diff --git a/nixos/modules/services/networking/nebula.nix b/nixos/modules/services/networking/nebula.nix index 7ef930fff68f..6f7d69cb6f99 100644 --- a/nixos/modules/services/networking/nebula.nix +++ b/nixos/modules/services/networking/nebula.nix @@ -292,7 +292,7 @@ in assertions = lib.mapAttrsToList (netName: netCfg: { # IFNAMSIZ caps network device names to 16 chars (including NULL terminator). # Without this check, users might end up with a truncated interface name. - assertion = !netCfg.tun.disable && builtins.stringLength netCfg.tun.device <= 15; + assertion = netCfg.tun.disable || builtins.stringLength netCfg.tun.device <= 15; message = '' Network device names can't be longer than 15 chars. `config.services.nebula.networks.${netName}.tun.device` is set to "${netCfg.tun.device}" which is above the limit. diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 58950fafd903..8109ee869fa8 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -1241,6 +1241,7 @@ in nebula-lighthouse-service = runTest ./nebula-lighthouse-service.nix; nebula.connectivity = runTest ./nebula/connectivity.nix; nebula.reload = runTest ./nebula/reload.nix; + nebula.tunless = runTest ./nebula/tunless.nix; neo4j = runTest ./neo4j.nix; netbird = runTest ./netbird.nix; netbird-relay = runTest ./netbird-relay.nix; diff --git a/nixos/tests/nebula/tunless.nix b/nixos/tests/nebula/tunless.nix new file mode 100644 index 000000000000..dac1607e27e8 --- /dev/null +++ b/nixos/tests/nebula/tunless.nix @@ -0,0 +1,43 @@ +{ ... }: +{ + name = "nebula"; + + nodes = { + lighthouse = + { pkgs, ... }: + { + environment.systemPackages = [ pkgs.nebula ]; + + services.nebula.networks.smoke = { + # Note that these paths won't exist when the machine is first booted. + ca = "/etc/nebula/ca.crt"; + cert = "/etc/nebula/lighthouse.crt"; + key = "/etc/nebula/lighthouse.key"; + isLighthouse = true; + listen = { + host = "0.0.0.0"; + port = 4242; + }; + # A lighthouse can run without a tun interface. The device name is + # unused then, so the length assertion must not apply to it. + tun.disable = true; + }; + }; + }; + + testScript = '' + # Create the certificate and sign the lighthouse's keys. + lighthouse.succeed( + "mkdir -p /etc/nebula", + 'nebula-cert ca -duration $((10*365*24*60))m -name "Smoke Test" -out-crt /etc/nebula/ca.crt -out-key /etc/nebula/ca.key', + 'nebula-cert sign -duration $((365*24*60))m -ca-crt /etc/nebula/ca.crt -ca-key /etc/nebula/ca.key -name "lighthouse" -groups "lighthouse" -networks "10.0.100.1/24" -out-crt /etc/nebula/lighthouse.crt -out-key /etc/nebula/lighthouse.key', + 'chown -R nebula-smoke:nebula-smoke /etc/nebula' + ) + + # Restart nebula to pick up the keys and verify it listens without creating a tun device. + lighthouse.systemctl("restart nebula@smoke.service") + lighthouse.wait_for_unit("nebula@smoke.service") + lighthouse.wait_until_succeeds("ss -lun | grep -q ':4242'", timeout=10) + lighthouse.fail("ip link show nebula.smoke") + ''; +} diff --git a/pkgs/by-name/ne/nebula/package.nix b/pkgs/by-name/ne/nebula/package.nix index 024c280c7a72..1da168e521e4 100644 --- a/pkgs/by-name/ne/nebula/package.nix +++ b/pkgs/by-name/ne/nebula/package.nix @@ -54,6 +54,7 @@ buildGoModule (finalAttrs: { inherit (nixosTests.nebula) connectivity reload + tunless ; };