From 01362f145f72a7c62e24ef9f324a8efb6080e733 Mon Sep 17 00:00:00 2001 From: Jimbo Date: Mon, 30 Sep 2024 23:15:15 -0400 Subject: [PATCH] Remove redundant IP storage --- extras/secrets-template.nix | 1 - extras/secrets.nix | Bin 3046 -> 3017 bytes system/server/firewall.nix | 2 +- 3 files changed, 1 insertion(+), 2 deletions(-) diff --git a/extras/secrets-template.nix b/extras/secrets-template.nix index bd7d892f..e1023319 100644 --- a/extras/secrets-template.nix +++ b/extras/secrets-template.nix @@ -69,5 +69,4 @@ jimIP2 = ""; lunaIP = ""; cornIP = ""; - vertIP = ""; } diff --git a/extras/secrets.nix b/extras/secrets.nix index 30312f92dd836559c0241795ef390e7a0084166d..0d7d38b1ef48744424b619af3817ec86056dafdc 100644 GIT binary patch literal 3017 zcmZQ@_Y83kiVO&02%lb=x9jv2!{h_Em%RKYERrbjOkhnn6O-<#4YDEn%$6So9?Yw9 z&Ak3EJS_3gyBo7pcBPlcZqIFAwR_hG--V{^&DyrD3!)D$V>*y1u;s7jRBg{TEv>Mt zcl%y#SCMb{oMBVfWV2-9y(s+`JNAEP^#1LlEqG+5RKa)6wqow;m#ojXZ|2gSS!#ar z%WvyD)r+^-7hL`%?(WzqA@tPIpt=8lC*M@P`bMW414Jh-_$d1Jwris^t5)~_M6Tm& zW+!qL*`NK}yC`jQ;+@xKdtQW?upaB*BfR0_jVn_Wv;%)>H z?u}`L>0bY?t1rz%XLYV-K6~=>o+gW=TdG@Y<|$08-I7}-bgPB!aR=Kq}w#{a1g@#a3G*3k{7xOF>O04j|C^qxdIsXUDS{_;VR^C|rDD=)%j`v1?=7gx; z`~G3ROzIll(?1zXKkwsdojog|*L}5v?-l2}n}u&TC;OFYtWuDAP@QKh|6_mjtA|OO zIJh{?XDaoy_J8~K^ZEM%H^~5}p6XMIC)GB-ntbHOLKo95_qSZ-oxoJC)Hr3z8>^)& zqF(>3G^oW%QBcQvXKMX}EpAHI1tHm5aU3frcg)Ey zzxn6;&fAvl_t~Zey|=bK{_6FztDA~v$LnpK=lspmzCuE;Cz-!{0f#>0zs|Vx{CpBd zOYdt=XuEdOs=KskO=s?-*md6u+P1i=#<5M1PMuY{(revIC&!#UWy`~oFVxh|{}Qm> zGtS2+IwvcC=IZ13UIeUdVYs(>!7o=&i&GW~vQ{e=cWw(86OZ4~X6?Re(v*qQX30)Z zmz~FTga7@?`=?%SU6-@LL_h7F!0sn^jk^E*@%UjF-OQ%uqnb4%#P2vuL?)+Il0=bV zWUz1Pf(tIYJ+n5Y++VY5@2&M0_rK42sPJ>nlzm5DE&W}0M2+Rb-xnfzyMnKlOuWf% zILWJ)zjmwP#3OZ`&pkUIHI+qqK9^DS|KobVeEY4XN6S-kax_={_pMcTZ~ecn_0jHz zc^r?ntL%H0VA(gDx9xQsXIA_cUGEEGf+;Wa7dePch?{fC=i~Hj)q~p8`O_TCWm&ej z=;Ys6Qms0NVN=$s2Zz6P%sfz|S(SZJ<*{sB#LBH+N`V||a$?^V^ea z-luH)xAk8Z>*v1`Rt@q#DYo+S6Drg@l)bfd@)fO2!_Mfv=aX3aG2hqz<4NX|>2)3% z+jhFIK@;cp?OJ;~YBfAE|bZ8{bplS$gE!1$~ic z3=5lIr|xaJ^TcDOTG&3h`JJmP^v!m(`_9UH!S&W8dW{BuXw^#{hr7*UQhOrb{Y>%@ z{-vHXEx)1QCtsOBgwm9qQNa`?`IP2uMrym+1Nza_4huT*KS`91$Co+%-p z46og7sIlL*cl9aerVghmpDr(+&pnsb$YjE#Fv~q^?