nixos/common/services/tailscale.nix
# Set up the secrets file:
sops.secrets.nixos-rpi4-01_tailscale_key = {
sops.secrets.tailscale.nixos-rpi4-01 = {
owner = "root";
sopsFile = ../../../secrets/tailscale.yaml;
restartUnits = [
@ -44,10 +44,10 @@
"tailscaled-autoconnect.service"
];
};
services.tailscale.authKeyFile = "/run/secrets/nixos-rpi4-01_tailscale_key";
services.tailscale.authKeyFile = "/run/secrets/tailscale/nixos-rpi4-01";
services.tailscale.extraUpFlags = [ "--advertise-exit-node" ];
boot.kernel.sysctl = { "net.ipv4.ip_forward" = true; };
# Temporary
# networking.firewall.allowedTCPPorts = [ 22 ];
networking.firewall.allowedTCPPorts = [ 22 ];
}

View file

@ -36,7 +36,7 @@
# Generic Tailscale configs are in /nixos/common/services/tailscale.nix
# Set up the secrets file:
sops.secrets.nixos-rpi4-01_tailscale_key = {
sops.secrets.tailscale.nixos-rpi4-02 = {
owner = "root";
sopsFile = ../../../secrets/tailscale.yaml;
restartUnits = [
@ -44,7 +44,7 @@
"tailscaled-autoconnect.service"
];
};
services.tailscale.authKeyFile = "/run/secrets/nixos-rpi4-02_tailscale_key";
services.tailscale.authKeyFile = "/run/secrets/tailscale/nixos-rpi4-02";
services.tailscale.extraUpFlags = [ "--advertise-exit-node" ];
boot.kernel.sysctl = { "net.ipv4.ip_forward" = true; };

View file

@ -36,7 +36,7 @@
# Generic Tailscale configs are in /nixos/common/services/tailscale.nix
# Set up the secrets file:
sops.secrets.nixos-rpi4-01_tailscale_key = {
sops.secrets.tailscale.nixos-rpi4-03 = {
owner = "root";
sopsFile = ../../../secrets/tailscale.yaml;
restartUnits = [
@ -44,7 +44,7 @@
"tailscaled-autoconnect.service"
];
};
services.tailscale.authKeyFile = "/run/secrets/nixos-rpi4-03_tailscale_key";
services.tailscale.authKeyFile = "/run/secrets/tailscale/nixos-rpi4-03";
services.tailscale.extraUpFlags = [ "--advertise-exit-node" ];
boot.kernel.sysctl = { "net.ipv4.ip_forward" = true; };