summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorlassulus <lass@aidsballs.de>2016-09-13 00:04:48 +0200
committerlassulus <lass@aidsballs.de>2016-09-13 00:04:48 +0200
commitf9148e16d478bdf6339d194cd9c8770ff244e759 (patch)
tree37562bc89f6c57ad4d335cdb4bb36c3d19390f2b
parent928ac9f153682aa2a98213a39b6732591a8c27a6 (diff)
l 2: add iodined.nix & import in prism
-rw-r--r--lass/1systems/prism.nix1
-rw-r--r--lass/2configs/iodined.nix20
2 files changed, 21 insertions, 0 deletions
diff --git a/lass/1systems/prism.nix b/lass/1systems/prism.nix
index 9cf5ca009..b508103c5 100644
--- a/lass/1systems/prism.nix
+++ b/lass/1systems/prism.nix
@@ -23,6 +23,7 @@ in {
../2configs/buildbot-standalone.nix
../2configs/repo-sync.nix
../2configs/binary-cache/server.nix
+ ../2configs/iodined.nix
{
imports = [
../2configs/git.nix
diff --git a/lass/2configs/iodined.nix b/lass/2configs/iodined.nix
new file mode 100644
index 000000000..3108a6b23
--- /dev/null
+++ b/lass/2configs/iodined.nix
@@ -0,0 +1,20 @@
+{ pkgs, config, ... }:
+
+let
+ # TODO: make this a parameter
+ domain = "io.lassul.us";
+ pw = import <secrets/iodinepw.nix>;
+in {
+
+ services.iodined = {
+ enable = true;
+ domain = domain;
+ ip = "172.16.10.1/24";
+ extraConfig = "-P ${pw} -l ${config.krebs.build.host.nets.internet.ip4.addr}";
+ };
+
+ krebs.iptables.tables.filter.INPUT.rules = [
+ { predicate = "-p udp --dport 54"; target = "ACCEPT";}
+ ];
+
+}