snix/ops/modules
Vincent Ambo c30344475c fix(tvl-headscale): restore default ACL policy
I omitted the `acls` section when adding the tag configuration. In "normal"
tailscale, emitting this is equivalent to putting the defaults there (i.e. all
traffic inside the tailnet is allowed), however in headscale it defaults to
blocking everything instead.

This meant that internal tailnet traffic wasn't really working correctly anymore.

Change-Id: Ic37504e9a8a97b9f8eb3ac173c88201aef1c044a
Reviewed-on: https://cl.tvl.fyi/c/depot/+/12972
Reviewed-by: sterni <sternenseemann@systemli.org>
Tested-by: BuildkiteCI
Autosubmit: tazjin <tazjin@tvl.su>
2025-01-12 21:53:54 +00:00
..
tvl-slapd chore(3p/sources): Bump channels & overlays 2022-08-13 14:43:05 +00:00
www feat(whitby): switch from nix-serve to harmonia for the cache 2024-09-26 23:27:29 +00:00
.skip-subtree refactor(ops): Split //ops/nixos into different locations 2021-04-11 22:18:22 +00:00
atward.nix style: format entire depot with nixpkgs-fmt 2022-01-31 16:11:53 +00:00
auto-deploy.nix style: format entire depot with nixpkgs-fmt 2022-01-31 16:11:53 +00:00
automatic-gc.nix feat(automatic-gc): robust way to disable automatic-gc 2024-03-31 21:44:26 +00:00
btrfs-auto-scrub.nix chore(ops/modules/btrfs-auto-scrub): schedule later by default 2024-02-15 00:03:45 +00:00
cgit.nix refactor(ops/cgit): make user configurable 2022-07-12 08:49:55 +00:00
cheddar.nix fix(ops/modules): re-add cheddar highlighting server 2024-08-23 23:41:39 +00:00
clbot.nix feat(fun/clbot,ops/machines/whitby): filter tvix-dev clbot 2024-06-03 19:35:34 +00:00
default-imports.nix feat(ops/auto-deploy): Support auto-deploy 2021-12-26 14:55:42 +00:00
default.nix style: format entire depot with nixpkgs-fmt 2022-01-31 16:11:53 +00:00
depot-inbox.nix chore(3p/sources): Bump channels & overlays 2023-06-15 17:09:02 +00:00
depot-replica.nix fix(depot-replica): make the depot replica world readable 2022-07-12 08:49:55 +00:00
gerrit-autosubmit.nix fix: explicit dependencies on network-online.target 2024-02-26 11:48:32 +00:00
harmonia.nix feat(whitby): switch from nix-serve to harmonia for the cache 2024-09-26 23:27:29 +00:00
irccat.nix fix(ops/modules/irccat): only start after network is online 2024-11-15 14:53:59 +00:00
josh.nix refactor(3p): use josh from nixpkgs 2024-04-28 15:19:15 +00:00
journaldriver.nix refactor(ops/modules): Move journaldriver configuration into module 2022-02-18 11:38:34 +00:00
known-hosts.nix fix(ops/modules): adapt for changed ssh.knownHosts 2022-05-26 10:05:54 +00:00
livegrep.nix feat(ops/modules): reindex livegrap when depot refs change 2024-02-18 08:20:50 +00:00
monorepo-gerrit.nix feat(ops/monorepo-gerrit): link r/<id> shortlinks to revisions 2024-11-25 11:39:36 +00:00
nixery.nix fix(ops/nixery): switch nixery.dev to stable nixpkgs channel 2023-08-22 15:01:02 +00:00
open_eid.nix chore(ops/modules/open_eid): use nativeMessagingHosts.packages 2024-03-13 18:06:19 +00:00
owothia.nix feat(3p/agenix): update to 2022-05-16 and add to niv 2022-05-25 15:00:37 +00:00
panettone.nix fix(ops/modules): regularly restart panettone for b/225 2022-12-05 09:40:38 +00:00
paroxysm.nix style: format entire depot with nixpkgs-fmt 2022-01-31 16:11:53 +00:00
prometheus-fail2ban-exporter.nix refactor(ops): Break out prometheus-fail2ban-exporter module 2021-06-12 15:51:49 +00:00
quassel.nix fix(ops/modules/quassel): use systemd LoadCredential to read certs 2023-06-15 21:34:36 +00:00
README.md refactor(ops): Split //ops/nixos into different locations 2021-04-11 22:18:22 +00:00
restic.nix style: format entire depot with nixpkgs-fmt 2022-01-31 16:11:53 +00:00
smtprelay.nix feat(3p/agenix): update to 2022-05-16 and add to niv 2022-05-25 15:00:37 +00:00
teleirc.nix feat(ops/modules): launch teleirc for Volga Sprint 2024-05-26 19:36:29 +00:00
tvl-buildkite.nix fix(ops/modules/tvl-buildkite): add /run/wrappers/bin to $PATH 2023-09-24 19:30:15 +00:00
tvl-cache.nix fix: reflect renames of Nix configuration options 2022-08-25 16:34:39 +00:00
tvl-headscale.nix fix(tvl-headscale): restore default ACL policy 2025-01-12 21:53:54 +00:00
tvl-users.nix chore(users): grfn -> aspen 2024-02-14 19:37:41 +00:00
yandex-cloud.nix fix(ops/modules): remove cloud-init from yandex-cloud module 2023-10-08 18:13:49 +00:00

NixOS modules

This folder contains various NixOS modules shared by our NixOS configurations.

It is not read by readTree.