{ config, ... }: { # Define VPN network namespace vpnNamespaces.wg0 = { enable = true; wireguardConfigFile = "${config.age.secrets.wg0.path}"; accessibleFrom = [ "10.0.0.0/24" ]; portMappings = [ { from = 9091; to = 9091; } ]; openVPNPorts = [ { port = 51413; protocol = "both"; } ]; }; systemd.services.transmission = { vpnConfinement = { enable = true; vpnNamespace = "wg0"; }; wants = ["wg0.service"]; after = ["wg0.service"]; partOf = ["wg0.service"]; serviceConfig = { Restart = "always"; RestartSec = 5; }; }; services.transmission = { enable = true; settings = { download-dir = "/mnt/media/downloads"; incomplete-dir-enabled = false; "rpc-bind-address" = "0.0.0.0"; # Bind RPC/WebUI to VPN network namespace address "rpc-whitelist-enabled" = true; "rpc-whitelist" = "10.0.0.*,192.168.15.*,127.0.0.1"; "rpc-host-whitelist-enabled" = true; "rpc-host-whitelist" = "torrent.nicknase27.com"; }; }; age.secrets.wg0 = { file = ../../secrets/wg0.age; path = "/run/secrets/wg0.conf"; }; }