diff options
author | lassulus <lass@aidsballs.de> | 2016-09-13 00:04:48 +0200 |
---|---|---|
committer | lassulus <lass@aidsballs.de> | 2016-09-13 00:04:48 +0200 |
commit | f9148e16d478bdf6339d194cd9c8770ff244e759 (patch) | |
tree | 37562bc89f6c57ad4d335cdb4bb36c3d19390f2b | |
parent | 928ac9f153682aa2a98213a39b6732591a8c27a6 (diff) |
l 2: add iodined.nix & import in prism
-rw-r--r-- | lass/1systems/prism.nix | 1 | ||||
-rw-r--r-- | lass/2configs/iodined.nix | 20 |
2 files changed, 21 insertions, 0 deletions
diff --git a/lass/1systems/prism.nix b/lass/1systems/prism.nix index 9cf5ca009..b508103c5 100644 --- a/lass/1systems/prism.nix +++ b/lass/1systems/prism.nix @@ -23,6 +23,7 @@ in { ../2configs/buildbot-standalone.nix ../2configs/repo-sync.nix ../2configs/binary-cache/server.nix + ../2configs/iodined.nix { imports = [ ../2configs/git.nix diff --git a/lass/2configs/iodined.nix b/lass/2configs/iodined.nix new file mode 100644 index 000000000..3108a6b23 --- /dev/null +++ b/lass/2configs/iodined.nix @@ -0,0 +1,20 @@ +{ pkgs, config, ... }: + +let + # TODO: make this a parameter + domain = "io.lassul.us"; + pw = import <secrets/iodinepw.nix>; +in { + + services.iodined = { + enable = true; + domain = domain; + ip = "172.16.10.1/24"; + extraConfig = "-P ${pw} -l ${config.krebs.build.host.nets.internet.ip4.addr}"; + }; + + krebs.iptables.tables.filter.INPUT.rules = [ + { predicate = "-p udp --dport 54"; target = "ACCEPT";} + ]; + +} |