2022-12-28 21:21:41 +00:00
|
|
|
{
|
|
|
|
config,
|
|
|
|
lib,
|
|
|
|
pkgs,
|
|
|
|
...
|
2024-10-09 16:51:18 +00:00
|
|
|
}: let
|
2022-02-10 20:34:41 +00:00
|
|
|
cfg = config.services.headscale;
|
|
|
|
|
|
|
|
dataDir = "/var/lib/headscale";
|
|
|
|
runDir = "/run/headscale";
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
cliConfig = {
|
|
|
|
# Turn off update checks since the origin of our package
|
|
|
|
# is nixpkgs and not Github.
|
|
|
|
disable_check_updates = true;
|
|
|
|
|
|
|
|
unix_socket = "${runDir}/headscale.sock";
|
|
|
|
};
|
|
|
|
|
2022-12-28 21:21:41 +00:00
|
|
|
settingsFormat = pkgs.formats.yaml {};
|
2022-02-10 20:34:41 +00:00
|
|
|
configFile = settingsFormat.generate "headscale.yaml" cfg.settings;
|
2024-10-09 16:51:18 +00:00
|
|
|
cliConfigFile = settingsFormat.generate "headscale.yaml" cliConfig;
|
2022-12-28 21:21:41 +00:00
|
|
|
in {
|
2022-02-10 20:34:41 +00:00
|
|
|
options = {
|
|
|
|
services.headscale = {
|
2024-10-09 16:51:18 +00:00
|
|
|
enable = lib.mkEnableOption "headscale, Open Source coordination server for Tailscale";
|
2022-02-10 20:34:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
package = lib.mkPackageOption pkgs "headscale" {};
|
2022-02-10 20:34:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
user = lib.mkOption {
|
2022-02-10 20:34:41 +00:00
|
|
|
default = "headscale";
|
2024-10-09 16:51:18 +00:00
|
|
|
type = lib.types.str;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-02-10 20:34:41 +00:00
|
|
|
User account under which headscale runs.
|
2022-09-09 14:08:57 +00:00
|
|
|
|
|
|
|
::: {.note}
|
2022-02-10 20:34:41 +00:00
|
|
|
If left as the default value this user will automatically be created
|
|
|
|
on system activation, otherwise you are responsible for
|
|
|
|
ensuring the user exists before the headscale service starts.
|
2022-09-09 14:08:57 +00:00
|
|
|
:::
|
2022-02-10 20:34:41 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
group = lib.mkOption {
|
2022-02-10 20:34:41 +00:00
|
|
|
default = "headscale";
|
2024-10-09 16:51:18 +00:00
|
|
|
type = lib.types.str;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-02-10 20:34:41 +00:00
|
|
|
Group under which headscale runs.
|
2022-09-09 14:08:57 +00:00
|
|
|
|
|
|
|
::: {.note}
|
2022-02-10 20:34:41 +00:00
|
|
|
If left as the default value this group will automatically be created
|
|
|
|
on system activation, otherwise you are responsible for
|
|
|
|
ensuring the user exists before the headscale service starts.
|
2022-09-09 14:08:57 +00:00
|
|
|
:::
|
2022-02-10 20:34:41 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
address = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
2022-02-10 20:34:41 +00:00
|
|
|
default = "127.0.0.1";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-02-10 20:34:41 +00:00
|
|
|
Listening address of headscale.
|
|
|
|
'';
|
|
|
|
example = "0.0.0.0";
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
port = lib.mkOption {
|
|
|
|
type = lib.types.port;
|
2022-02-10 20:34:41 +00:00
|
|
|
default = 8080;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-02-10 20:34:41 +00:00
|
|
|
Listening port of headscale.
|
|
|
|
'';
|
|
|
|
example = 443;
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
settings = lib.mkOption {
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-08-12 12:06:08 +00:00
|
|
|
Overrides to {file}`config.yaml` as a Nix attribute set.
|
|
|
|
Check the [example config](https://github.com/juanfont/headscale/blob/main/config-example.yaml)
|
2022-02-10 20:34:41 +00:00
|
|
|
for possible options.
