forked from NixOS/nixpkgs
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
nixos/scion: init scion-ip-gateway module
- Loading branch information
1 parent
828ce9b
commit 6c527bf
Showing
3 changed files
with
94 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
92 changes: 92 additions & 0 deletions
92
nixos/modules/services/networking/scion/scion-ip-gateway.nix
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,92 @@ | ||
{ | ||
config, | ||
lib, | ||
pkgs, | ||
... | ||
}: | ||
|
||
with lib; | ||
|
||
let | ||
globalCfg = config.services.scion; | ||
cfg = config.services.scion.scion-ip-gateway; | ||
toml = pkgs.formats.toml { }; | ||
json = pkgs.formats.json { }; | ||
connectionDir = if globalCfg.stateless then "/run" else "/var/lib"; | ||
defaultConfig = { | ||
tunnel = { }; | ||
gateway = { | ||
traffic_policy_file = "${trafficConfigFile}"; | ||
}; | ||
}; | ||
defaultTrafficConfig = { | ||
ASes = { }; | ||
ConfigVersion = 9001; | ||
}; | ||
configFile = toml.generate "scion-ip-gateway.toml" (recursiveUpdate defaultConfig cfg.config); | ||
trafficConfigFile = json.generate "scion-ip-gateway-traffic.json" ( | ||
recursiveUpdate defaultTrafficConfig cfg.trafficConfig | ||
); | ||
in | ||
{ | ||
options.services.scion.scion-ip-gateway = { | ||
enable = mkEnableOption "the scion-ip-gateway service"; | ||
config = mkOption { | ||
default = { }; | ||
type = toml.type; | ||
example = literalExpression '' | ||
{ | ||
tunnel = { | ||
src_ipv4 = "172.16.100.1"; | ||
}; | ||
} | ||
''; | ||
description = '' | ||
scion-ip-gateway daemon configuration | ||
''; | ||
}; | ||
trafficConfig = mkOption { | ||
default = { }; | ||
type = json.type; | ||
example = literalExpression '' | ||
{ | ||
ASes = { | ||
"2-ffaa:0:b" = { | ||
Nets = [ | ||
"172.16.1.0/24" | ||
]; | ||
}; | ||
}; | ||
ConfigVersion = 9001; | ||
} | ||
''; | ||
description = '' | ||
scion-ip-gateway traffic configuration | ||
''; | ||
}; | ||
}; | ||
config = mkIf cfg.enable { | ||
systemd.services.scion-ip-gateway = { | ||
description = "SCION IP Gateway Service"; | ||
after = [ | ||
"network-online.target" | ||
"scion-dispatcher.service" | ||
]; | ||
wants = [ | ||
"network-online.target" | ||
"scion-dispatcher.service" | ||
]; | ||
wantedBy = [ "multi-user.target" ]; | ||
serviceConfig = { | ||
Type = "simple"; | ||
Group = if (config.services.scion.scion-dispatcher.enable == true) then "scion" else null; | ||
ExecStart = "${globalCfg.package}/bin/scion-ip-gateway --config ${configFile}"; | ||
DynamicUser = true; | ||
AmbientCapabilities = [ "CAP_NET_ADMIN" ]; | ||
Restart = "on-failure"; | ||
KillMode = "control-group"; | ||
RemainAfterExit = false; | ||
}; | ||
}; | ||
}; | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters