|
1 |
| -{ config, pkgs, lib, ... }: |
| 1 | +{ config, pkgs, ... }: |
2 | 2 |
|
3 |
| -let manifests = [ |
4 |
| - { |
5 |
| - file = config.sops.templates."tailscale.yaml".path; |
6 |
| - toWait = "deployment.apps/operator"; |
7 |
| - namespace = "tailscale"; |
8 |
| - condition = "condition=Available"; |
9 |
| - } |
10 |
| - { |
11 |
| - file = pkgs.writeText "tailscale-namespace.yaml" '' |
12 |
| - apiVersion: v1 |
13 |
| - kind: Namespace |
14 |
| - metadata: |
15 |
| - name: tailscale |
16 |
| - ''; |
17 |
| - condition = "jsonpath={.status.phase}=Active"; |
18 |
| - toWait = "namespace/tailscale"; |
19 |
| - namespace = ""; |
20 |
| - } |
21 |
| -]; |
22 |
| -in { |
23 |
| - services.tailscale.authKeyFile = config.sops.secrets.tailscale.path; |
24 |
| - services.tailscale.extraUpFlags = ["--ssh" "--hostname=${config.networking.hostName}"]; |
| 3 | +{ |
| 4 | + services.tailscale.authKeyFile = config.sops.secrets.tailscaleNodeKey.path; |
| 5 | + services.tailscale.extraUpFlags = ["--ssh" "--accept-dns" ]; |
25 | 6 |
|
26 |
| - system.activationScripts.tailscaleOperator.deps = [ "renderSecrets" ]; |
27 |
| - system.activationScripts.tailscaleOperator.text = (pkgs.callPackage ./install-k3s-manifest.nix { |
28 |
| - inherit lib pkgs manifests; |
29 |
| - }).script; |
30 |
| - |
31 |
| - sops.secrets.tailscale = {}; |
32 |
| - sops.secrets.tailscale_oauth_client_id = {}; |
33 |
| - sops.secrets.tailscale_oauth_client_secret = {}; |
| 7 | + sops.secrets.tailscaleNodeKey = {}; |
| 8 | + sops.secrets.tailscaleNodeHostname = {}; |
| 9 | + sops.secrets.tailscaleOauthClientId = {}; |
| 10 | + sops.secrets.tailscaleOauthClientSecret = {}; |
34 | 11 |
|
35 | 12 | sops.templates."tailscale.yaml".content = ''
|
36 | 13 | apiVersion: helm.cattle.io/v1
|
|
43 | 20 | chart: tailscale-operator
|
44 | 21 | targetNamespace: tailscale
|
45 | 22 | valuesContent: |
|
| 23 | + operatorConfig: |
| 24 | + hostname: "k8s-operator-${config.sops.placeholder.tailscaleNodeHostname}" |
46 | 25 | oauth:
|
47 |
| - clientId: ${config.sops.placeholder.tailscale_oauth_client_id} |
48 |
| - clientSecret: ${config.sops.placeholder.tailscale_oauth_client_secret} |
| 26 | + clientId: ${config.sops.placeholder.tailscaleOauthClientId} |
| 27 | + clientSecret: ${config.sops.placeholder.tailscaleOauthClientSecret} |
49 | 28 | apiServerProxyConfig:
|
50 | 29 | mode: "true"
|
51 | 30 | waitForJobs: true
|
52 | 31 | waitForHelm: true
|
53 | 32 | '';
|
| 33 | + |
| 34 | + system.activationScripts.tailscaleNamespace.text = (pkgs.callPackage ./install-k3s-manifest.nix { |
| 35 | + inherit pkgs; |
| 36 | + manifest = { |
| 37 | + file = pkgs.writeText "tailscale-namespace.yaml" '' |
| 38 | + apiVersion: v1 |
| 39 | + kind: Namespace |
| 40 | + metadata: |
| 41 | + name: tailscale |
| 42 | + ''; |
| 43 | + condition = "jsonpath={.status.phase}=Active"; |
| 44 | + toWait = "namespace/tailscale"; |
| 45 | + namespace = ""; |
| 46 | + }; |
| 47 | + }).script; |
| 48 | + system.activationScripts.tailscaleOperator.deps = [ "renderSecrets" "tailscaleNamespace" ]; |
| 49 | + system.activationScripts.tailscaleOperator.text = (pkgs.callPackage ./install-k3s-manifest.nix { |
| 50 | + inherit pkgs; |
| 51 | + manifest = { |
| 52 | + file = config.sops.templates."tailscale.yaml".path; |
| 53 | + toWait = "deployment.apps/operator"; |
| 54 | + namespace = "tailscale"; |
| 55 | + condition = "condition=Available"; |
| 56 | + }; |
| 57 | + }).script; |
54 | 58 | }
|
0 commit comments