{...}: let ports = import ../data/ports.nix {}; internal_wireguard = import ../../../../../data/chaos_wireguard_internal.nix {}; in { services.cockroachdb = { enable = true; certsDir = "/var/lib/cockroachdb-certs"; join = "localhost:${toString ports.cockroachdb},${internal_wireguard.hosts.raspberry.ip}:26257"; # ssh -L 3014:127.0.0.1:3014 -L 26257:127.0.0.1:26257 hetzner-vm listen.port = ports.cockroachdb; http = { address = "0.0.0.0"; port = ports.cockroachdb-http; }; }; }