nixpkgs/nixos/modules/services/networking/hans.nix

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

146 lines
3.8 KiB
Nix
Raw Normal View History

2018-03-27 16:43:11 +00:00
# NixOS module for hans, ip over icmp daemon
{ config, lib, pkgs, ... }:
with lib;
let
cfg = config.services.hans;
hansUser = "hans";
in
{
### configuration
options = {
services.hans = {
clients = mkOption {
default = {};
description = lib.mdDoc ''
Each attribute of this option defines a systemd service that
runs hans. Many or none may be defined.
The name of each service is
`hans-«name»`
where «name» is the name of the
2018-03-27 16:43:11 +00:00
corresponding attribute name.
'';
example = literalExpression ''
2018-03-27 16:43:11 +00:00
{
foo = {
server = "192.0.2.1";
2018-03-27 19:23:36 +00:00
extraConfig = "-v";
2018-03-27 16:43:11 +00:00
}
}
'';
type = types.attrsOf (types.submodule (
{
options = {
server = mkOption {
type = types.str;
default = "";
description = lib.mdDoc "IP address of server running hans";
example = "192.0.2.1";
};
extraConfig = mkOption {
type = types.str;
default = "";
description = lib.mdDoc "Additional command line parameters";
2018-03-27 19:23:36 +00:00
example = "-v";
2018-03-27 16:43:11 +00:00
};
2018-03-27 19:23:36 +00:00
passwordFile = mkOption {
type = types.str;
default = "";
2022-12-18 00:31:14 +00:00
description = lib.mdDoc "File that contains password";
2018-03-27 19:23:36 +00:00
};
2018-03-27 16:43:11 +00:00
};
}));
};
server = {
enable = mkOption {
type = types.bool;
default = false;
description = lib.mdDoc "enable hans server";
};
ip = mkOption {
type = types.str;
default = "";
description = lib.mdDoc "The assigned ip range";
example = "198.51.100.0";
};
2018-03-28 06:13:09 +00:00
respondToSystemPings = mkOption {
2018-03-27 16:43:11 +00:00
type = types.bool;
default = false;
2018-03-28 06:13:09 +00:00
description = lib.mdDoc "Force hans respond to ordinary pings";
2018-03-27 16:43:11 +00:00
};
extraConfig = mkOption {
type = types.str;
default = "";
description = lib.mdDoc "Additional command line parameters";
2018-03-27 19:23:36 +00:00
example = "-v";
};
passwordFile = mkOption {
type = types.str;
default = "";
2022-12-18 00:31:14 +00:00
description = lib.mdDoc "File that contains password";
2018-03-27 16:43:11 +00:00
};
};
};
};
### implementation
config = mkIf (cfg.server.enable || cfg.clients != {}) {
2018-03-28 06:13:09 +00:00
boot.kernel.sysctl = optionalAttrs cfg.server.respondToSystemPings {
2018-03-27 16:43:11 +00:00
"net.ipv4.icmp_echo_ignore_all" = 1;
};
boot.kernelModules = [ "tun" ];
systemd.services =
let
createHansClientService = name: cfg:
{
description = "hans client - ${name}";
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
2018-03-28 05:32:29 +00:00
script = "${pkgs.hans}/bin/hans -f -u ${hansUser} ${cfg.extraConfig} -c ${cfg.server} ${optionalString (cfg.passwordFile != "") "-p $(cat \"${cfg.passwordFile}\")"}";
2018-03-27 16:43:11 +00:00
serviceConfig = {
RestartSec = "30s";
Restart = "always";
};
};
in
listToAttrs (
mapAttrsToList
(name: value: nameValuePair "hans-${name}" (createHansClientService name value))
cfg.clients
) // {
hans = mkIf (cfg.server.enable) {
description = "hans, ip over icmp server daemon";
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
script = "${pkgs.hans}/bin/hans -f -u ${hansUser} ${cfg.server.extraConfig} -s ${cfg.server.ip} ${optionalString cfg.server.respondToSystemPings "-r"} ${optionalString (cfg.server.passwordFile != "") "-p $(cat \"${cfg.server.passwordFile}\")"}";
2018-03-27 16:43:11 +00:00
};
};
users.users.${hansUser} = {
2018-03-27 16:43:11 +00:00
description = "Hans daemon user";
2019-10-12 20:25:28 +00:00
isSystemUser = true;
2018-03-27 16:43:11 +00:00
};
};
meta.maintainers = with maintainers; [ ];
2018-03-27 16:43:11 +00:00
}