custom-vpn-picker: init

This commit is contained in:
tomasr committed 2026-08-15 20:07:34 +02:00
1 parent 7cd934c58c
commit bc67f2b0e8
11 files changed
+144 -19

No files matched your search

+3
View File
@@ -569,6 +569,9 @@ secrets/
Encrypted secrets should remain encrypted in Git. Decrypted secret contents and private keys should not be committed.
* To edit a secret use `agenix -e <secret_file>.age -i /etc/ssh/ssh_host_ed25519_key`.
* To decrypt a secret use `sudo agenix -d <secret_file>.age -i /etc/ssh/ssh_host_ed25519_key`.
---
# Quickshell
+2 -1
View File
@@ -1,4 +1,4 @@
{...}: {
_: {
flake.nixosModules.hyprland = {
pkgs,
pkgs-unstable,
@@ -93,6 +93,7 @@ let
(builtins.readFile ../../other/hyprland/hyprland.lua);
in
{
#refer to https://wiki.hypr.land/Nix/Hyprland-on-Home-Manager/
wayland.windowManager.hyprland.enable = true;
wayland.windowManager.hyprland.package = pkgs-unstable.hyprland;
-13
View File
@@ -1,13 +0,0 @@
_: {
flake.nixosModules.mullvad = _: {
services.mullvad-vpn = {
enable = true;
};
};
flake.homeModules.mullvad = _: {
programs.mullvad-vpn = {
# gui
enable = true;
};
};
}
+1 -2
View File
@@ -38,7 +38,6 @@
latex
ly
mathematics
mullvad
networking
nixUtils
notifications
@@ -51,6 +50,7 @@
rss
udev
user
vpn
];
};
flake.homeModules.desktop = {...}: {
@@ -68,7 +68,6 @@
hyprland-desktop
kitty
librewolf
mullvad
neovim
nix-git-cherry-picker-desktop
desktop-notewrapper
+1 -2
View File
@@ -40,7 +40,6 @@
latex
ly
mathematics
mullvad
networking
nixUtils-laptop
nixUtils
@@ -52,6 +51,7 @@
rss
udev
user
vpn
];
};
flake.homeModules.laptop = {...}: {
@@ -70,7 +70,6 @@
hyprland-laptop
kitty
librewolf
mullvad
neovim
nix-git-cherry-picker-laptop
laptop-notewrapper
+12
View File
@@ -44,6 +44,18 @@ _: {
command = "${pkgs-unstable.nixos-rebuild}/bin/nixos-rebuild";
options = ["NOPASSWD"];
}
{
command = "/run/current-system/sw/bin/open";
options = ["NOPASSWD"];
}
{
command = "${pkgs.openconnect}/bin/openconnect";
options = ["NOPASSWD"];
}
{
command = "${pkgs-unstable.openconnect}/bin/openconnect";
options = ["NOPASSWD"];
}
];
}
];
+6
View File
@@ -13,5 +13,11 @@
group = "users";
mode = "0400";
};
age.secrets.epfl = {
file = ../../secrets/epfl.age;
owner = "tomasr";
group = "users";
mode = "0400";
};
};
}
+100
View File
@@ -0,0 +1,100 @@
# config for openconnect is in ./epfl.nix
{self, ...}: {
flake.nixosModules.vpn = {pkgs,...}: {
services.mullvad-vpn = {
enable = true;
};
environment.systemPackages = [
self.packages.${pkgs.system}.custom-vpn-picker
];
age.secrets.epfl = {
file = ../../secrets/epfl.age;
};
};
perSystem = {pkgs, ...}: {
packages.custom-vpn-picker = pkgs.writeShellApplication {
name = "custom-vpn-picker";
runtimeInputs = with pkgs; [
fzf
mullvad-compass
mullvad
openconnect
gawk
wl-clipboard
cliphist
];
text = ''
mullvad_connect () {
