diff --git a/hosts/dn42-il-gw1/configuration.nix b/hosts/dn42-il-gw1/configuration.nix index f7b22bf..5086572 100644 --- a/hosts/dn42-il-gw1/configuration.nix +++ b/hosts/dn42-il-gw1/configuration.nix @@ -62,6 +62,44 @@ ]; privateKeyFile = config.sops.secrets.wg0565.path; }; + # prefixlabs + # https://prefixlabs.net/ + wg1240 = { + ips = [ + "fe80::2574/128" + ]; + postSetup = '' + ip addr replace dev wg1718 fe80::2574/128 peer fe80::1240:11/128 + ''; + listenPort = 51240; + allowedIPsAsRoutes = false; + peers = [ + { + allowedIPs = [ "fe80::/10" "fd00::/8" ]; + endpoint = "de-01.prefixlabs.net:22574"; + publicKey = "ixeEBfac1BXpjNKbxcgL6Beg9HTgtmq6CjHIfMwNSDw="; + } + ]; + privateKeyFile = config.sops.secrets.wg1240.path; + }; + wg1241 = { + ips = [ + "fe80::2574/128" + ]; + postSetup = '' + ip addr replace dev wg1718 fe80::2574/128 peer fe80::1240:1/128 + ''; + listenPort = 51241; + allowedIPsAsRoutes = false; + peers = [ + { + allowedIPs = [ "fe80::/10" "fd00::/8" ]; + endpoint = "uk-01.prefixlabs.net:22574"; + publicKey = "Yu1Y4qdSaf+OWPbAoh7PvuM2eWCVbNg84+EX5Q2Zjl4="; + } + ]; + privateKeyFile = config.sops.secrets.wg1241.path; + }; # fooker wg1271 = { ips = [ @@ -164,6 +202,8 @@ networking.firewall.allowedUDPPorts = [ 50565 # wg0565 + 51240 # wg1240 + 51241 # wg1241 51271 # wg1271 51272 # wg1272 51280 # wg1280 @@ -199,6 +239,20 @@ remoteAsn = "4242420565"; localAddress = "fe80::2574"; } + { + peerName = "peer_1240_de_01"; + remoteAddress = "fe80::1240:11"; + interfaceName = "wg1240"; + remoteAsn = "4242421240"; + localAddress = "fe80::2574"; + } + { + peerName = "peer_1240_uk_01"; + remoteAddress = "fe80::1240:1"; + interfaceName = "wg1241"; + remoteAsn = "4242421240"; + localAddress = "fe80::2574"; + } { peerName = "peer_1271_north"; remoteAddress = "fe80::2"; diff --git a/hosts/dn42-il-gw1/secrets.json b/hosts/dn42-il-gw1/secrets.json index 7290601..3126b12 100644 --- a/hosts/dn42-il-gw1/secrets.json +++ b/hosts/dn42-il-gw1/secrets.json @@ -1,6 +1,8 @@ { "wg0197": "ENC[AES256_GCM,data:1QJ5GXLMLIOj6xNC4sMnShjyB1wqfTkhkPTlLJz6AJxMjA0BsBZvZ1Pdln4=,iv:nVRIQB8/Ged616ELhkGnDyAz6A+3HQ55+yG0vf0f7aQ=,tag:GtI8ICMCih1tN4Xoc+8RdQ==,type:str]", "wg0565": "ENC[AES256_GCM,data:kLgKOGDA+kPDB0SZ/yU7Ax7NYn28LiVT2W6zSsc0APfyoZWW6nF0fUQFv4s=,iv:6zjLGAOROifubQUMxRLvoFzN6GRYob841rzNiVyrt84=,tag:Gh15/ROPYiqqobcJcTzmGQ==,type:str]", + "wg1240": "ENC[AES256_GCM,data:ta0FRxhDGeta6TpWghWP2ogqymtiVsnWvuwzOhqhGN6zyK/GYd5b+SgSYAI=,iv:9gxEtK+ZOFj0D/SNWV7GyWHkBXjGgofJPmqcu3CMMKo=,tag:MFE/bhGk6oLeOK4TaEoXgQ==,type:str]", + "wg1241": "ENC[AES256_GCM,data:qjr50/KWJya8YiNQ2pymlUGMIZBdOY1Opt/rmM6Iill/B5jWiPOJuGQdKnc=,iv:WSoRv7wvLTmTX0lV9yhfenwLtTvVmPNK+Hqd6H3iFEU=,tag:SRwAWQa761PL8JqdVgTr3Q==,type:str]", "wg1271": "ENC[AES256_GCM,data:NPcFMxVNpwoPkLsb6NvZVxGxw+Og3RzlYx7TAL9nT95x6I8aDRpOnR5tY5w=,iv:gYuem6vX+jRQvirrt3lZQb5gKnN/z32W/MgmGuzQ/Ks=,tag:I9qZJSNKFEM3Vx4Yugxy1w==,type:str]", "wg1272": "ENC[AES256_GCM,data:LU6jtNkNn2Xs+0OH8cD1HJnbHsNNnqlY83lDFa11/dHwVgdFxMtDXMqIMEc=,iv:/A8rWGR6jExa4ms7jTYC0eZVGCvlKw1I58Co41gw3TU=,tag:tIBRkQzFFpEEzflnDrpcOA==,type:str]", "wg1280": "ENC[AES256_GCM,data:F4KLY6jiZNl52ko32nM0iTER0DyHvaCSmxeYAKB0MLUD8l9u1Ugk6kYZnUc=,iv:XcaxnvxM1kE/ahNFX+BH7Jmr9q2Py1vHHqOjFUqs5O8=,tag:a1up4gGFqyHz2lmDRJl3bA==,type:str]", @@ -15,8 +17,8 @@ "enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA3QWdFYjFjTmRVRlV3U3p4\nTSsyc1E0dWtiYjNtVkV2SXJEWkxnTDhLN1Y0Cng4aGlidjhydUVGaFcvK215aGdq\nN0FGajYwa1lPUCsva0tmNkErUGtlOWsKLS0tIG9pLzJEUDA2WWUzd1kzSVZrdVRX\nbUxjQzBCd3p0R1dWTTJaRmZNQjJEUVkKPz6OUQHpYrhRxMdQzpZRR3exVqkG2JvX\nI32PwvbeQK8cgpYwKLGar8U8aiPPm0Y64pID1wedDsNZzLqLOrS3wQ==\n-----END AGE ENCRYPTED FILE-----\n" } ], - "lastmodified": "2025-06-10T20:51:10Z", - "mac": "ENC[AES256_GCM,data:9lF4HV0oJyGHXdtYdMxR7+ev7JLAQVr6kE55nLoZcrbC92MHJzQpgM9XAhIynvwdAmC7ARd3orCn6eYkQJDdNX0JjMtebsBE+H4B7mEUCz8wtTN0iHS+oHmQxrqjnoSw2uHh9udgqAJa+sd6VGU3t2XUuuKtVHPwzROqVgvas9M=,iv:KT+BlFeXGZQc5pbBX+XOsmKEydUtir1LuPvseDkFeqw=,tag:hlRskY6b5EAZkUYs7ph/JA==,type:str]", + "lastmodified": "2025-12-03T17:59:59Z", + "mac": "ENC[AES256_GCM,data:v6Wpp641MvetzKj36sw422T5yZp3XssRXHMVMI0RA28dyZSeNSQ+YI0UBItUH1FXyieZSvHtpFf7LiY+xSCRuwZB8H9ofofwOxhJU3F5Abzb/aAL4rRnsbawYp1SZVWVhtt2FXBgvtWAJKn5iPHjpUU6ccdaW/OuHnudHfeQxZg=,iv:s8Z6r7tF9u3l1ygnX6rdU3xiU9TPG6qY2vTuR5fGCQQ=,tag:Jf93btCoTWIBTCMpHU864A==,type:str]", "pgp": [ { "created_at": "2024-04-28T09:25:37Z", @@ -25,6 +27,6 @@ } ], "unencrypted_suffix": "_unencrypted", - "version": "3.10.2" + "version": "3.11.0" } }