# roles/thin-client/network/netbird.nix # # NetBird client for Thin Clients. Per-host setup-key via agenix. # Q15 decisions: Per-Host Setup-Key, Corp DNS + NetBird DNS parallel, # Client-only + accept-routes. # # SSH via NetBird: enabled (Q7). {config, lib, pkgs, ...}: let inherit (lib) mkIf mkOption types; cfg = config.az.tc; hostname = config.networking.hostName; in { options.az.tc.netbird = { setupKeyFile = mkOption { type = types.path; default = ../../../secrets/${hostname}-netbird-setupkey.age; readOnly = true; description = '' agenix-encrypted NetBird setup key for this host. Provisioned in the NetBird UI before first boot. Decrypted to /run/agenix/netbird-setupkey (referenced by the systemd service). ''; }; managementUrl = mkOption { type = types.str; default = "https://netbird.az-group.local:443"; # TODO: real URL description = "NetBird management URL (self-hosted)."; }; }; config = mkIf cfg.enable { services.netbird.enable = true; systemd.services.netbird = { environment = { NB_DISABLE_SSH_CONFIG = "false"; # we want SSH-via-NetBird NB_MGMT_URL = config.az.tc.netbird.managementUrl; NB_SETUP_KEY = "file:/run/agenix/${hostname}-netbird-setupkey"; }; path = with pkgs; [shadow util-linux]; after = ["age-identity.service" "network-online.target"]; wants = ["age-identity.service" "network-online.target"]; }; # Per-host setup key (agenix) age.secrets."${hostname}-netbird-setupkey" = { file = config.az.tc.netbird.setupKeyFile; mode = "0400"; owner = "root"; group = "root"; }; # SSH config: allow SSH via NetBird hosts (the netbird binary acts as # a ProxyCommand when the target is a NetBird peer). programs.ssh.extraConfig = '' Match exec "${pkgs.netbird}/bin/netbird ssh detect %h %p" PreferredAuthentications publickey PubkeyAuthentication yes PasswordAuthentication no ProxyCommand ${pkgs.netbird}/bin/netbird ssh proxy %h %p StrictHostKeyChecking accept-new LogLevel ERROR ''; # Loose reverse-path filter — required for overlay networks. networking.firewall.checkReversePath = "loose"; }; }