yep, more dotfiles

server: enable own derp server

wiro.world 2f45d00e e6e1ce8e

verified
Changed files
+7
nixos
profiles
+7
nixos/profiles/server.nix
···
thelounge-hostname = "lounge.wiro.world";
headscale-port = 3006;
+
headscale-derp-port = 3478;
headscale-hostname = "headscale.wiro.world";
lldap-port = 3007;
···
# Reflect firewall configuration on Hetzner
firewall.allowedTCPPorts = [ 22 80 443 ];
+
firewall.allowedUDPPorts = [ headscale-derp-port ];
};
services.qemuGuest.enable = true;
···
client_secret_path = config.age.secrets.headscale-oidc-secret.path;
scope = [ "openid" "profile" "email" "groups" ];
pkce.enabled = true;
+
};
+
+
derp.server = {
+
enable = true;
+
stun_listen_addr = "0.0.0.0:${toString headscale-derp-port}";
};
};
};