|H%mB6hsCJ+boowmqC;u9y1H zP2fwHdUej_s{fS(528Q)<>*NljaypJ9lS_jjX`FDr@4vlO)LZ$>vgBp*_Ny|cLFtQU`)d8~UwM5+ z-G-0fgP*Nr5MFN)bWF}PE_qRl=dGet>v--*FY3}%1n>S|a4h=labBL*ziXz|BrcGN zwinv}soYfk|3*Rmr?WQY-+k7?DQc8* zwKlz5D`4T3XQiZf$&<_bj|!WXyZc+!U#9QgtDI#@3Mn!Adr99)bVqzgUS`X=;C?5r z4c2S+X=KgaP;zUj;DwLh>*T)~m;KN@?E1UZa#_{OT^G8Y7hJ3kRtVAEsdFziTt6u8 z59_5%p=Qrc|5iKqEqeBK!TLtWb1T`;if>Grx52qgcfVTMn`s-u)F1dwGP=fo&dTGZ z^|Z_T4N991RSBJ~h}_wx;B`99v_J6Kt_ROn`O27d6))*!(@#59J0sZqXlnK<IH~iwRqpkb@Rz1rm+Xj%qK|$_ zp4gY;6}C|6=<0awi9dJslnGv{(--H^dB5F$-rB(MKiyw?+4MC|?Z3Q%C9=0s{7lqy z^H+N;sxxvKKXxX`y_{`h7geyQ^YOD&yA2-wnh^a$q5bNNg#Lh7U9p;=+f%Yz+T$j9 zcb_tSR=!2_c-{-)0HcoTaz!g?YnBaZRg<`UF;!m zsvE9wac;=UVY(Dz%sR8Q?E1?8te#P~G~b7XepRU6DX_U@ai8+vRlAI?y#2XGX3C|x zyp~?~r*G-bUflSe*Fmdx&JTmjXCGEL^i2x7vVOy)V|7};RnjU-?mg&I@rvDVb1>?3 zhqS?z$$u_hocKNR>fCuQZL-c!cuZx&{}gY_ox*job?T@32?yVarFvBLl+K?x_2%Q3 z@3dl!x@IO)${rULY4Y^!#WlOZQdBe&2!>g^}@fBx3ppdS~Bt; zeyWU5Y-rs%C*bMR4NI=*8v94@J^g^^_sf%0eAy1fGc(=3(mBobv^e|9)z9+fqolfK zcs{>!@4>Rt5b=!J>HG=1{CXxoOfAnkdFgqe>UrMQx4YZ-UtJ>hR$`;lbG=DjG9O&; z1bHYst1whf_&WW#n(-GIAE5`+&&=PumgzHJN2kf&t(jb{=C8cN4pf>SIS{@q_(l7d QzHOJboVE^F+j3G20L%L8h5!Hn literal 3046 zcmZQ@_Y83kiVO&0nEpd@%Idb;YZiR(z50B&M)9MU1^?pC2VFX4_j%&Gi^iwozB$eP ztJu4L-gfo7HmX8W7g!hX@mEYMQdqdoQ|95EW+mY<6vwg1#PS(D1YgcpFWxfM%cfKs|yY=d?*U^aQ559$;%V>Kk z@W*D(gybD=HGBPQG(UJUuzmXAXp^{Jq4w$aX`h=;bKm8Bc65{I?ac1&>D&n(9H)y- znuPctExLL)@%GF2k@3G4FRXBLG?#dq8f~EU<*?uG*O@oPUg#Q|ud)^p*s^@aq}UTi z&vY~_y_^_0E}3pC=GYw-bMGjZyq)AOm-gqz(#n^5EW9@VUVL`e^erocr?9*^v+!Zj z=Bl=(=93oXH@F^cjTN_KQCxT8vfLJ%S(@v+b-p>H2hDjpCO|SC=f0{&qy%WcA6u z1yd#W%)jdMr_=k+ImyZ|PtN#Bhdz#;oqo`+|H3ZZN%ctn4z98fd6|FLWzNmvW}SIU{H?OLKT=Vo#;sE7>z5n9vOXIw@Y~A&5@~Mu1 z>^p`xOe^^!W*UmDOG|#kder*t-UOyOs%#R6%vNx$?VhLG9{S|`^4$&Qu}^NwEPOfT zUQ^bIMeT>?YPpr{tgUIEHuZ|giEn+~iynM?GXKrd9F7DdrNb<;&!@cDcU)0vW0Fjf z%a^Sw(;s+NAD{F8l1k>(pNX&Lsjzgl+q_pQIP<}H^7Yowp##@4NG^uBAHIC6K=65a`y z9nv1lek>Q8!xzJH`@v?(;vM11Ov&r&w)P)gJAGDU$KuxwX;0RrvvjrozG6Ewlz;tv z$(!oGqmIA$`7wIg9LH6^8ndG1*}B@dyRAFpX5{+bJ@SR*gNSntv&^$jO_GjWDOa=f z-KL0$-_1XR6}12BshhB0n*6`I=g#@dOL`v~XD0YNV?cPry*#s`&>$9&{ktRCHzZwxmPt(p_`U2}bly?dA85=H5l zHI3&U%c*jlTq?}Y(KU2+3n}DZ&T}vgDY!