From b896a064f4f34f8f102d4556a3bc342c66c09288 Mon Sep 17 00:00:00 2001 From: jimjam4real Date: Mon, 23 Sep 2024 14:16:30 -0400 Subject: [PATCH] Final touchups --- system/pinebook.nix | 9 ++++++--- system/server/firewall.nix | 2 +- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/system/pinebook.nix b/system/pinebook.nix index c321732..3632aac 100644 --- a/system/pinebook.nix +++ b/system/pinebook.nix @@ -1,4 +1,6 @@ -{ lib, ...}: { +{ lib, ...}: let + ips = import ./modules/ips.nix; +in { imports = [ # Base configs ./base.nix @@ -7,7 +9,7 @@ ./users/jimbo.nix ./users/groups.nix - # Desktop only + # Desktop ./desktop/misc.nix ./desktop/sway.nix ./desktop/greetd-sway.nix @@ -17,8 +19,9 @@ ./desktop/firewall.nix ./desktop/fonts.nix ./desktop/qt.nix + ./desktop/wireguard.nix - # Laptop/Portable only + # Laptop/Portable ./hardware/wireless.nix # Modules diff --git a/system/server/firewall.nix b/system/server/firewall.nix index 18aad42..1b3ecae 100644 --- a/system/server/firewall.nix +++ b/system/server/firewall.nix @@ -12,7 +12,7 @@ # Add extra input rules using nftables extraInputRules = '' - ip saddr ${ips.localSpan}.0/24 tcp dport 2049 accept comment "Accept NFS" + ip saddr { ${ips.localSpan}.0/24, ${ips.wgSpan}.0/24 } tcp dport 2049 accept comment "Accept NFS" ip saddr { ${ips.pc}, ${outputs.secrets.lunaIP}, ${outputs.secrets.cornIP}, ${outputs.secrets.vertIP} } tcp dport { 1935, 1945 } accept comment "Accept RTMP" ip saddr ${ips.wgSpan}.3 tcp dport ${mailPorts} accept comment "Accept mail" '';