Files
nixos-config/servers/hetzner/modules/services/wireguard.nix
T
jory 5116faf0d3
CI / Flake check (aarch64-linux) (push) Successful in 29s
CI / Flake check (x86_64-linux) (push) Successful in 30s
CI / Pre-commit checks (x86_64-linux) (push) Successful in 8s
Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  deadnix); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys)
  + disable empty_pattern via statix.toml (nixpkgs standard)
- Clean up unused lambda patterns across 38 .nix files via deadnix
- Format whole repo with alejandra (27 files)
- Remove .github/workflows/ci.yml (Gitea shadows .github; runner labels differ)
- Fix CI nix-not-found: export /run/current-system/sw/bin in PATH
- Trim aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
2026-07-12 09:11:41 +02:00

23 lines
584 B
Nix

{...}: {
virtualisation.oci-containers.containers.wg-easy = {
image = "ghcr.io/wg-easy/wg-easy:latest";
autoStart = true;
volumes = [
"/home/admin/config:/etc/wireguard:Z"
];
environment = {
WG_HOST = "severijnse.eu";
PASSWORD_HASH = "$2a$12$b3n4drXgS3B6ubMZxxjPUOQ1XktZ1EuDwm4AIdVulhtoD7b1.WQGC";
WG_DEFAULT_ADDRESS = "10.8.0.x";
WG_DEFAULT_DNS = "1.1.1.1";
WG_PORT = "51820";
};
extraOptions = [
"--cap-add=NET_ADMIN"
"--cap-add=SYS_MODULE"
"--cap-add=NET_RAW"
"--network=host"
];
};
}