From 5f848623dff7cbcd21911032e5fd4c77bcf7d413 Mon Sep 17 00:00:00 2001 From: seth Date: Sun, 4 Feb 2024 16:40:38 -0500 Subject: tree-wide: better separate/name some things --- ext/terranix/tailscale/acl.nix | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 ext/terranix/tailscale/acl.nix (limited to 'ext/terranix/tailscale/acl.nix') diff --git a/ext/terranix/tailscale/acl.nix b/ext/terranix/tailscale/acl.nix new file mode 100644 index 0000000..d27d3e1 --- /dev/null +++ b/ext/terranix/tailscale/acl.nix @@ -0,0 +1,25 @@ +{lib, ...}: { + resource.tailscale_acl.default = { + acl = toString (builtins.toJSON { + tagOwners = let + me = ["getchoo@github"]; + tags = map (name: "tag:${name}") ["server" "personal" "gha"]; + in + lib.genAttrs tags (_: me); + + acls = let + mkAcl = action: src: dst: {inherit action src dst;}; + in [ + (mkAcl "accept" ["tag:personal"] ["*:*"]) + (mkAcl "accept" ["tag:server" "tag:gha"] ["tag:server:*"]) + ]; + + ssh = let + mkSshAcl = action: src: dst: users: {inherit action src dst users;}; + in [ + (mkSshAcl "accept" ["tag:personal"] ["tag:server" "tag:personal"] ["autogroup:nonroot" "root"]) + (mkSshAcl "accept" ["tag:gha"] ["tag:server"] ["root"]) + ]; + }); + }; +} -- cgit v1.2.3