{ config, lib, pkgs, modulesPath, desktop, username, ... }: { imports = [ ./disks.nix ]; nixpkgs.config.allowUnfree = false; boot.initrd.availableKernelModules = [ "ata_piix" "ohci_pci" "virtio_pci" "virtio_blk" "sr_mod" ]; boot.initrd.kernelModules = [ ]; boot.kernelModules = [ ]; boot.extraModulePackages = [ ]; virtualisation.hypervGuest.enable = true; networking.useDHCP = lib.mkDefault true; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; time.timeZone = "Asia/Tokyo"; networking.hostName = "osaka-vultr-01"; networking.firewall.allowedTCPPorts = [ 22 ]; networking.firewall.allowedUDPPorts = [ 51820 ]; # Set up the secrets file: sops.secrets."wireguard_keys/osaka-vultr-01/private" = { owner = "root"; sopsFile = ../../../secrets/wireguard.yaml; }; # Wireguard Forwarder boot.kernel.sysctl = { "net.ipv4.ip_forward" = true; }; networking.wireguard = { enable = true; interfaces = { "exit" = { privateKeyFile = "/run/secrets/wireguard_keys/osaka-vultr-01"; # Testing peers."nixos-rpi4-01" = { publicKey = ""; persistentKeepalive = 5; }; }; }; }; }