gateway
The gateway host uses tailscale. knixl writes one file for it. The Nix below is the golden test output, so it is exactly what knixl emits.
host "gateway" { system "x86_64-linux"
tailscale { open-firewall #true up-flag "--ssh" auth-key secret="tailscale-authkey" }}Generated
Section titled “Generated”# Generated by knixl 1.5.2 from hosts/gateway.kdl# Do NOT edit. Regenerate from the KDL source.# Overrides: add a sibling module and use lib.mkForce / lib.mkAfter.{ config, lib, pkgs, ...}:{ nixpkgs.hostPlatform = "x86_64-linux"; networking.hostName = "gateway"; services.tailscale.enable = true; services.tailscale.openFirewall = true; services.tailscale.extraUpFlags = [ "--ssh" ]; services.tailscale.authKeyFile = config.sops.secrets."tailscale-authkey".path;}