mirror of
https://github.com/ryan4yin/nix-config.git
synced 2026-08-03 18:28:37 +02:00
feat(desktop): enable the firewall on desktop machines
Signed-off-by: Ryan Yin <xiaoyin_c@qq.com>
This commit is contained in:
@@ -21,9 +21,7 @@ in
|
||||
services.sunshine.enable = lib.mkForce false;
|
||||
services.tuned.ppdSettings.main.default = lib.mkForce "power-saver";
|
||||
|
||||
# This laptop joins untrusted networks and the firewall is disabled
|
||||
# (modules/nixos/base/ssh.nix), so a 0.0.0.0:9100 node-exporter would be exposed
|
||||
# to whatever network it is on. It is no longer scraped anyway - disable it.
|
||||
# Laptop joins untrusted networks and is no longer scraped; don't expose :9100.
|
||||
services.prometheus.exporters.node.enable = lib.mkForce false;
|
||||
|
||||
networking = {
|
||||
|
||||
@@ -52,8 +52,7 @@
|
||||
receiver = "telegram";
|
||||
routes = [
|
||||
{
|
||||
# Meta alerts like Watchdog & InfoInhibitor should never notify,
|
||||
# and info-level alerts are too noisy; route them to a null receiver.
|
||||
# Meta alerts (Watchdog, InfoInhibitor) and info-level noise never notify.
|
||||
receiver = "null";
|
||||
matchers = [ ''severity =~ "none|info"'' ];
|
||||
}
|
||||
|
||||
@@ -4,11 +4,8 @@
|
||||
...
|
||||
}:
|
||||
let
|
||||
# Hosts that should not be scraped:
|
||||
# - powered-off machines (SBCs and the whole k3s-prod-1 cluster), to avoid TargetDown
|
||||
# noise; remove entries from this list when the machines come back online.
|
||||
# - shoukei (a laptop on untrusted networks), its node-exporter is disabled on the
|
||||
# machine itself, so there is nothing to scrape.
|
||||
# Powered-off hosts (SBCs, k3s-prod-1) plus shoukei (exporter disabled on the
|
||||
# machine); remove entries when they come back online.
|
||||
offlineHosts = [
|
||||
"shoukei"
|
||||
"suzu"
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
# Desktops hold personal data and laptops join untrusted networks, so enable the
|
||||
# firewall here (repo-wide default is off, see modules/nixos/base/ssh.nix).
|
||||
# SSH/Tailscale/LocalSend/Sunshine keep working via their own `openFirewall` options.
|
||||
{
|
||||
networking.firewall = {
|
||||
enable = true;
|
||||
# Trust everything from the tailnet.
|
||||
trustedInterfaces = [ "tailscale0" ];
|
||||
};
|
||||
}
|
||||
Reference in New Issue
Block a user