From eabb8bd1a7eddc00d9d77e04916d749fcd14dd58 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Moritz=20B=C3=B6hme?= Date: Mon, 7 Mar 2022 12:02:20 +0100 Subject: [PATCH] :rocket: add openvpn service --- modules/services/agenix.nix | 4 ++++ modules/services/default.nix | 1 + modules/services/openvpn.nix | 11 +++++++++++ secrets/home-vpn.age | Bin 0 -> 8995 bytes secrets/secrets.nix | 1 + 5 files changed, 17 insertions(+) create mode 100644 modules/services/openvpn.nix create mode 100644 secrets/home-vpn.age diff --git a/modules/services/agenix.nix b/modules/services/agenix.nix index 93bdb5b..7a8958d 100644 --- a/modules/services/agenix.nix +++ b/modules/services/agenix.nix @@ -18,5 +18,9 @@ file = ../../secrets/spotifyd.age; owner = "1000"; }; + homeVPN = { + file = ../../secrets/home-vpn.age; + owner = "1000"; + }; }; } diff --git a/modules/services/default.nix b/modules/services/default.nix index 5a30921..6da254f 100644 --- a/modules/services/default.nix +++ b/modules/services/default.nix @@ -9,6 +9,7 @@ ./jupyter.nix ./kdeconnect.nix ./keyring.nix + ./openvpn.nix ./picom.nix ]; diff --git a/modules/services/openvpn.nix b/modules/services/openvpn.nix new file mode 100644 index 0000000..50745df --- /dev/null +++ b/modules/services/openvpn.nix @@ -0,0 +1,11 @@ +{ config, lib, pkgs, ... }: + +{ + services.openvpn.servers = { + homeVPN = { + config = "config /run/agenix/homeVPN "; + autoStart = false; + updateResolvConf = true; + }; + }; +} diff --git a/secrets/home-vpn.age b/secrets/home-vpn.age new file mode 100644 index 0000000000000000000000000000000000000000..25b3839d96c16299b3fb7dfb9a1685a4392e9155 GIT binary patch literal 8995 zcmV+;Bi!6!XJsvAZewzJaCB*JZZ2z`VpU@|S!r)KIAl~#FG*u+cWQZSXj({hPeBSTJ|J^*Xf0)AGBq_ZIUsjO zHcVM(AW=C?HbYr%Q&Cz?MQBW9O-*QOLoabwIazUSZ)0atYE4jPL{~>eOJY|^3R726 