2022-12-13 03:45:49 +00:00
|
|
|
# to add a new OVPN VPN:
|
|
|
|
# - generate a privkey `wg genkey`
|
|
|
|
# - add this key to `sops secrets/universal.yaml`
|
2024-01-16 03:20:40 +00:00
|
|
|
# - upload pubkey to OVPN.com (`cat wg.priv | wg pubkey`)
|
2022-12-13 03:45:49 +00:00
|
|
|
# - generate config @ OVPN.com
|
|
|
|
# - copy the Address, PublicKey, Endpoint from OVPN's config
|
2024-01-21 00:49:34 +00:00
|
|
|
|
|
|
|
{ config, lib, pkgs, ... }:
|
2022-12-13 03:17:27 +00:00
|
|
|
let
|
2024-01-21 00:49:34 +00:00
|
|
|
def-ovpn = name: { endpoint, publicKey, addrV4, id }: {
|
|
|
|
sane.vpn."ovpnd-${name}" = {
|
|
|
|
inherit endpoint publicKey addrV4 id;
|
|
|
|
privateKeyFile = config.sops.secrets."wg/ovpnd_${name}_privkey".path;
|
|
|
|
dns = [
|
|
|
|
"46.227.67.134"
|
|
|
|
"192.165.9.158"
|
2024-01-16 03:20:40 +00:00
|
|
|
];
|
2024-01-19 09:54:01 +00:00
|
|
|
};
|
|
|
|
|
2024-01-16 03:20:40 +00:00
|
|
|
sops.secrets."wg/ovpnd_${name}_privkey" = {
|
|
|
|
# needs to be readable by systemd-network or else it says "Ignoring network device" and doesn't expose it to networkctl.
|
|
|
|
owner = "systemd-network";
|
|
|
|
};
|
2023-09-19 15:29:47 +00:00
|
|
|
};
|
2022-12-13 03:45:49 +00:00
|
|
|
in lib.mkMerge [
|
|
|
|
(def-ovpn "us" {
|
2022-12-13 03:17:27 +00:00
|
|
|
endpoint = "vpn31.prd.losangeles.ovpn.com:9929";
|
|
|
|
publicKey = "VW6bEWMOlOneta1bf6YFE25N/oMGh1E1UFBCfyggd0k=";
|
2024-01-19 09:54:01 +00:00
|
|
|
id = 1;
|
|
|
|
addrV4 = "172.27.237.218";
|
|
|
|
# addrV6 = "fd00:0000:1337:cafe:1111:1111:ab00:4c8f";
|
2022-12-13 03:45:49 +00:00
|
|
|
})
|
2024-01-19 09:54:01 +00:00
|
|
|
# TODO: us-atl disabled until i can give it a different link-local address and wireguard key than us-mi
|
|
|
|
# (def-ovpn "us-atl" {
|
|
|
|
# endpoint = "vpn18.prd.atlanta.ovpn.com:9929";
|
|
|
|
# publicKey = "Dpg/4v5s9u0YbrXukfrMpkA+XQqKIFpf8ZFgyw0IkE0=";
|
|
|
|
# address = [
|
|
|
|
# "172.21.182.178/32"
|
|
|
|
# "fd00:0000:1337:cafe:1111:1111:cfcb:27e3/128"
|
|
|
|
# ];
|
|
|
|
# })
|
2022-12-13 04:26:00 +00:00
|
|
|
(def-ovpn "us-mi" {
|
|
|
|
endpoint = "vpn34.prd.miami.ovpn.com:9929";
|
|
|
|
publicKey = "VtJz2irbu8mdkIQvzlsYhU+k9d55or9mx4A2a14t0V0=";
|
2024-01-19 09:54:01 +00:00
|
|
|
id = 2;
|
|
|
|
addrV4 = "172.21.182.178";
|
|
|
|
# addrV6 = "fd00:0000:1337:cafe:1111:1111:cfcb:27e3";
|
2022-12-13 04:26:00 +00:00
|
|
|
})
|
2022-12-13 03:45:49 +00:00
|
|
|
(def-ovpn "ukr" {
|
2022-12-13 03:17:27 +00:00
|
|
|
endpoint = "vpn96.prd.kyiv.ovpn.com:9929";
|
|
|
|
publicKey = "CjZcXDxaaKpW8b5As1EcNbI6+42A6BjWahwXDCwfVFg=";
|
2024-01-19 09:54:01 +00:00
|
|
|
id = 3;
|
|
|
|
addrV4 = "172.18.180.159";
|
|
|
|
# addrV6 = "fd00:0000:1337:cafe:1111:1111:ec5c:add3";
|
2022-12-13 03:45:49 +00:00
|
|
|
})
|
|
|
|
]
|