2023-11-30 14:40:07 -07:00
|
|
|
(define-module (machines vpn.metznet.ca)
|
2023-11-30 17:19:46 -07:00
|
|
|
#:use-module (guix gexp)
|
2023-11-30 14:40:07 -07:00
|
|
|
#:use-module (gnu system)
|
|
|
|
#:use-module (gnu services)
|
|
|
|
#:use-module (gnu services certbot)
|
|
|
|
#:use-module (gnu services vpn)
|
|
|
|
#:use-module (system base-system))
|
|
|
|
|
|
|
|
(operating-system
|
|
|
|
(inherit %metznet-base-server-system)
|
2023-11-30 16:24:50 -07:00
|
|
|
(host-name "vpn.metznet.ca")
|
2023-11-30 14:40:07 -07:00
|
|
|
(services
|
|
|
|
(append (list (service openvpn-server-service-type
|
|
|
|
(openvpn-server-configuration
|
2023-11-30 16:24:50 -07:00
|
|
|
(tls-auth "/etc/openvpn/ta.key")
|
2023-11-30 14:40:07 -07:00
|
|
|
(server "10.0.80.0 255.255.255.0")))
|
2023-11-30 17:19:46 -07:00
|
|
|
|
|
|
|
(simple-service 'vpn-server-etc etc-service-type
|
|
|
|
`(("openvpn/dh2048.pem" ,(local-file "dh2048.pem"))))
|
2023-11-30 14:40:07 -07:00
|
|
|
(service certbot-service-type
|
|
|
|
(certbot-configuration (email "admin@metznet.ca")
|
|
|
|
(certificates (list (certificate-configuration
|
|
|
|
(domains '
|
2023-11-30 16:24:50 -07:00
|
|
|
("vpn.metznet.ca"))))))))
|
2023-11-30 14:40:07 -07:00
|
|
|
(modify-services %metznet-server-services (delete openvpn-client-service-type)))))
|
|
|
|
|