···1414 # See https://tailscale.com/kb/1081/magicdns/ for more details
1515 magicDns = true;
1616 # I inject DNS.sb as my secondary nameserver, and my adblocking server as primary.
1717- nameservers = ["45.11.45.11"];
1717+ nameservers = [ "45.11.45.11" ];
1818 # Domains to inject, so I can type "media/" into my search bar and go to "media.main.hog"
1919 # You can't tell headscale to not create a namespace, so this is the best that I can do
2020- domains = ["main.hog"];
2020+ domains = [ "main.hog" ];
2121 };
2222 # Automatic TLS
2323 tls = {
···4747 # oidc.strip_email_domain = true;
4848 # NixOS handles our updates
4949 disable_check_updates = true;
5050- ip_prefixes = ["4349:3909:beef::/48" "100.64.0.0/10"];
5050+ ip_prefixes = [
5151+ "4349:3909:beef::/48"
5252+ "100.64.0.0/10"
5353+ ];
5154 derp = {
5255 server = {
5356 enabled = true;
···5962 };
6063 };
6164 };
6262- systemd.services.headscale.serviceConfig.CapabilityBoundingSet = ["CAP_CHOWN" "CAP_NET_BIND_SERVICE"];
6363- systemd.services.headscale.serviceConfig.AmbientCapabilities = ["CAP_CHOWN" "CAP_NET_BIND_SERVICE"];
6565+ systemd.services.headscale.serviceConfig.CapabilityBoundingSet = [
6666+ "CAP_CHOWN"
6767+ "CAP_NET_BIND_SERVICE"
6868+ ];
6969+ systemd.services.headscale.serviceConfig.AmbientCapabilities = [
7070+ "CAP_CHOWN"
7171+ "CAP_NET_BIND_SERVICE"
7272+ ];
6473}