zNO3YaM`%!3byG@MdQ(I>OHgb}X>@NzO*uwSM{`VYPZEFfGJ|Jys zXe@OtXL4m>b7decL}5TvTx@0_C`UygaAk1{F;g#WY;to-SaC6IY&dIXRcJR?d1Pa6 zQ8!L-aY1%+MNl?RF+omhOgU^+S2R;nFhY1{cTF#PLT+YwHCT5_3PV(CPgrU}ZccS! zQgdffS644edU;H4PH;|DZZ9=tLRNS-Hf=;_Zg@~^LRmLPR!Bo^R$6sxT4Q2iLPauF z3N0-yAb40gQARaRX=g@Ld188Lc2jaUXIM~lIdgS&dP8+MM|ML*WLQ}@D{L=k3iTS< zyy-W}%HL8JpDvwSMvCx4Hd=2us+I4B6b*0|Kl8w`q2_7kpVlA-O+Wz@m-Mj+7dc42 zI+<_(-VELpJtr(l(c%0AVbOa8e#(Dy%}JcJ@k;?91X7cC5>L~G)6f^E+4zRH{`!h> z0XlzJN+%1ry-j0C2+#zru2$?~f%GVOcKd9J&Fgv&Q*_1cKQ| z3L=5hnUm6%%xWk~Wn*e=Kc6PeL(6#7d!y+P0avmB`UubS@ z(a&I=8L)6xbFFzdm}(s zja{hHgJFm_Q*ksC4mixb%l8wkCFw2w99No^y7eZ?=7$0XymK^y)2xRL1Tj4F%fbo$ zMG}(or&8#Qfqp z-2-HC_vyaYWc#CUXI?qh`2bV`4d@D=b^g2!IJ9+KzB@xSFZD-by{Fwo6=o*m4S6i_ zUJD;@3a9WT)hU%s!?P~Wgc?Gw&8_)2Q1He3$GQKh>>3^#xtir&y^DcTl%t(!0wkWE zt%WR#PGN@>GwHwW4&6~*cbPkjpn&b&iCGje0Noosv3T zCR=2KE;%rR{usEREq1!RNRiS{U_@i?e|*BO%6L6%y2u_DXFqkO%(%NUe^f9wgy10hgaM9%7#7GmM^f1x8-Aw<)|t)@k8Sbp-r7IPHfJ=9l=0 z?LPenfe#jSDddg?y@piF;F`lUfTgoDS`{@(NXbGGx-hQ_1EBfXAUwXkYTd5{q;|(< zc)Amk;`OJ0|3)@@xBrZmQUvdd`-CpLyF-c?%^Wqi7eKrg&r|tQ)boTvFKkvT(1Qe9 zxhR1bl3AN={PpC4ZyAvik>Li9QPaaoOo`Ceix7;ZyYh9_i+Qz?Xt@L_5M= zPCq1c>6F(wWEbu)gBo$o|IXQRI2_k=yoLD!36?x`+Y@Znn$>%XK>Y&qGAcw^g}PWw z!D%7?+AiIG-BKW`hmI|Jp%(Y#4QF&30y3n2%^e&fxY>kcuD_zYwrFnlWhkR%^wD6q z7Z4Oe9RYP$-~_iqm5Z;iVLe*y);S zWG$&~SV%F}&c_%3F%>+AxsIqD`dqKk=zbtG_9@%2;Riz$*{B@)agOlP+TJYS>$KSd zyD8Z1CRIj=fhR*9Q-o$S)4%SoWL=b$m)Ij)-UQ7zfl6+*tjJTOYQjSYnz*SIrl9L| zy$~Cq{MdsckoN!RWOq_(Dl~=1#u3z&e5NYYJuF?w>^i|=)Z#}d3$;2&SPWIn7lIM zwfCkWaa^`6g|QBwlq0o^cdG-~;c?7VE0kknae(9uT@R2?g4jjW<5X{JBP$+zzI%g*|*?a@- z1#SJvQr}!Y21D|x0W=2Xs%{@EJ8kiRa({<&Y&~~du+*#Rw>K+sva`k+5-Rtrz+vT~ab=@zj+`novWoi}a-Eo#n3{b^Fsd^!qeNC#xG zV#nk$-YrrVX#8Ot-RpPP$#B^0O7ixvb z>iWcY@g?_f!$E9$>3iupP=|1Fnr>k`v547jv;$W5HlkCv%$@gpyAU1?