This repository has been archived on 2026-07-30. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
nixos/modules/build-types/tailscale-router.nix
T
beatzaplentyandClaude Sonnet 4.6 997918e2f7
Check NixOS configurations / eval-hosts (pull_request) Failing after 11m33s
feat(beszel): add beszel agent to tailscale-router
Wires beszel-agent into all tailscale-router variants (lxc/linode/proxmox)
by importing enable-agent.nix in the build type and host-token.nix in the
host file. Adds the sops creation rule for secrets/tailscale-router.yaml
(all three platform variants as recipients). The secrets file must be
created manually before deploying — see instructions in PR.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-26 11:07:51 +10:00

46 lines
1.9 KiB
Nix

{ vars, ... }:
{
imports = [
../tailscale/subnet-router.nix
../beszel/enable-agent.nix
];
# "server", not "both": this build type advertises LAN subnet routes but
# doesn't use another tailscale exit node itself, so it doesn't need the
# "client"-side loose reverse-path filtering that "both" would also enable.
# Deliberately kept explicit here (not just relying on subnet-router.nix's
# own setting) so the intent is clear at the build-type level.
services.tailscale.useRoutingFeatures = "server";
# Advertise the LAN subnet so Tailscale peers can route back to LAN machines.
# Must also be approved in the Tailscale admin console (Machines → Edit route settings).
services.tailscale.extraUpFlags = [ "--advertise-routes=${vars.lanCidr}" ];
networking = {
# SNAT traffic from LAN machines going out through Tailscale so the remote
# peer sees it sourced from this router's Tailscale IP (100.x.x.x) rather
# than a raw LAN IP. Without this, Tailscale drops the forwarded packets
# because the source is not a recognised Tailscale address.
#
# networking.nat.externalInterface alone does not insert a MASQUERADE rule
# (it only does so when internalInterfaces is also set). We use
# extraCommands to add the rule into the nixos-nat-post chain that
# networking.nat.enable creates, and extraStopCommands to clean it up.
nat.enable = true;
firewall = {
# Forwarded subnet-router traffic arrives on tailscale0 already
# tailscale-authenticated -- the firewall's normal per-port allow-list
# would otherwise drop it. Standard NixOS/Tailscale subnet-router guidance.
trustedInterfaces = [ "tailscale0" ];
extraCommands = ''
iptables -t nat -A nixos-nat-post -s ${vars.lanCidr} -o tailscale0 -j MASQUERADE
'';
extraStopCommands = ''
iptables -t nat -D nixos-nat-post -s ${vars.lanCidr} -o tailscale0 -j MASQUERADE 2>/dev/null || true
'';
};
};
}