(Z1+`sQKIAb zAbVS0=_-TkPu8c{$W8sCe!9dmKdQr~bIGEW-L{!HV=ytG|;4UDmr? zG2jcjddcgbG;8oO#SC6+^$QY?p~9{Haht`yt_eyxANy2&dF%1dQ`;Wxl;1baOSjB- z{&~(L^QWKjdiY`DQX#qK$qOYP7SEXFFjafD#K9mdor#~cA7_17EV=gm>JyR|xK7*d zzTLV>|3Gf7phvhB-&gTur(a)|IL$t}=SpwZDyfTEmHVt&5_Ss-Ry%rHsBag@JYJ-F z^P|%2tlGtC;a?8_=9=~9-_f6w*QU5HHeRs3Ve`zw`0qj|-W$zj&wo5yZ&7nl;zIps zgOoGZ;%?M%s#l3S7)6^F@bvuOt+M}kWM4o(_v-ZTQ`FdM@^`M{UTVUlb^NyHj%xxr z-%FWNdX_wuD(kt)a-$(;uBG&<(vLxFc}%ix{`m16F*efA zib9%~7K`OX${h*vlZu=4sBH7AuImprl+WH(QqNnuYh70Cxx88O0`n&>{%&P#W~*+! zCAZY}#En@e?wJKjh%R2qIb(&0Ms$wuU5;BtOfKCYWo4Bd9Ve`Wsb?`7s_ z8-1_Sf6{X+@I_#o!Q*$w8RTDzJ)L%(`xVpd_zgMS91gKR_N~W$@x>>HS7|(xT_ROJX*tiY?-bm1Ot0$eHP*%M$3oaEm+tRL6$_vYT3K3`g4mlW*h^W5#ir+cDTHpp;yVM!_}%B;kwl`BmjE&|9NU% z?RDX8OY(*6xk%kKPF}{k9alQ2kHa$JolHc>3en%lBtytVoHB{QlF6MY^w2 z&~dU-!Nxbn<%_o-x%d9J0_X1OSG0>nlQuJCFN_XrRQH-#!5G6h@8q1cLoXbQ*9GVI z9#kZp>9g#+9}}-UczfbE1J_~}xha>dzh#Pl&Ev{$yD0a; z_I~VlrX9&QUVWRjs_Al7z1vm2tZCY7`)^04^HpcAcKDmQ_(RqbJvCPI;;6vtz5nNN z)$Iv%&fjLXX_0B_Vh-8uhpnILophOflI>OM$!W(@F0WQxFQ+r>;(ev1pS=v9nr!DkN9JKV_nMfZV@cO8sJ3tFlzH{w2&2cNbIj~l zydE0=I%skz!g9BMQN$J~^z{n!II=>XZC>`<6;`u|>zR zdFJy=`lbl3u)QcWTWFbU$d#!a&klW8aB`i+vP+qd!Oqd*g8rqFMyW^H%eq3sC!Trn zDeLEPk3+|eL-#uWS(Kf$Y=xQ76rSdNS-Pk7HXaQr7W7Vfp>}ZLm-YVr$^2C(KFvS2 zf2q>(3eK&~9kUj#YFaa`;#p}%-HgMNeg>wd=RJNtQRIvBMA3z&4LMH_`KE8)>3+Fj zHOuNZzDMT9u^O3*2TDA8I$b31UaytVoEr8dF4yBLZ@!zjC?&t95&eUGF zd#YD(*DjN3@o%{g2&g`u!?*hR`x9@{T7PGpxR<5D*=T#}!TBi+M)eoVL`{_+g?*YJ zpR=m%jE>CwJ=K*(FB$eROb=fF?%%`k?&GGrX8k@Z!{&aB`;zT+KF`gLeM_HDeIhmE zb{&)apHIb{XRd8f+>=u|TSw)*wa~n+9~D%qpFX)4GIOd|u6(WFW|iMf)-(N8B^OL= zSa32%&~`@_)6U8Z`!8&?ZMNc2vDCa(^(9%mYx63xwX0V}F1GJ(5{tT%q_KG0+0u}S z*Jp5FlupZ9eC_C(g^VA%Cw)6+H$72f$pPy}o1322yxV{Ifuv7=n1HrR_+6>pRi;UM zcm7DSbmR>3WM9e5)5BiBJy32-ok+9k)CX*pQMaSE+={+CX;$@vuPJYyJWMWH3;?70 B{n7vc diff --git a/system/server/firewall.nix b/system/server/firewall.nix index cab7798f..a5a4184f 100644 --- a/system/server/firewall.nix +++ b/system/server/firewall.nix @@ -12,7 +12,7 @@ # Add extra input rules using nftables extraInputRules = '' ip saddr { ${outputs.ips.localSpan}.0/24, ${outputs.ips.wgSpan}.0/24 } tcp dport 2049 accept comment "Accept NFS" - ip saddr { ${outputs.ips.pc}, ${outputs.secrets.lunaIP}, ${outputs.secrets.cornIP}, ${outputs.secrets.vertIP} } tcp dport { 1935, 1945 } accept comment "Accept RTMP" + ip saddr { ${outputs.ips.pc}, ${outputs.secrets.lunaIP}, ${outputs.secrets.cornIP} } tcp dport { 1935, 1945 } accept comment "Accept RTMP" ip saddr ${outputs.ips.wgSpan}.3 tcp dport ${mailPorts} accept comment "Accept mail" ''; };