(-!r=ArN3a z4-2Gle>>uYb<1I>#oM@f)6U#3oG$KPlrz8Lv%y7 z6ryF@F2}#q640=CYy$8b{G{3n$n8O(h05DSV(u#$!ZIi0T8}qO0Q|$*wS)g1Cr90U zEf>M($@LCj%#8D7&G$|i->dz|*~{o4k_o10ur|jFgM_Oo)#4CNT5L4;*H`cJ*b0_?Jqkf35W zH+UqxZZ9ne@)}}&kwx~4EbBut0JMyWJ@aB0OA_RUDEPomiagFes3)s6Xey}k{cO2+ z4=4ADFt^z2$-DECZFLBdq^6J2Q9Zlnq=h8x%Mk9zIrQa~o=9Kbb4F z_HwP4!KD@nr1qz}fwCtSo1SsZu@dBCo|99bH+17TjZE#NDa{;e&L97|1Ied?M^J;T zUp;8pV=lF{Q{fEJvlFC1AR=V#hF(_^#vGe!RB@01;&?Cb$8)9TAxsStC+#%RHzl8O zrg-lWJ$6ePl%{=THSFp9qvQR?2hOy`(pdC80+-rG@NIeJ`Hrb z#W+NNm_TB7;g3Dj3Ww5ZaMMKjcVC+4UyBJ^(l|oIBpBrvdH!Ff9r)@=RC!(t*0#ya z0*Cs~?-s2S;)-0k8f?Ig0j+Lq1jY{hfb$U+)b#<~V^X^eYLv!Us_NT|h+81rEyem& zX4^Z*PBLz9Xqb_>X3yECDRWSK4@;9bJJ}5hNDN)fW_pEEy-K(4bI&`y8TCh=#rz-7 zu|UTax_z4_vL{G`zf|rgnDG0wzlEy`kCR2L8yuj!Szede;V^8Jc65n|_$HIIkN{OQPX zs>Tko$dz}YF(KqS2Tz+U&&d$5=bcO;-Bw7bw>0d~{b7dSJAUaE=b&`%BE@11{I4GV z$#_&uXx#B>;IR6zNSeH9&KmsF^UJP=CE};*(|=8U?y#w&FnEIiUU883O^aL z+?<3OCW_M?PfV3g_rPWmV+^J@zd^Q25zF)ngb%=6_3$pPY=-gNJ1Xpy5;jaiaBgRWK<@Ai zUN&Ldxp5Q_#NXvuurPn`bjW-lcJhyNFX@l1F%*( zR|3Sl=i6ym#&_3`Q*%A1kC@5H8nrcXLkspBKu8g43PE&v&(`AiTgM?6!Y9M&TR=qk04=XEzNHYNDORz&+q93#2ZfNqz|f(d(Pzhl>~Hu$?ru zC(HzTz|)HM=VM34A5%^=(rat-eR}QkSeS8$^Ydjr*{aX6dJzZZu=5mr^6&!Nd~tE$ zs}H=v6w$RlX#{pFsWI!;L6XaTAoFm3ZKyK)pfPu#z1!yn<3hk@1iTE2n6S5qN*+lE zu(~qH`3Y%h-L8$WOXo0%f7g(==};_djO(4>XS{|xPOmSRf&aKeQ^M?`g7e>49Zm$! z^+weF2}t}49S)NTj&a_snQ!~!a+$)hj~914k)a5F%E99A1CE;(dH8qm=zRzOlgap9 z-4hmATmv8$odaVs**3aH;>=+66MX|p*N^3;{1r4vFc;Xdm&~(GKWXG5bWWq5}| zgif@-pJf|x@2#(yJv?nEIi!(q0Kr%bzqsPQMhnG;LZ4ei}M<%+j?T zbYGCvL;Yd%hL$!NPRr5dbH4-HHe9kM#(*#(nyC8?Y5T7Ff3@x$Xgx&QI-!$d#S6s` zdSE9cK2KH*1cm?LqTBe5->^ME8@kWJ(#A^iNxW^0?KPAW6e=Syj!-gI-gw_dru=`* zptYmve)I)*wvoROGFk2&eVNsVM*4Sr!r`(%l1Pd`3(&zMqn_0(xT^L}X)XrbPumiY z>H=NsMsGm58>(7WQ3S0Ey8?c&Fm9=NMn>SsSek!6+Uga;RO~g6&E;}m*Y7YB zzJztP5ClU;wd{00*I+MKSi~YoF$;DBE$n?)wCm_51Hnp34-u80>jMS2!!Bv?