|
|
|
|
'';
|
2024-10-09 16:51:18 +00:00
|
|
|
type = lib.types.submodule {
|
2022-12-28 21:21:41 +00:00
|
|
|
freeformType = settingsFormat.type;
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
imports = with lib; [
|
|
|
|
(mkAliasOptionModule ["acl_policy_path"] ["policy" "path"])
|
|
|
|
(mkAliasOptionModule ["db_host"] ["database" "postgres" "host"])
|
|
|
|
(mkAliasOptionModule ["db_name"] ["database" "postgres" "name"])
|
|
|
|
(mkAliasOptionModule ["db_password_file"] ["database" "postgres" "password_file"])
|
|
|
|
(mkAliasOptionModule ["db_path"] ["database" "sqlite" "path"])
|
|
|
|
(mkAliasOptionModule ["db_port"] ["database" "postgres" "port"])
|
|
|
|
(mkAliasOptionModule ["db_type"] ["database" "type"])
|
|
|
|
(mkAliasOptionModule ["db_user"] ["database" "postgres" "user"])
|
|
|
|
(mkAliasOptionModule ["dns_config" "base_domain"] ["dns" "base_domain"])
|
|
|
|
(mkAliasOptionModule ["dns_config" "domains"] ["dns" "search_domains"])
|
|
|
|
(mkAliasOptionModule ["dns_config" "magic_dns"] ["dns" "magic_dns"])
|
|
|
|
(mkAliasOptionModule ["dns_config" "nameservers"] ["dns" "nameservers" "global"])
|
|
|
|
];
|
|
|
|
|
2022-12-28 21:21:41 +00:00
|
|
|
options = {
|
2024-10-09 16:51:18 +00:00
|
|
|
server_url = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = "http://127.0.0.1:8080";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
The url clients will connect to.
|
|
|
|
'';
|
|
|
|
example = "https://myheadscale.example.com:443";
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
noise.private_key_path = lib.mkOption {
|
|
|
|
type = lib.types.path;
|
|
|
|
default = "${dataDir}/noise_private.key";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2024-10-09 16:51:18 +00:00
|
|
|
Path to noise private key file, generated automatically if it does not exist.
|
2022-12-28 21:21:41 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
prefixes = let
|
|
|
|
prefDesc = ''
|
|
|
|
Each prefix consists of either an IPv4 or IPv6 address,
|
|
|
|
and the associated prefix length, delimited by a slash.
|
|
|
|
It must be within IP ranges supported by the Tailscale
|
|
|
|
client - i.e., subnets of 100.64.0.0/10 and fd7a:115c:a1e0::/48.
|
2022-12-28 21:21:41 +00:00
|
|
|
'';
|
2024-10-09 16:51:18 +00:00
|
|
|
in {
|
|
|
|
v4 = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
|
|
|
default = "100.64.0.0/10";
|
|
|
|
description = prefDesc;
|
|
|
|
};
|
|
|
|
|
|
|
|
v6 = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
|
|
|
default = "fd7a:115c:a1e0::/48";
|
|
|
|
description = prefDesc;
|
|
|
|
};
|
|
|
|
|
|
|
|
allocation = lib.mkOption {
|
|
|
|
type = lib.types.enum ["sequential" "random"];
|
|
|
|
example = "random";
|
|
|
|
default = "sequential";
|
|
|
|
description = ''
|
|
|
|
Strategy used for allocation of IPs to nodes, available options:
|
|
|
|
- sequential (default): assigns the next free IP from the previous given IP.
|
|
|
|
- random: assigns the next free IP from a pseudo-random IP generator (crypto/rand).
|
|
|
|
'';
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
derp = {
|
2024-10-09 16:51:18 +00:00
|
|
|
urls = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = ["https://controlplane.tailscale.com/derpmap/default"];
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
List of urls containing DERP maps.
|
|
|
|
See [How Tailscale works](https://tailscale.com/blog/how-tailscale-works/) for more information on DERP maps.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
paths = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.path;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = [];
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
List of file paths containing DERP maps.
|
|
|
|
See [How Tailscale works](https://tailscale.com/blog/how-tailscale-works/) for more information on DERP maps.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
auto_update_enable = lib.mkOption {
|
|
|
|
type = lib.types.bool;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = true;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Whether to automatically update DERP maps on a set frequency.
|
|
|
|
'';
|
|
|
|
example = false;
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
update_frequency = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = "24h";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Frequency to update DERP maps.
