aboutsummaryrefslogtreecommitdiff
path: root/nixos/modules/openvpn.nix
blob: 6a21721729c3446fde03f196d61cc8970cf510f8 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
{
  config,
  lib,
  pkgs,
  ...
}: let
  inherit (lib) mkOption types mkIf;
  cnf = config.cynerd.openvpn;
in {
  options = {
    cynerd.openvpn = {
      oldpersonal = mkOption {
        type = types.bool;
        default = false;
        description = "My personal old OpenVPN";
      };
      elektroline = mkOption {
        type = types.bool;
        default = false;
        description = "Elektroline OpenVPN";
      };
    };
  };

  config = {
    services.openvpn.servers = {
      oldpersonal = mkIf cnf.oldpersonal {
        config = "config /run/secrets/old.ovpn";
      };
      elektroline = mkIf cnf.elektroline {
        config = "config /run/secrets/elektroline.ovpn";
        up = ''
          domain=""
          dns=()
          for optionname in ''${!foreign_option_*} ; do
            read -r p1 p2 p3 <<<"''${!optionname}"
            [[ "$p1" == "dhcp-option" ]] || continue
            case "$p2" in
              DNS)
                dns+=("$p3")
                ;;
              DOMAIN)
                domain="$p3"
                ;;
            esac
          done
          ${pkgs.systemd}/bin/resolvectl dns "$dev" "''${dns[@]}"
          ${pkgs.systemd}/bin/resolvectl domain "$dev" "~$domain"
        '';
      };
    };
  };
}