add vpn and transmission

This commit is contained in:
nicknase27
2026-07-26 14:26:19 +02:00
parent f9810da223
commit 82db9dd9cf
6 changed files with 81 additions and 1 deletions
Generated
+17 -1
View File
@@ -138,7 +138,8 @@
"inputs": {
"agenix": "agenix",
"nixpkgs": "nixpkgs_2",
"unifi-os-server": "unifi-os-server"
"unifi-os-server": "unifi-os-server",
"vpn-confinement": "vpn-confinement"
}
},
"systems": {
@@ -189,6 +190,21 @@
"repo": "unifi-os-server",
"type": "github"
}
},
"vpn-confinement": {
"locked": {
"lastModified": 1784582736,
"narHash": "sha256-a3V/LkUvwbN30QlCwPjNQq88TGOXiqXAzcYTSWgYIp4=",
"owner": "Maroka-chan",
"repo": "VPN-Confinement",
"rev": "bd17046da0262f3a93524845982825fa2ed23f40",
"type": "github"
},
"original": {
"owner": "Maroka-chan",
"repo": "VPN-Confinement",
"type": "github"
}
}
},
"root": "root",
+3
View File
@@ -5,6 +5,7 @@
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
agenix.url = "github:ryantm/agenix";
unifi-os-server.url = "github:rcambrj/unifi-os-server";
vpn-confinement.url = "github:Maroka-chan/VPN-Confinement";
};
outputs = {
@@ -12,6 +13,7 @@
nixpkgs,
agenix,
unifi-os-server,
vpn-confinement,
...
} @ inputs: {
nixosConfigurations.Hermes = nixpkgs.lib.nixosSystem {
@@ -24,6 +26,7 @@
./modules/system
agenix.nixosModules.default
unifi-os-server.nixosModules.unifi-os-server
vpn-confinement.nixosModules.default
];
};
};
+1
View File
@@ -4,6 +4,7 @@
...
}: {
imports = [
./transmission.nix
./vaultwarden.nix
./navidrome.nix
./caddy.nix
+59
View File
@@ -0,0 +1,59 @@
{
pkgs,
lib,
config,
inputs,
...
}: {
# Define VPN network namespace
vpnNamespaces.wg0 = {
enable = true;
wireguardConfigFile = "${config.age.secrets.wg0.path}";
accessibleFrom = [
"10.0.0.0/24"
];
portMappings = [
{
from = 9091;
to = 9091;
}
];
openVPNPorts = [
{
port = 51413;
protocol = "both";
}
];
};
systemd.services.transmission = {
vpnConfinement = {
enable = true;
vpnNamespace = "wg0";
};
wants = ["wg0.service"];
after = ["wg0.service"];
partOf = ["wg0.service"];
serviceConfig = {
Restart = "always";
RestartSec = 5;
};
};
services.transmission = {
enable = true;
settings = {
"rpc-bind-address" = "0.0.0.0"; # Bind RPC/WebUI to VPN network namespace address
"rpc-whitelist-enabled" = false;
"rpc-whitelist" = "10.0.0.*,127.0.0.1";
download-dir = "/mnt/media/downloads";
incomplete-dir-enabled = false;
};
};
age.secrets.wg0 = {
file = ../../secrets/wg0.age;
path = "/run/secrets/wg0.conf";
};
}
+1
View File
@@ -11,4 +11,5 @@ in {
"gitea-runner.age".publicKeys = systems;
"navidrome.age".publicKeys = systems;
"vaultwarden.age".publicKeys = systems;
"wg0.age".publicKeys = systems;
}
BIN
View File
Binary file not shown.