|
|
|
|
'';
|
|
|
|
example = "5m";
|
|
|
|
};
|
2024-10-09 16:51:18 +00:00
|
|
|
|
|
|
|
server.private_key_path = lib.mkOption {
|
|
|
|
type = lib.types.path;
|
|
|
|
default = "${dataDir}/derp_server_private.key";
|
|
|
|
description = ''
|
|
|
|
Path to derp private key file, generated automatically if it does not exist.
|
|
|
|
'';
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
ephemeral_node_inactivity_timeout = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = "30m";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Time before an inactive ephemeral node is deleted.
|
|
|
|
'';
|
|
|
|
example = "5m";
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
database = {
|
|
|
|
type = lib.mkOption {
|
|
|
|
type = lib.types.enum ["sqlite" "sqlite3" "postgres"];
|
|
|
|
example = "postgres";
|
|
|
|
default = "sqlite";
|
|
|
|
description = ''
|
|
|
|
Database engine to use.
|
|
|
|
Please note that using Postgres is highly discouraged as it is only supported for legacy reasons.
|
|
|
|
All new development, testing and optimisations are done with SQLite in mind.
|
|
|
|
'';
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
sqlite = {
|
|
|
|
path = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.str;
|
|
|
|
default = "${dataDir}/db.sqlite";
|
|
|
|
description = "Path to the sqlite3 database file.";
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
write_ahead_log = lib.mkOption {
|
|
|
|
type = lib.types.bool;
|
|
|
|
default = true;
|
|
|
|
description = ''
|
|
|
|
Enable WAL mode for SQLite. This is recommended for production environments.
|
|
|
|
https://www.sqlite.org/wal.html
|
|
|
|
'';
|
|
|
|
example = true;
|
|
|
|
};
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
postgres = {
|
|
|
|
host = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.str;
|
|
|
|
default = null;
|
|
|
|
example = "127.0.0.1";
|
|
|
|
description = "Database host address.";
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
port = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.port;
|
|
|
|
default = null;
|
|
|
|
example = 3306;
|
|
|
|
description = "Database host port.";
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
name = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.str;
|
|
|
|
default = null;
|
|
|
|
example = "headscale";
|
|
|
|
description = "Database name.";
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
user = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.str;
|
|
|
|
default = null;
|
|
|
|
example = "headscale";
|
|
|
|
description = "Database user.";
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
password_file = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.path;
|
|
|
|
default = null;
|
|
|
|
example = "/run/keys/headscale-dbpassword";
|
|
|
|
description = ''
|
|
|
|
A file containing the password corresponding to
|
|
|
|
{option}`database.user`.
|
|
|
|
'';
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
2024-10-09 16:51:18 +00:00
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
log = {
|
|
|
|
level = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
|
|
|
default = "info";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2024-10-09 16:51:18 +00:00
|
|
|
headscale log level.
|
2022-12-28 21:21:41 +00:00
|
|
|
'';
|
2024-10-09 16:51:18 +00:00
|
|
|
example = "debug";
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
format = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
|
|
|
default = "text";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2024-10-09 16:51:18 +00:00
|
|
|
headscale log format.
|
2022-12-28 21:21:41 +00:00
|
|
|
'';
|
2024-10-09 16:51:18 +00:00
|
|
|
example = "json";
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
2024-10-09 16:51:18 +00:00
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
dns = {
|
|
|
|
magic_dns = lib.mkOption {
|
|
|
|
type = lib.types.bool;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = true;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Whether to use [MagicDNS](https://tailscale.com/kb/1081/magicdns/).
|
|
|
|
Only works if there is at least a nameserver defined.
|
|
|
|
'';
|
|
|
|
example = false;
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
base_domain = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = "";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Defines the base domain to create the hostnames for MagicDNS.
|
|
|
|
{option}`baseDomain` must be a FQDNs, without the trailing dot.
|
|
|
|
The FQDN of the hosts will be
|
|
|
|
`hostname.namespace.base_domain` (e.g.
|
|
|
|
`myhost.mynamespace.example.com`).
