summaryrefslogtreecommitdiff
path: root/tofu/tailscale
diff options
context:
space:
mode:
authorseth <[email protected]>2023-12-13 15:13:33 -0500
committerseth <[email protected]>2023-12-13 15:15:01 -0500
commit109114703b42ba17c8f2a4a347bd4a9ecd1e82d5 (patch)
treef7da6b640fbab2a5016d0a62a4a58060e2acf292 /tofu/tailscale
parent163daad93da692fc280036b80f29ca9b65c005d4 (diff)
tofu: use imported resources
Diffstat (limited to 'tofu/tailscale')
-rw-r--r--tofu/tailscale/acl.nix42
1 files changed, 20 insertions, 22 deletions
diff --git a/tofu/tailscale/acl.nix b/tofu/tailscale/acl.nix
index 46503d8..d27d3e1 100644
--- a/tofu/tailscale/acl.nix
+++ b/tofu/tailscale/acl.nix
@@ -1,27 +1,25 @@
{lib, ...}: {
- resource = {
- tailscale_acl.main = {
- acl = toString (builtins.toJSON {
- tagOwners = let
- me = ["getchoo@github"];
- tags = map (name: "tag:${name}") ["server" "personal" "gha"];
- in
- lib.genAttrs tags (_: me);
+ resource.tailscale_acl.default = {
+ acl = toString (builtins.toJSON {
+ tagOwners = let
+ me = ["getchoo@github"];
+ tags = map (name: "tag:${name}") ["server" "personal" "gha"];
+ in
+ lib.genAttrs tags (_: me);
- acls = let
- mkAcl = action: src: dst: {inherit action src dst;};
- in [
- (mkAcl "accept" ["tag:personal"] ["*:*"])
- (mkAcl "accept" ["tag:server" "tag:gha"] ["tag:server:*"])
- ];
+ acls = let
+ mkAcl = action: src: dst: {inherit action src dst;};
+ in [
+ (mkAcl "accept" ["tag:personal"] ["*:*"])
+ (mkAcl "accept" ["tag:server" "tag:gha"] ["tag:server:*"])
+ ];
- ssh = let
- mkSshAcl = action: src: dst: users: {inherit action src dst users;};
- in [
- (mkSshAcl "accept" ["tag:personal"] ["tag:server" "tag:personal"] ["autogroup:nonroot" "root"])
- (mkSshAcl "accept" ["tag:gha"] ["tag:server"] ["root"])
- ];
- });
- };
+ ssh = let
+ mkSshAcl = action: src: dst: users: {inherit action src dst users;};
+ in [
+ (mkSshAcl "accept" ["tag:personal"] ["tag:server" "tag:personal"] ["autogroup:nonroot" "root"])
+ (mkSshAcl "accept" ["tag:gha"] ["tag:server"] ["root"])
+ ];
+ });
};
}