{ config, ... }: # Tailscale node joined to the self-hosted headscale control server. # Auto-registers on boot from a sops pre-auth key. Requires the importing host # to declare `sops.secrets.tailscale_authkey` (see each host's secrets.nix). # Not for the VM (no sops). { # TEMPORARY: nixpkgs bumped tailscale 1.98.8->1.98.9 without updating # vendorHash (NixOS/nixpkgs#545860, fixed on the `release-26.05` branch # 2026-07-26 but not yet promoted to the `nixos-26.05` channel branch this # flake tracks). Remove this override once `nix flake lock --update-input # nixpkgs` picks up a nixos-26.05 rev at/after that fix. nixpkgs.overlays = [ (final: prev: { tailscale = prev.tailscale.overrideAttrs (old: { vendorHash = "sha256-Sd2iLJ7eDfDYdIRuW4xuiKgzhQWJWGAnz97FJWrVRlE="; }); }) ]; services.tailscale = { enable = true; openFirewall = true; # UDP 41641 for direct connections authKeyFile = config.sops.secrets.tailscale_authkey.path; extraUpFlags = [ "--login-server=https://vpn.mgaction.town" ]; }; # Reach the host's services over the tailnet without opening LAN ports. networking.firewall.trustedInterfaces = [ "tailscale0" ]; # The upstream unit is a one-shot with no Restart, so a login attempt made # before the control server is reachable fails permanently until someone # starts it by hand. That's the norm on a first boot — neptun hosts headscale # itself, and the other hosts race it. 30s spacing also keeps restarts clear # of systemd's default start limit (5 within 10s). systemd.services.tailscaled-autoconnect.serviceConfig = { Restart = "on-failure"; RestartSec = 30; }; }