Update port config

This commit is contained in:
Invariantspace 2023-11-27 13:19:16 -08:00
parent f2e2700acb
commit aa79162e2c
6 changed files with 33 additions and 21 deletions

View file

@ -1,6 +1,6 @@
{ config, ... }: {
networking = {
domain = config.constants.domain;
networking = let const = config.constants; in {
domain = const.domain;
hostId = "30f8f777";
networkmanager = {
enable = true;
@ -11,7 +11,7 @@
ips = [ "10.32.54.2/32" ];
peers = [{
allowedIPs = [ "10.32.54.0/24" ];
endpoint = "${config.constants.domain}:45556";
endpoint = "${const.domain}:${toString const.port.wireguard-server}";
publicKey = "0j8+alXU/f2UgWN61R6+Wjs9xelGRwpSbe5NyOwWlF4=";
}];
privateKeyFile = config.sops.secrets."wireguard/${config.networking.hostName}".path;

View file

@ -16,7 +16,7 @@
reverse_proxy ${forgejoCfg.HTTP_ADDR}:${toString forgejoCfg.HTTP_PORT}
'';
"jellyfin.${dn}".extraConfig = ''
reverse_proxy ${lh}:8096
reverse_proxy ${lh}:${toString config.constants.port.jellyfin}
'';
"matrix.${dn}".extraConfig = ''
reverse_proxy /_matrix/* ${conduitCfg.address}:${toString conduitCfg.port}

View file

@ -1,9 +1,9 @@
{ config, ... }:
let hn = config.networking.hostName; in {
let const = config.constants; hn = config.networking.hostName; in {
networking = {
domain = config.constants.domain;
firewall.allowedTCPPorts = [ 80 443 ];
firewall.allowedTCPPorts = with const.port; [ http https ];
hostId = "e6449321";
networkmanager = {
enable = true;
@ -15,7 +15,7 @@ let hn = config.networking.hostName; in {
ips = [ "10.32.54.3/32" ];
peers = [{
allowedIPs = [ "10.32.54.0/24" ];
endpoint = "${config.constants.domain}:45556";
endpoint = "${const.domain}:${toString const.port.wireguard-server}";
persistentKeepalive = 54;
publicKey = "0j8+alXU/f2UgWN61R6+Wjs9xelGRwpSbe5NyOwWlF4=";
}];

View file

@ -1,7 +1,6 @@
{ config, ... }:
{
services.caddy = {
enable = true;
email = config.constants.postMaster;
@ -17,7 +16,7 @@
"${dn}".extraConfig = let wnm = wn "matrix"; in ''
header ${wnm}/* Content-Type application/json
header ${wnm}/* Access-Control-Allow-Origin *
respond ${wnm}/server `{ "m.server": "${mtfqdn}:443" }`
respond ${wnm}/server `{ "m.server": "${mtfqdn}:${toString config.constants.port.https}" }`
respond ${wnm}/client `{
"m.homeserver": { "base_url": "https://${mtfqdn}" },
"m.identity_server": { "base_url": "https://${mtfqdn}" }

View file

@ -1,22 +1,22 @@
{ config, ... }:
let hn = config.networking.hostName; in {
networking = let wg = { interface = "wgs"; port = 45556; }; in {
let hn = config.networking.hostName; port = config.constants.port; wgi = "wgs"; in {
networking = {
domain = config.constants.domain;
firewall = {
allowedTCPPorts = [ 80 443 50051 ];
allowedUDPPorts = [ wg.port ];
allowedTCPPorts = with port; [ http https xray ];
allowedUDPPorts = with port; [ wireguard-server ];
};
hostId = "2cadb253";
nat = {
enable = true;
externalInterface = "ens18";
internalInterfaces = [ wg.interface ];
internalInterfaces = [ wgi ];
};
nftables.enable = true;
wireguard.interfaces.${wg.interface} = {
wireguard.interfaces.${wgi} = {
ips = [ "10.32.54.76/24" ];
listenPort = wg.port;
listenPort = port.wireguard-server;
peers = [
{
allowedIPs = [ "10.32.54.2/32" ];