|
|
|
|
'';
|
|
|
|
};
|
2024-10-09 16:51:18 +00:00
|
|
|
|
|
|
|
nameservers = {
|
|
|
|
global = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.str;
|
|
|
|
default = [];
|
|
|
|
description = ''
|
|
|
|
List of nameservers to pass to Tailscale clients.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
search_domains = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.str;
|
|
|
|
default = [];
|
|
|
|
description = ''
|
|
|
|
Search domains to inject to Tailscale clients.
|
|
|
|
'';
|
|
|
|
example = ["mydomain.internal"];
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
oidc = {
|
2024-10-09 16:51:18 +00:00
|
|
|
issuer = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = "";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
URL to OpenID issuer.
|
|
|
|
'';
|
|
|
|
example = "https://openid.example.com";
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
client_id = lib.mkOption {
|
|
|
|
type = lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = "";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
OpenID Connect client ID.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
client_secret_path = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = null;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2023-03-24 00:07:29 +00:00
|
|
|
Path to OpenID Connect client secret file. Expands environment variables in format ''${VAR}.
|
2022-12-28 21:21:41 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
scope = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.str;
|
2023-03-04 12:14:45 +00:00
|
|
|
default = ["openid" "profile" "email"];
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2023-03-04 12:14:45 +00:00
|
|
|
Scopes used in the OIDC flow.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
extra_params = lib.mkOption {
|
|
|
|
type = lib.types.attrsOf lib.types.str;
|
|
|
|
default = {};
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2023-03-04 12:14:45 +00:00
|
|
|
Custom query parameters to send with the Authorize Endpoint request.
|
2022-12-28 21:21:41 +00:00
|
|
|
'';
|
|
|
|
example = {
|
2023-03-04 12:14:45 +00:00
|
|
|
domain_hint = "example.com";
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
|
|
|
};
|
2023-03-04 12:14:45 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
allowed_domains = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.str;
|
|
|
|
default = [];
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2023-03-04 12:14:45 +00:00
|
|
|
Allowed principal domains. if an authenticated user's domain
|
|
|
|
is not in this list authentication request will be rejected.
|
|
|
|
'';
|
2024-10-09 16:51:18 +00:00
|
|
|
example = ["example.com"];
|
2023-03-04 12:14:45 +00:00
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
allowed_users = lib.mkOption {
|
|
|
|
type = lib.types.listOf lib.types.str;
|
|
|
|
default = [];
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2023-03-04 12:14:45 +00:00
|
|
|
Users allowed to authenticate even if not in allowedDomains.
|
|
|
|
'';
|
2024-10-09 16:51:18 +00:00
|
|
|
example = ["alice@example.com"];
|
2023-03-04 12:14:45 +00:00
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
strip_email_domain = lib.mkOption {
|
|
|
|
type = lib.types.bool;
|
2023-03-04 12:14:45 +00:00
|
|
|
default = true;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2023-03-04 12:14:45 +00:00
|
|
|
Whether the domain part of the email address should be removed when generating namespaces.
|
|
|
|
'';
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
tls_letsencrypt_hostname = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = "";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Domain name to request a TLS certificate for.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
tls_letsencrypt_challenge_type = lib.mkOption {
|
|
|
|
type = lib.types.enum ["TLS-ALPN-01" "HTTP-01"];
|
2022-12-28 21:21:41 +00:00
|
|
|
default = "HTTP-01";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Type of ACME challenge to use, currently supported types:
|
|
|
|
`HTTP-01` or `TLS-ALPN-01`.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
tls_letsencrypt_listen = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.str;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = ":http";
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
When HTTP-01 challenge is chosen, letsencrypt must set up a
|
|
|
|
verification endpoint, and it will be listening on:
|
|
|
|
`:http = port 80`.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
tls_cert_path = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.path;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = null;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Path to already created certificate.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
tls_key_path = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.path;
|
2022-12-28 21:21:41 +00:00
|
|
|
default = null;
|
2024-04-21 15:54:59 +00:00
|
|
|
description = ''
|
2022-12-28 21:21:41 +00:00
|
|
|
Path to key for already created certificate.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
policy = {
|
|
|
|
mode = lib.mkOption {
|
|
|
|
type = lib.types.enum ["file" "database"];
|
|
|
|
default = "file";
|
|
|
|
description = ''
|
|
|
|
The mode can be "file" or "database" that defines
|
|
|
|
where the ACL policies are stored and read from.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
path = lib.mkOption {
|
|
|
|
type = lib.types.nullOr lib.types.path;
|
|
|
|
default = null;
|
|
|
|
description = ''
|
|
|
|
If the mode is set to "file", the path to a
|
|
|
|
HuJSON file containing ACL policies.