{u1%m zN7OhI?|^T+Hz;{jt!h?zh_n~ zu`pW?9ZLTB+Hm6tgxia`OjrVUPA~qq+LVYsCKPV{@q#4!_}I<2cXs|J^$NWU2VN;XphMxzyBEU>BzOAck2ZVppw zP_vbp2>_Iul)6IUtx^a4V(mq4k!vc`Wh!rrkW8=^lq7o+aHM+PkE1#O{^B@^bIIU5 z!dbJ=SrVB44a;?FL=jQ|l+Pw_Zp-70jnBOvBiwnEV&qEOgdM?~cn(b4TgM*5cT!oh zFbATZ5s_qWbXeoj`Et?^2#tCreF;3TB^8;+QT-;ifDjz$q1q=)7plR|9{wsBhokfd z22>N~3=247j-=!`9s!2(Jtn9Dya{{^St|PJ%T>hoKKV9iFNF>+F!fvJs&%cNvv1Is z2BP$L4IYMR`LSjvif96lSCp685)98O0Gm+m0xfo3Z{JtI+1a`> z!qarDl#(C2(5Lqzo+|PrJae=sSsU+Dr&3j=xZkc>N58rcuso#4HdIOIQ#C{%>Sn`k z2cZ3Wd!}wrL8vGPpys==3VXIsngu1)VgT>|Frmw@Gv++@;)Sg7BXZ(m!`KdpAf z^fqpM;vTAkE7X)?Yp?;K??Mk4T)isU2OE0REV7{B=Oqs7M6Gzi>sT3w6eDyXe{wM< zS|@bMN_ShQ7PLJ)k?yG4iH`_oF~~Zyq!@gOMUx5PhqYYFpRCkTZKvS~LMB8Fy!zyxDzDQ8SI2axcr^EPB&PH{M+$@RKG|WN;^;YD zGeK{{EiRZ7blHp=^(7&z61rduUN1|T*`ghJPn@a$4rYvz;M4@mvIAyhlk;0#{Gh)j zwUqlm>f9fe_~j|D+CM0 zS$EFLEecE)8biG5p{+D>yI=-EsQq8&&E$cW=;Vm~g@c~s33UPO7#4U*mhg_EWmRwX zh@v#y%z;*uS(-}N);*b3;4UHOT(D-;6}gGmBKAr1FpnTqljG^rlFkn#oZQ;xoFAub zM@aISFW57lQD{YW;kFxz=VG6Jsi&lrH%RK8rVsQENbUcD3|~2Gh}QKJj;9Glge=;b zoA$8Zbd`&iCwKI^?UL0$-|Kj#84VW1N+!k};M8~dKJRPGu)!8`zzEkiydNzLL@xp8C^z=k?0I%Vwjcb_mATq;b z=ODJufNsz>y9i5wtWq~1ag~&|@AO1B3Rh*~=*|7AC)=BOTmb8MYmt*>!U@>flnD12 zT}udPvSZ5PQT63l+}0Q86{r&>+#>Ozd#MRG-{WEZcmzJ;bS>_D1PLfY3;X}}O4TcB zQwL!rs!@R9x0)Xf%>Z0Y)RF~k>r;lrh^dBD2%|;sHMdh3txmp>&_1h!FNrw5!;0>1 z?DqF<#MtxLvYpwk9JAdbJoTxZJ%RCs0d4+c2FZpaMnfCw?UsoFC@=XG2qriyk{?Yr zNaM@4{*we)gxTEO2ANW&57>|SpwUM@s#M5CrMf&Z9yX`Wir;Acybh{`!7C zpgGNounRmuwBADRB|!b;M{68TW3r8WAtT<}vyBIgMBbNOy=^O~1+3wVlCD^A=>OnP z7!W|+T#VuP2)~|5uQ~N@K&%b)kd+)#GEvm!n+BUxuDBaLqujv!p{Q>zxg;{y7p?5l5f9xEbG@jym4|L)GOt zIu!hQQ>*s;#lA?ZK*Z-XCgxr6yZ*UfRhZ!X+0T@0)BP$ zh&8MD((kup@<#q1a&NS`<=Bw<=5t7u`-SK>Ik;wui#S!nA-i#agt>Ek;0JR4;Hr!