commit 67135636c2172c70d6ef32e6703e961552dfae34 from: mtmn date: Mon Jul 20 10:51:14 2026 UTC add headscale policies, etc. commit - 8b67385501cc720d0a0b99f9ba857205e748d043 commit + 67135636c2172c70d6ef32e6703e961552dfae34 blob - aa36675e477fc08c61deff55fdf3213935c246b3 blob + db8975a2ff27c2691d0df19542103a5109cdc5fb --- flake.lock +++ flake.lock @@ -164,11 +164,11 @@ ] }, "locked": { - "lastModified": 1784489491, - "narHash": "sha256-j9maqjx1T8+ljAVntAdSI5hSGCm77QNZz64JF1rJNu0=", + "lastModified": 1784546264, + "narHash": "sha256-jxVr5EHMYAOkFvS2k0abIvt6NqyshyWmiHHzV17sT2g=", "owner": "nix-community", "repo": "home-manager", - "rev": "3139deb8cafbe73b39b24451255b2fdd3426077e", + "rev": "e3dea8e4792b09a6c0eb5836b0284ad05b1acba0", "type": "github" }, "original": { @@ -234,11 +234,11 @@ }, "nixpkgs_2": { "locked": { - "lastModified": 1784494590, - "narHash": "sha256-Gn7vGw9aIyoJy7GkNbsHXvSkvXeNLoP9ZiK1RtS/0M8=", + "lastModified": 1784525419, + "narHash": "sha256-yocJ4I4Kd4as0UPMFs9P7laPvvA2x/Bj8EW46iW3VVM=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "472e4428b5aee60be7ac35c03662ebb36c901edd", + "rev": "a16c3fde2ffeab7f6326f50f460aaffde7ae066d", "type": "github" }, "original": { blob - 65721dc8713796a0ec95c46e555f19f57b846bfe blob + 90e1e523ff9499702fd77d3fed84785dd024183c Binary files hosts/nixaran/configuration.nix and hosts/nixaran/configuration.nix differ blob - 9d87cfe56c8801ccb03c1af903a94d0681f539fd blob + b5be95f8eebb125e411775b7938b1c86db773b3a --- hosts/void/overlays/home/nbrc +++ hosts/void/overlays/home/nbrc @@ -1,5 +1,5 @@ #!/usr/bin/env bash -export EDITOR="emacsclient --tty" +export EDITOR="emacsclient" export NB_DEFAULT_EXTENSION="${NB_DEFAULT_EXTENSION:-org}" export NB_SYNTAX_THEME="${NB_SYNTAX_THEME:-base16}" export NB_COLOR_THEME="${NB_COLOR_THEME:-smoke}" blob - 64e1d60e37554f2d0bf9fe329313c0611ede7beb blob + fe99bbb6c7e59568aba78283d1ba7e37223e6829 --- modules/mixins/dotfiles/config/shell/rc/functions +++ modules/mixins/dotfiles/config/shell/rc/functions @@ -150,7 +150,7 @@ ae() { } em() { - emacsclient --tty "${1:-.}" + emacsclient -n "${1:-.}" } cd() { blob - a8082b247839a8f15e66f39fc45f0bd75f6a1b0c blob + c8387f9becffb9227b6246a4e44402bde8861e7b --- modules/services/headscale.nix +++ modules/services/headscale.nix @@ -34,6 +34,21 @@ in { default = []; description = "Extra DNS records to push to all tailnet clients"; }; + aclPolicy = lib.mkOption { + type = lib.types.nullOr (lib.types.attrsOf lib.types.anything); + default = null; + example = lib.literalExpression '' + { + acls = [ + { action = "accept"; src = ["miro@"]; dst = ["*:*"]; } + ]; + } + ''; + description = '' + When set, headscale switches to a file-based policy mode and the + default becomes deny - users are referenced as "@". + ''; + }; derp = { enable = lib.mkEnableOption "embedded DERP relay server"; stunPort = lib.mkOption { @@ -84,9 +99,17 @@ in { private_key_path = "/var/lib/headscale/derp_server_private.key"; automatically_add_embedded_derp_region = true; }; + policy = lib.mkIf (cfg.aclPolicy != null) { + mode = "file"; + path = "/etc/headscale/policy.hujson"; + }; }; }; + environment.etc."headscale/policy.hujson" = lib.mkIf (cfg.aclPolicy != null) { + text = builtins.toJSON cfg.aclPolicy; + }; + networking.firewall.allowedUDPPorts = lib.mkIf cfg.derp.enable [cfg.derp.stunPort]; services.caddy.virtualHosts."${cfg.domain}" = {