summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorRyan Lahfa <masterancpp@gmail.com>2023-03-22 20:27:18 +0100
committerGitHub <noreply@github.com>2023-03-22 20:27:18 +0100
commitb712670a1fa2be70d23ce65d83b1ccbbdabe5ad2 (patch)
treeab146d86cc41961e0ffa1ceae6f2597c8b14949e
parentMerge pull request #217366 from puppe/fix-yggdrasil (diff)
downloadnixpkgs-origin/revert-217366-fix-yggdrasil.tar.gz
Revert "nixos/yggdrasil: fix configFile option"origin/revert-217366-fix-yggdrasil
-rw-r--r--nixos/modules/services/networking/yggdrasil.nix186
1 files changed, 79 insertions, 107 deletions
diff --git a/nixos/modules/services/networking/yggdrasil.nix b/nixos/modules/services/networking/yggdrasil.nix
index 55a6002d61af..fd7193154c6c 100644
--- a/nixos/modules/services/networking/yggdrasil.nix
+++ b/nixos/modules/services/networking/yggdrasil.nix
@@ -8,8 +8,7 @@ let
configFileProvided = cfg.configFile != null;
format = pkgs.formats.json { };
-in
-{
+in {
imports = [
(mkRenamedOptionModule
[ "services" "yggdrasil" "config" ]
@@ -22,7 +21,7 @@ in
settings = mkOption {
type = format.type;
- default = { };
+ default = {};
example = {
Peers = [
"tcp://aa.bb.cc.dd:eeeee"
@@ -46,7 +45,7 @@ in
If no keys are specified then ephemeral keys are generated
and the Yggdrasil interface will have a random IPv6 address
- each time the service is started. This is the default.
+ each time the service is started, this is the default.
If both {option}`configFile` and {option}`settings`
are supplied, they will be combined, with values from
@@ -62,13 +61,8 @@ in
default = null;
example = "/run/keys/yggdrasil.conf";
description = lib.mdDoc ''
- A file which contains JSON or HJSON configuration for yggdrasil. See
- the {option}`settings` option for more information.
-
- Note: This file must not be larger than 1 MB because it is passed to
- the yggdrasil process via systemd‘s LoadCredential mechanism. For
- details, see <https://systemd.io/CREDENTIALS/> and `man 5
- systemd.exec`.
+ A file which contains JSON configuration for yggdrasil.
+ See the {option}`settings` option for more information.
'';
};
@@ -83,20 +77,20 @@ in
type = bool;
default = false;
description = lib.mdDoc ''
- Whether to open the UDP port used for multicast peer discovery. The
- NixOS firewall blocks link-local communication, so in order to make
- incoming local peering work you will also need to configure
- `MulticastInterfaces` in your Yggdrasil configuration
- ({option}`settings` or {option}`configFile`). You will then have to
- add the ports that you configure there to your firewall configuration
- ({option}`networking.firewall.allowedTCPPorts` or
- {option}`networking.firewall.interfaces.<name>.allowedTCPPorts`).
+ Whether to open the UDP port used for multicast peer
+ discovery. The NixOS firewall blocks link-local
+ communication, so in order to make local peering work you
+ will also need to set `LinkLocalTCPPort` in your
+ yggdrasil configuration ({option}`settings` or
+ {option}`configFile`) to a port number other than 0,
+ and then add that port to
+ {option}`networking.firewall.allowedTCPPorts`.
'';
};
denyDhcpcdInterfaces = mkOption {
type = listOf str;
- default = [ ];
+ default = [];
example = [ "tap*" ];
description = lib.mdDoc ''
Disable the DHCP client for any interface whose name matches
@@ -124,102 +118,80 @@ in
};
};
- config = mkIf cfg.enable (
- let
- binYggdrasil = "${cfg.package}/bin/yggdrasil";
- binHjson = "${pkgs.hjson-go}/bin/hjson-cli";
- in
- {
- assertions = [{
- assertion = config.networking.enableIPv6;
- message = "networking.enableIPv6 must be true for yggdrasil to work";
- }];
-
- system.activationScripts.yggdrasil = mkIf cfg.persistentKeys ''
- if [ ! -e ${keysPath} ]
- then
- mkdir --mode=700 -p ${builtins.dirOf keysPath}
- ${binYggdrasil} -genconf -json \
- | ${pkgs.jq}/bin/jq \
- 'to_entries|map(select(.key|endswith("Key")))|from_entries' \
- > ${keysPath}
- fi
- '';
-
- systemd.services.yggdrasil = {
- description = "Yggdrasil Network Service";
- after = [ "network-pre.target" ];
- wants = [ "network.target" ];
- before = [ "network.target" ];
- wantedBy = [ "multi-user.target" ];
+ config = mkIf cfg.enable (let binYggdrasil = cfg.package + "/bin/yggdrasil";
+ in {
+ assertions = [{
+ assertion = config.networking.enableIPv6;
+ message = "networking.enableIPv6 must be true for yggdrasil to work";
+ }];
- # This script first prepares the config file, then it starts Yggdrasil.
- # The preparation could also be done in ExecStartPre/preStart but only
- # systemd versions >= v252 support reading credentials in ExecStartPre. As
- # of February 2023, systemd v252 is not yet in the stable branch of NixOS.
- #
- # This could be changed in the future once systemd version v252 has
- # reached NixOS but it does not have to be. Config file preparation is
- # fast enough, it does not need elevated privileges, and `set -euo
- # pipefail` should make sure that the service is not started if the
- # preparation fails. Therefore, it is not necessary to move the
- # preparation to ExecStartPre.
- script = ''
- set -euo pipefail
+ system.activationScripts.yggdrasil = mkIf cfg.persistentKeys ''
+ if [ ! -e ${keysPath} ]
+ then
+ mkdir --mode=700 -p ${builtins.dirOf keysPath}
+ ${binYggdrasil} -genconf -json \
+ | ${pkgs.jq}/bin/jq \
+ 'to_entries|map(select(.key|endswith("Key")))|from_entries' \
+ > ${keysPath}
+ fi
+ '';
- # prepare config file
- ${(if settingsProvided || configFileProvided || cfg.persistentKeys then
- "echo "
+ systemd.services.yggdrasil = {
+ description = "Yggdrasil Network Service";
+ after = [ "network-pre.target" ];
+ wants = [ "network.target" ];
+ before = [ "network.target" ];
+ wantedBy = [ "multi-user.target" ];
- + (lib.optionalString settingsProvided
- "'${builtins.toJSON cfg.settings}'")
- + (lib.optionalString configFileProvided
- "$(${binHjson} -c \"$CREDENTIALS_DIRECTORY/yggdrasil.conf\")")
- + (lib.optionalString cfg.persistentKeys "$(cat ${keysPath})")
- + " | ${pkgs.jq}/bin/jq -s add | ${binYggdrasil} -normaliseconf -useconf"
- else
- "${binYggdrasil} -genconf") + " > /run/yggdrasil/yggdrasil.conf"}
+ preStart =
+ (if settingsProvided || configFileProvided || cfg.persistentKeys then
+ "echo "
- # start yggdrasil
- ${binYggdrasil} -useconffile /run/yggdrasil/yggdrasil.conf
- '';
+ + (lib.optionalString settingsProvided
+ "'${builtins.toJSON cfg.settings}'")
+ + (lib.optionalString configFileProvided "$(cat ${cfg.configFile})")
+ + (lib.optionalString cfg.persistentKeys "$(cat ${keysPath})")
+ + " | ${pkgs.jq}/bin/jq -s add | ${binYggdrasil} -normaliseconf -useconf"
+ else
+ "${binYggdrasil} -genconf") + " > /run/yggdrasil/yggdrasil.conf";
- serviceConfig = {
- ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID";
- Restart = "always";
+ serviceConfig = {
+ ExecStart =
+ "${binYggdrasil} -useconffile /run/yggdrasil/yggdrasil.conf";
+ ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID";
+ Restart = "always";
- DynamicUser = true;
- StateDirectory = "yggdrasil";
- RuntimeDirectory = "yggdrasil";
- RuntimeDirectoryMode = "0750";
- BindReadOnlyPaths = lib.optional cfg.persistentKeys keysPath;
- LoadCredential =
- mkIf configFileProvided "yggdrasil.conf:${cfg.configFile}";
+ DynamicUser = true;
+ StateDirectory = "yggdrasil";
+ RuntimeDirectory = "yggdrasil";
+ RuntimeDirectoryMode = "0750";
+ BindReadOnlyPaths = lib.optional configFileProvided cfg.configFile
+ ++ lib.optional cfg.persistentKeys keysPath;
+ ReadWritePaths = "/run/yggdrasil";
- AmbientCapabilities = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE";
- CapabilityBoundingSet = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE";
- MemoryDenyWriteExecute = true;
- ProtectControlGroups = true;
- ProtectHome = "tmpfs";
- ProtectKernelModules = true;
- ProtectKernelTunables = true;
- RestrictAddressFamilies = "AF_UNIX AF_INET AF_INET6 AF_NETLINK";
- RestrictNamespaces = true;
- RestrictRealtime = true;
- SystemCallArchitectures = "native";
- SystemCallFilter = [ "@system-service" "~@privileged @keyring" ];
- } // (if (cfg.group != null) then {
- Group = cfg.group;
- } else { });
- };
+ AmbientCapabilities = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE";
+ CapabilityBoundingSet = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE";
+ MemoryDenyWriteExecute = true;
+ ProtectControlGroups = true;
+ ProtectHome = "tmpfs";
+ ProtectKernelModules = true;
+ ProtectKernelTunables = true;
+ RestrictAddressFamilies = "AF_UNIX AF_INET AF_INET6 AF_NETLINK";
+ RestrictNamespaces = true;
+ RestrictRealtime = true;
+ SystemCallArchitectures = "native";
+ SystemCallFilter = [ "@system-service" "~@privileged @keyring" ];
+ } // (if (cfg.group != null) then {
+ Group = cfg.group;
+ } else {});
+ };
- networking.dhcpcd.denyInterfaces = cfg.denyDhcpcdInterfaces;
- networking.firewall.allowedUDPPorts = mkIf cfg.openMulticastPort [ 9001 ];
+ networking.dhcpcd.denyInterfaces = cfg.denyDhcpcdInterfaces;
+ networking.firewall.allowedUDPPorts = mkIf cfg.openMulticastPort [ 9001 ];
- # Make yggdrasilctl available on the command line.
- environment.systemPackages = [ cfg.package ];
- }
- );
+ # Make yggdrasilctl available on the command line.
+ environment.systemPackages = [ cfg.package ];
+ });
meta = {
doc = ./yggdrasil.md;
maintainers = with lib.maintainers; [ gazally ehmry ];