& zp4~M1B$$f(@4SOqsF$VG5167{g#+DE%+q~^qAC0YED7M|^XvB?i<%)Ib&lKdKu!ju z`Fz8CXc@l#S%)?j18sqi9&8a`7LRT|UnlwWU4zWWWeIz%L1iI;t5H+$SKUXTE4MY= zmc3O%S0Vf#mwp({oTIyhk*s8Phv9488u^9NP*X&X=|&&K87%AK7}KH=*~(yY4x~sO z0^UWml>naTevNA|!(Y{1F*7#&&Il*nR{EFx*j{=J?yB>;Q)uU~($ddskVi^hW)Ra% zv@=Zq;{aGBHS(EXs&puSRb=35PkBYQkv{tZ;tL=fCT~2)zzMA$m8Zk%J5U>(D7I|82%Pi2(eULua=(?zBUEOc8@6unCVKhQROQE z5q_>2xT`mFJ-m!*5a-$P$iwV=0{@EyQ6#MBwJiF%dD{GEwm@UB7K-a@NW~52-p`R? zC~G8mG5B2H-yXlI;Z4CyAsXx65L^k*>j{rZoEh0ev4Kx>f>RJg-@1iVH877W!JalJx;`rl3IUQ8H|NZ(}A`N;ZR1h=t=bXS9i4`X!uR&x+H z>I}pQe1lxBeCMlU(i`FoE&OBVoa;csQTr9OnrCm76(Qw}3~yQV6s6 zj#-_P1!5YACX*KJ9xIX3&kPm$1!5&SjVVT#siV&5gX4*$0)JwN^a|{LqlA{qcI5FA$vcUP0gQmh!6ioJjU|IgutN>7^){R} zbqBnv-HFPPvS9g=6rn5+aW*w<`lncua&*c2cR1?dW8n`^8TgpG;aX}J$3hIh1fL;$ zchG#t?~f85C-SaaiDY%Gl8LeG{wsATM>g-xkUo?G^3vW{Xb)i>oV#bTA@{1z3m;%c z(-ZChpti6TTPE=|*2!>JbwKi~$*9EZdI{9D)OP$`vRD=qn0Mpmo6VI(Y@0C4p6s<+ z#bZ7pDjV1UT4??cMT4JjDNfjg7sdbkVn}O2+MYSAtEGw1yqe85IBg~tMkJdB#6q&m zkTIhN#q|@V>_#N`jPi57KwksnC(5M+UrNmY67=YF%Hz^GQj*nkU^;CheE&b4e-VH# zHYy3!px-Zjtfs#BhP-UUMoMktoCp|iP^W_L8nNEJ=TI~3hF$T}j4V2b53T3dKvfL@ zl3`{gYRhZ$o*fVKiS+?Aw!znNSpGH2)@NdCP!i|z@)O_lu;_1H9dQ(n2@UpfyGZaf zCc552=eqAbv3Fz4#a{1@77A!yvaq6H*)+i@*=c{2j+60uh|Nt+XT6t0~sw=8jMSub~pI zjVt$f-&>4G{94puZ&y$H6$}r@(SIw%!U{it<6#T5kXM`!{nX6|pJ0+Op(VoH6f3wv zy~U0cjqG#_GcLdrXp0JDTY+qxYfaBfq|2Z`0e0PRNWgGS@%6CHZ9sP-tIrX5@sANt z-IYpb`KKF^6}WSCkfdR(r`CAnM5(Im9Mz0@w;P+vG}d`vT~Fv{o65_P|2f3@0tG$$$w`HiB=zJFq@JrRro{ zio8b!`C&0e8rmv^FNo(Xc&uugy^8*XpWXiW9W||i*fPo2vEP#OUJKnSWuODgn}5ck JI69}TAq2R-D8~Q* literal 0 HcmV?d00001 diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 3251a54..2b9e941 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -16,4 +16,5 @@ in { "spotifyd.age".publicKeys = users ++ hosts; "email-desktop.age".publicKeys = users ++ hosts; "email-laptop.age".publicKeys = users ++ hosts; + "home-vpn.age".publicKeys = users ++ hosts; }