working mtls for janus system

This commit is contained in:
John Lancaster
2026-03-15 20:52:34 -05:00
parent 3800ae7502
commit a8a9a73e08
2 changed files with 24 additions and 7 deletions

View File

@@ -2,18 +2,27 @@
{
flake.modules.nixos.mtls = { config, lib, pkgs, ... }:
let
certDir = config.mtls.certDir;
tlsKey = "${certDir}/${config.mtls.keyFilename}";
tlsCert = "${certDir}/${config.mtls.certFilename}";
mtlsBundle = "${certDir}/${config.mtls.bundleFilename}";
cfg = config.mtls;
certDir = cfg.certDir;
tlsKey = "${certDir}/${cfg.keyFilename}";
tlsCert = "${certDir}/${cfg.certFilename}";
mtlsBundle = "${certDir}/${cfg.bundleFilename}";
in
{
options.mtls = {
enable = lib.mkEnableOption "Enable mTLS";
caURL = lib.mkOption {
description = "URL to the certificate authority";
type = lib.types.str;
};
subject = lib.mkOption {
description = "The Common Name, DNS Name, or IP address that will be set as the Subject Common Name for the certificate. If no Subject Alternative Names (SANs) are configured (via the --san flag) then the subject will be set as the only SAN.";
type = lib.types.str;
};
certDir = lib.mkOption {
description = "String path to where the mtls certs will be stored.";
type = lib.types.str;
default = "/var/lib/tls";
default = "/etc/step";
};
keyFilename = lib.mkOption {
description = "String filename for the private key";
@@ -33,10 +42,13 @@
};
config = {
environment.systemPackages = with pkgs; [
environment.systemPackages = with pkgs; lib.optionals cfg.enable [
(writeShellScriptBin "mtls-generate" ''
set -euo pipefail
${lib.getExe pkgs.step-cli} ca certificate \
john-pc-ubuntu ${tlsCert} ${tlsKey} \
${cfg.subject} ${tlsCert} ${tlsKey} \
--ca-url ${cfg.caURL} \
--root ${cfg.certDir}/certs/root_ca.crt \
--provisioner admin \
--san 192.168.1.85 \
--san spiffe://john-stream.com/ubuntu