Use environmentFile for wireless network configuration
This commit is contained in:
parent
52e05029ee
commit
336a353639
7 changed files with 87 additions and 27 deletions
|
@ -15,7 +15,14 @@
|
||||||
stateVersion = "20.09";
|
stateVersion = "20.09";
|
||||||
base = {
|
base = {
|
||||||
bluetooth.enable = true;
|
bluetooth.enable = true;
|
||||||
network.networkmanager.enable = true;
|
network.mobile = {
|
||||||
|
enable = true;
|
||||||
|
wireless-interface = "wlp2s0";
|
||||||
|
wired-interfaces = {
|
||||||
|
"enp0s20f0u1u2" = { macAddress = "10:65:30:df:80:f5"; };
|
||||||
|
"enp0s31f6" = { macAddress = "10:65:30:df:80:f5"; };
|
||||||
|
};
|
||||||
|
};
|
||||||
zfs = {
|
zfs = {
|
||||||
encrypted = true;
|
encrypted = true;
|
||||||
backups = [
|
backups = [
|
||||||
|
|
|
@ -12,7 +12,13 @@
|
||||||
stateVersion = "20.09";
|
stateVersion = "20.09";
|
||||||
base = {
|
base = {
|
||||||
bluetooth.enable = true;
|
bluetooth.enable = true;
|
||||||
network.networkmanager.enable = true;
|
network.mobile = {
|
||||||
|
enable = true;
|
||||||
|
wireless-interface = "wlp2s0";
|
||||||
|
wired-interfaces = {
|
||||||
|
"enp0s31f6" = { macAddress = "10:65:30:df:80:f5"; };
|
||||||
|
};
|
||||||
|
};
|
||||||
zfs = {
|
zfs = {
|
||||||
encrypted = true;
|
encrypted = true;
|
||||||
backups = [
|
backups = [
|
||||||
|
|
|
@ -3,6 +3,6 @@
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
./ovh.nix
|
./ovh.nix
|
||||||
./networkmanager.nix
|
./mobile.nix
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|
55
modules/base/network/mobile.nix
Normal file
55
modules/base/network/mobile.nix
Normal file
|
@ -0,0 +1,55 @@
|
||||||
|
{ config, lib, pkgs, ... }:
|
||||||
|
|
||||||
|
{
|
||||||
|
options.chvp.base.network.mobile = {
|
||||||
|
enable = lib.mkOption {
|
||||||
|
default = false;
|
||||||
|
example = true;
|
||||||
|
};
|
||||||
|
wireless-interface = lib.mkOption {
|
||||||
|
type = lib.types.str;
|
||||||
|
example = "wlp2s0";
|
||||||
|
};
|
||||||
|
wired-interfaces = lib.mkOption {
|
||||||
|
example = { "enp0s29f0u1u2" = { macAddress = "10:65:30:85:bb:18"; }; };
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
config = with config.chvp.base.network.mobile; lib.mkIf enable {
|
||||||
|
networking = {
|
||||||
|
wireless = {
|
||||||
|
enable = true;
|
||||||
|
interfaces = [ wireless-interface ];
|
||||||
|
environmentFile = config.age.secrets."passwords/networks.age".path;
|
||||||
|
networks = {
|
||||||
|
"Public Universal Friend".psk = "@PSK_PUF@";
|
||||||
|
AndroidAP.psk = "@PSK_AndroidAP@";
|
||||||
|
draadloosnw.psk = "@PSK_draadloosnw@";
|
||||||
|
Secorima.psk = "@PSK_Secorima@";
|
||||||
|
eduroam = {
|
||||||
|
authProtocols = [ "WPA-EAP" ];
|
||||||
|
auth = ''
|
||||||
|
eap=PEAP
|
||||||
|
identity="@EDUROAM_USER@"
|
||||||
|
password="@EDUROAM_PASS@"
|
||||||
|
'';
|
||||||
|
extraConfig = ''
|
||||||
|
phase1="peaplabel=0"
|
||||||
|
phase2="auth=MSCHAPV2"
|
||||||
|
group=CCMP TKIP
|
||||||
|
ca_cert="/etc/ssl/certs/ca-bundle.crt"
|
||||||
|
altsubject_match="DNS:ugnps.ugent.be"
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
