diff options
| author | seth <[email protected]> | 2023-12-13 15:13:33 -0500 |
|---|---|---|
| committer | seth <[email protected]> | 2023-12-13 15:15:01 -0500 |
| commit | 109114703b42ba17c8f2a4a347bd4a9ecd1e82d5 (patch) | |
| tree | f7da6b640fbab2a5016d0a62a4a58060e2acf292 /tofu/tailscale/acl.nix | |
| parent | 163daad93da692fc280036b80f29ca9b65c005d4 (diff) | |
tofu: use imported resources
Diffstat (limited to 'tofu/tailscale/acl.nix')
| -rw-r--r-- | tofu/tailscale/acl.nix | 42 |
1 files changed, 20 insertions, 22 deletions
diff --git a/tofu/tailscale/acl.nix b/tofu/tailscale/acl.nix index 46503d8..d27d3e1 100644 --- a/tofu/tailscale/acl.nix +++ b/tofu/tailscale/acl.nix @@ -1,27 +1,25 @@ {lib, ...}: { - resource = { - tailscale_acl.main = { - acl = toString (builtins.toJSON { - tagOwners = let - me = ["getchoo@github"]; - tags = map (name: "tag:${name}") ["server" "personal" "gha"]; - in - lib.genAttrs tags (_: me); + resource.tailscale_acl.default = { + acl = toString (builtins.toJSON { + tagOwners = let + me = ["getchoo@github"]; + tags = map (name: "tag:${name}") ["server" "personal" "gha"]; + in + lib.genAttrs tags (_: me); - acls = let - mkAcl = action: src: dst: {inherit action src dst;}; - in [ - (mkAcl "accept" ["tag:personal"] ["*:*"]) - (mkAcl "accept" ["tag:server" "tag:gha"] ["tag:server:*"]) - ]; + acls = let + mkAcl = action: src: dst: {inherit action src dst;}; + in [ + (mkAcl "accept" ["tag:personal"] ["*:*"]) + (mkAcl "accept" ["tag:server" "tag:gha"] ["tag:server:*"]) + ]; - ssh = let - mkSshAcl = action: src: dst: users: {inherit action src dst users;}; - in [ - (mkSshAcl "accept" ["tag:personal"] ["tag:server" "tag:personal"] ["autogroup:nonroot" "root"]) - (mkSshAcl "accept" ["tag:gha"] ["tag:server"] ["root"]) - ]; - }); - }; + ssh = let + mkSshAcl = action: src: dst: users: {inherit action src dst users;}; + in [ + (mkSshAcl "accept" ["tag:personal"] ["tag:server" "tag:personal"] ["autogroup:nonroot" "root"]) + (mkSshAcl "accept" ["tag:gha"] ["tag:server"] ["root"]) + ]; + }); }; } |