|
|
|
|
'';
|
|
|
|
};
|
2022-12-28 21:21:41 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
2022-02-10 20:34:41 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
imports = with lib; [
|
2022-12-28 21:21:41 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "derp" "autoUpdate"] ["services" "headscale" "settings" "derp" "auto_update_enable"])
|
2024-10-09 16:51:18 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "derp" "paths"] ["services" "headscale" "settings" "derp" "paths"])
|
2022-12-28 21:21:41 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "derp" "updateFrequency"] ["services" "headscale" "settings" "derp" "update_frequency"])
|
2024-10-09 16:51:18 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "derp" "urls"] ["services" "headscale" "settings" "derp" "urls"])
|
2022-12-28 21:21:41 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "ephemeralNodeInactivityTimeout"] ["services" "headscale" "settings" "ephemeral_node_inactivity_timeout"])
|
|
|
|
(mkRenamedOptionModule ["services" "headscale" "logLevel"] ["services" "headscale" "settings" "log" "level"])
|
|
|
|
(mkRenamedOptionModule ["services" "headscale" "openIdConnect" "clientId"] ["services" "headscale" "settings" "oidc" "client_id"])
|
2023-03-24 00:07:29 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "openIdConnect" "clientSecretFile"] ["services" "headscale" "settings" "oidc" "client_secret_path"])
|
2024-10-09 16:51:18 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "openIdConnect" "issuer"] ["services" "headscale" "settings" "oidc" "issuer"])
|
|
|
|
(mkRenamedOptionModule ["services" "headscale" "serverUrl"] ["services" "headscale" "settings" "server_url"])
|
2022-12-28 21:21:41 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "tls" "certFile"] ["services" "headscale" "settings" "tls_cert_path"])
|
|
|
|
(mkRenamedOptionModule ["services" "headscale" "tls" "keyFile"] ["services" "headscale" "settings" "tls_key_path"])
|
2024-10-09 16:51:18 +00:00
|
|
|
(mkRenamedOptionModule ["services" "headscale" "tls" "letsencrypt" "challengeType"] ["services" "headscale" "settings" "tls_letsencrypt_challenge_type"])
|
|
|
|
(mkRenamedOptionModule ["services" "headscale" "tls" "letsencrypt" "hostname"] ["services" "headscale" "settings" "tls_letsencrypt_hostname"])
|
|
|
|
(mkRenamedOptionModule ["services" "headscale" "tls" "letsencrypt" "httpListen"] ["services" "headscale" "settings" "tls_letsencrypt_listen"])
|
2023-03-04 12:14:45 +00:00
|
|
|
|
|
|
|
(mkRemovedOptionModule ["services" "headscale" "openIdConnect" "domainMap"] ''
|
|
|
|
Headscale no longer uses domain_map. If you're using an old version of headscale you can still set this option via services.headscale.settings.oidc.domain_map.
|
|
|
|
'')
|
2022-12-28 21:21:41 +00:00
|
|
|
];
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
config = lib.mkIf cfg.enable {
|
|
|
|
services.headscale.settings = lib.mkMerge [
|
|
|
|
cliConfig
|
|
|
|
{
|
|
|
|
listen_addr = lib.mkDefault "${cfg.address}:${toString cfg.port}";
|
2022-02-10 20:34:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
tls_letsencrypt_cache_dir = "${dataDir}/.cache";
|
|
|
|
}
|
|
|
|
];
