blob: 6a21721729c3446fde03f196d61cc8970cf510f8 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
|
{
config,
lib,
pkgs,
...
}: let
inherit (lib) mkOption types mkIf;
cnf = config.cynerd.openvpn;
in {
options = {
cynerd.openvpn = {
oldpersonal = mkOption {
type = types.bool;
default = false;
description = "My personal old OpenVPN";
};
elektroline = mkOption {
type = types.bool;
default = false;
description = "Elektroline OpenVPN";
};
};
};
config = {
services.openvpn.servers = {
oldpersonal = mkIf cnf.oldpersonal {
config = "config /run/secrets/old.ovpn";
};
elektroline = mkIf cnf.elektroline {
config = "config /run/secrets/elektroline.ovpn";
up = ''
domain=""
dns=()
for optionname in ''${!foreign_option_*} ; do
read -r p1 p2 p3 <<<"''${!optionname}"
[[ "$p1" == "dhcp-option" ]] || continue
case "$p2" in
DNS)
dns+=("$p3")
;;
DOMAIN)
domain="$p3"
;;
esac
done
${pkgs.systemd}/bin/resolvectl dns "$dev" "''${dns[@]}"
${pkgs.systemd}/bin/resolvectl domain "$dev" "~$domain"
'';
};
};
};
}
|