mullvad disconnect
mullvad relay set location "$1"
mullvad connect
}
profiles=(
"mullvad-best"
"mullvad-zurich"
"mullvad-tirana"
"mullvad-bogota"
"epfl"
"disconnect"
)
selected=$(printf "%s\n" "''${profiles[@]}" |
fzf --height 8 --reverse --prompt="Select vpn:")
[[ -z "$selected" ]] && exit 0
if [[ "$selected" == "mullvad-best" ]]; then
mullvad_connect "$(
mullvad-compass |
awk '/Best server:/ {
getline
split($1, a, "-")
print a[1]
}'
)"
elif [[ "$selected" == "mullvad-zurich" ]]; then
mullvad_connect ch
elif [[ "$selected" == "mullvad-tirana" ]]; then
mullvad_connect al
elif [[ "$selected" == "mullvad-bogota" ]]; then
mullvad_connect co
elif [[ "$selected" == "epfl" ]]; then
# shellcheck disable=SC1091
source /run/agenix/epfl
# Put password in clipboard so it can be pasted into openconnect.
printf '%s' "$EPFL_VPN_PASSWORD" | wl-copy
sudo openconnect \
--background \
--pid-file="$HOME/.local/state/epfl-openconnect.pid" \
--server="$EPFL_VPN_SERVER" \
--user="$EPFL_VPN_USER"
# Remove the password from cliphist and clear the current clipboard.
cliphist delete-query "$EPFL_VPN_PASSWORD" || true
wl-copy --clear
elif [[ "$selected" == "disconnect" ]]; then
if [[ -f "$HOME/.local/state/epfl-openconnect.pid" ]]; then
sudo kill "$(cat "$HOME/.local/state/epfl-openconnect.pid")" 2>/dev/null || true
fi
mullvad disconnect
rm "$HOME/.local/state/epfl-openconnect.pid"
fi
pkill -f "kitty.*Select vpn option" || true
exit
'';
};
};
}
+8 -1
View File
@@ -300,7 +300,7 @@ hl.bind(mod .. " + D", hl.dsp.layout("move +col"))
hl.bind(mod .. " + T", hl.dsp.exec_cmd(term))
hl.bind(mod .. " + E", hl.dsp.exec_cmd(file))
hl.bind(mod .. " + F", hl.dsp.exec_cmd(browser))
hl.bind(mod .. " + N", hl.dsp.exec_cmd(notes))
hl.bind(mod .. " + N", hl.dsp.exec_cmd("kitty --hold --class \"custom-vpn-picker\" --name \"Select vpn option\" custom-vpn-picker"))
hl.bind(mod .. " + SHIFT + A", hl.dsp.exec_cmd("caelestia shell drawers toggle launcher"))
hl.bind(mod .. " + Q", close_or_move_special)
local function toggle_sidebar()
@@ -812,6 +812,13 @@ hl.window_rule({
float = true,
size = "400 225",
})
hl.window_rule({
match = {
class = "^(custom-vpn-picker)$",
},
float = true,
size = "350 250",
})
hl.window_rule({
match = {
+7
View File
@@ -0,0 +1,7 @@
age-encryption.org/v1
-> X25519 XuDyuQL0WjW/IvtzxswKnOfXlJa42Itdu+inNPsiNhw
3z2v3GbNdMvX9QtgAMrWZB/5Y1HatgpoXGQUMnW91+M
-> ssh-ed25519 +tvThg i3NM64rsEgRRgah4PKWdrl4i0pmP6X2bgr2Etzm33Ag
OwUETps78LPyjIAcJo8eC9eh0m9qtRUh399xGzMCTwQ
--- 7LnVrVnmfA8YubysLVeGyRGlLI+ef0VxnIHRi6rRAlc
W¾TîópF’X±áì‘làBTœÝ"^ï”�-þµ‹à¤û§÷Ÿ(üÛ'™ghÕóÎôGÜqx5FË~6Èï6DÎí¬gŒz…¾w·nñSÏHtß…ÌÂÓT«Úè›æŒÅó¤˜sød@°1!P""WHA$Ÿ�›,d68Ñ“õˆ�k“tù\qXÞHŽ®R=�vÕîŸZ
+4
View File
@@ -6,4 +6,8 @@ in {
backupAgeKey
laptopHostKey
];
"epfl.age".publicKeys = [
backupAgeKey
laptopHostKey
];
}