|
2022-02-10 20:34:41 +00:00
|
|
|
|
2024-02-07 01:22:34 +00:00
|
|
|
environment = {
|
2024-10-09 16:51:18 +00:00
|
|
|
# Headscale CLI needs a minimal config to be able to locate the unix socket
|
|
|
|
# to talk to the server instance.
|
|
|
|
etc."headscale/config.yaml".source = cliConfigFile;
|
2024-02-07 01:22:34 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
systemPackages = [cfg.package];
|
2024-02-07 01:22:34 +00:00
|
|
|
};
|
2022-02-10 20:34:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
users.groups.headscale = lib.mkIf (cfg.group == "headscale") {};
|
2022-02-10 20:34:41 +00:00
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
users.users.headscale = lib.mkIf (cfg.user == "headscale") {
|
2022-02-10 20:34:41 +00:00
|
|
|
description = "headscale user";
|
|
|
|
home = dataDir;
|
|
|
|
group = cfg.group;
|
|
|
|
isSystemUser = true;
|
|
|
|
};
|
|
|
|
|
|
|
|
systemd.services.headscale = {
|
|
|
|
description = "headscale coordination server for Tailscale";
|
2024-10-09 16:51:18 +00:00
|
|
|
wants = ["network-online.target"];
|
2022-12-28 21:21:41 +00:00
|
|
|
after = ["network-online.target"];
|
|
|
|
wantedBy = ["multi-user.target"];
|
2022-08-12 12:06:08 +00:00
|
|
|
|
2022-02-10 20:34:41 +00:00
|
|
|
script = ''
|
2024-10-09 16:51:18 +00:00
|
|
|
${lib.optionalString (cfg.settings.database.postgres.password_file != null) ''
|
|
|
|
export HEADSCALE_DATABASE_POSTGRES_PASS="$(head -n1 ${lib.escapeShellArg cfg.settings.database.postgres.password_file})"
|
2022-02-10 20:34:41 +00:00
|
|
|
''}
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
exec ${lib.getExe cfg.package} serve --config ${configFile}
|
2022-02-10 20:34:41 +00:00
|
|
|
'';
|
|
|
|
|
2022-12-28 21:21:41 +00:00
|
|
|
serviceConfig = let
|
2024-10-09 16:51:18 +00:00
|
|
|
capabilityBoundingSet = ["CAP_CHOWN"] ++ lib.optional (cfg.port < 1024) "CAP_NET_BIND_SERVICE";
|
2022-12-28 21:21:41 +00:00
|
|
|
in {
|
|
|
|
Restart = "always";
|
|
|
|
Type = "simple";
|
|
|
|
User = cfg.user;
|
|
|
|
Group = cfg.group;
|
|
|
|
|
|
|
|
# Hardening options
|
|
|
|
RuntimeDirectory = "headscale";
|
|
|
|
# Allow headscale group access so users can be added and use the CLI.
|
|
|
|
RuntimeDirectoryMode = "0750";
|
|
|
|
|
|
|
|
StateDirectory = "headscale";
|
|
|
|
StateDirectoryMode = "0750";
|
|
|
|
|
|
|
|
ProtectSystem = "strict";
|
|
|
|
ProtectHome = true;
|
|
|
|
PrivateTmp = true;
|
|
|
|
PrivateDevices = true;
|
|
|
|
ProtectKernelTunables = true;
|
|
|
|
ProtectControlGroups = true;
|
|
|
|
RestrictSUIDSGID = true;
|
|
|
|
PrivateMounts = true;
|
|
|
|
ProtectKernelModules = true;
|
|
|
|
ProtectKernelLogs = true;
|
|
|
|
ProtectHostname = true;
|
|
|
|
ProtectClock = true;
|
|
|
|
ProtectProc = "invisible";
|
|
|
|
ProcSubset = "pid";
|
|
|
|
RestrictNamespaces = true;
|
|
|
|
RemoveIPC = true;
|
|
|
|
UMask = "0077";
|
|
|
|
|
|
|
|
CapabilityBoundingSet = capabilityBoundingSet;
|
|
|
|
AmbientCapabilities = capabilityBoundingSet;
|
|
|
|
NoNewPrivileges = true;
|
|
|
|
LockPersonality = true;
|
|
|
|
RestrictRealtime = true;
|
|
|
|
SystemCallFilter = ["@system-service" "~@privileged" "@chown"];
|
|
|
|
SystemCallArchitectures = "native";
|
|
|
|
RestrictAddressFamilies = "AF_INET AF_INET6 AF_UNIX";
|
|
|
|
};
|
2022-02-10 20:34:41 +00:00
|
|
|
};
|
|
|
|
};
|
|
|
|
|
2024-10-09 16:51:18 +00:00
|
|
|
meta.maintainers = with lib.maintainers; [kradalby misterio77];
|
2022-02-10 20:34:41 +00:00
|
|
|
}
|