interfaces = {
|
||||||
|
"${wireless-interface}".useDHCP = true;
|
||||||
|
} // lib.mapAttrs (name: attrs: { useDHCP = true; } // attrs) wired-interfaces;
|
||||||
|
};
|
||||||
|
|
||||||
|
age.secrets."passwords/networks.age" = {
|
||||||
|
file = ../../../secrets/passwords/networks.age;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
|
@ -1,24 +0,0 @@
|
||||||
{ config, lib, pkgs, ... }:
|
|
||||||
|
|
||||||
{
|
|
||||||
options.chvp.base.network.networkmanager.enable = lib.mkOption {
|
|
||||||
default = false;
|
|
||||||
example = true;
|
|
||||||
};
|
|
||||||
|
|
||||||
config = lib.mkIf config.chvp.base.network.networkmanager.enable {
|
|
||||||
chvp.base.zfs.systemLinks = [
|
|
||||||
{ path = "/etc/NetworkManager/system-connections"; type = "data"; }
|
|
||||||
];
|
|
||||||
|
|
||||||
networking.networkmanager = {
|
|
||||||
enable = true;
|
|
||||||
wifi.macAddress = "random";
|
|
||||||
};
|
|
||||||
|
|
||||||
users.users.charlotte.extraGroups = [ "networkmanager" ];
|
|
||||||
home-manager.users.charlotte = { ... }: {
|
|
||||||
home.packages = with pkgs; [ networkmanagerapplet ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
|
@ -31,6 +31,8 @@ in
|
||||||
"secrets/authorized_keys/charlotte.age".publicKeys = hosts ++ users;
|
"secrets/authorized_keys/charlotte.age".publicKeys = hosts ++ users;
|
||||||
"secrets/authorized_keys/root.age".publicKeys = hosts ++ users;
|
"secrets/authorized_keys/root.age".publicKeys = hosts ++ users;
|
||||||
|
|
||||||
|
"secrets/passwords/networks.age".publicKeys = laptops ++ users;
|
||||||
|
|
||||||
"secrets/passwords/ugent-mount-credentials.age".publicKeys = laptops ++ users;
|
"secrets/passwords/ugent-mount-credentials.age".publicKeys = laptops ++ users;
|
||||||
"secrets/passwords/ugent-vpn.age".publicKeys = laptops ++ users;
|
"secrets/passwords/ugent-vpn.age".publicKeys = laptops ++ users;
|
||||||
"secrets/files/programs/vpn/local.age".publicKeys = laptops ++ users;
|
"secrets/files/programs/vpn/local.age".publicKeys = laptops ++ users;
|
||||||
|
|
14
secrets/passwords/networks.age
Normal file
14
secrets/passwords/networks.age
Normal file
|
@ -0,0 +1,14 @@
|
||||||
|
age-encryption.org/v1
|
||||||
|
-> ssh-ed25519 umFZoA EgJA71dMaNjzeIrIk26f9ZYesUZC61hcz4SVMbRR1Sc
|
||||||
|
8xQ6pCqqnwpRNsQcty/emlYJMOK3cKZL9v5lBOTkpEc
|
||||||
|
-> ssh-ed25519 aUd9Ng kDSdEEr7yBvW6xjQYCfjXH8MKiX7ErXyXobNgKMGVGA
|
||||||
|
0oxfjV2prMCjk0YMqpaKibvnh0lEa8cE8OZOakARq6I
|
||||||
|
-> ssh-ed25519 s9rb8g QCGjI/c2Lb1/BxH+cPHgIhR7PjDezUUqeDKde/l+3E4
|
||||||
|
frUFtiDd5duiqEIUM0+e3b+z+451eBlzbl5R1spw++E
|
||||||
|
-> ssh-ed25519 yad4VQ BP7LN1CEbor9KE65BfhfXTa9Xzn2H/pybBrAC7fxh0A
|
||||||
|
34Pkw68+0+9GheQsPSiwJ3ZsmVNjZ4lOQWrEdwKfYH8
|
||||||
|
-> ?diR@~VE-grease
|
||||||
|
H7EVKOdVfcjcgYgh9ph2HV9yFMMyCte4jt9BHa2hag
|
||||||
|
--- gZWd5okcan8zWduhUh5UeP7ZFXAa7BXAPW1Sv8hoPt4
|
||||||
|
AwRš°RÜDGCB4u#þ$vÂùŒ-‘òWz‹‘£žøÃ>ƒ…ÐzË€¨Ð±ä)Ó†»B磊*eŠÈ¨TìÞåÉJêÛÃK9TéY« nöºW>d <À&ûHZóAÚ…ý°<aJ¡·@¥
±‘cü0³‘Ìç5¶Œ‹#UÙ3l—#½Þ3Ÿ‡:žÊr/Zá’‰ <20>èˆÌ,‰²×ú±$¨í œ'&]
|
||||||
|
?nHÇö0)¸êoûé‚q"6iwsò2±
Îeå$Jr©&¬
|
Loading…
Add table
Add a link
Reference in a new issue