diff --git a/nixos/doc/manual/from_md/release-notes/rl-2205.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2205.section.xml
index a57fd5186cbc..4b3eea55290e 100644
--- a/nixos/doc/manual/from_md/release-notes/rl-2205.section.xml
+++ b/nixos/doc/manual/from_md/release-notes/rl-2205.section.xml
@@ -81,6 +81,14 @@
services.maddy.
+
+
+ tetrd, share your
+ internet connection from your device to your PC and vice versa
+ through a USB cable. Available at
+ services.tetrd.
+
+
diff --git a/nixos/doc/manual/release-notes/rl-2205.section.md b/nixos/doc/manual/release-notes/rl-2205.section.md
index 804db667ecfb..b4caca17f720 100644
--- a/nixos/doc/manual/release-notes/rl-2205.section.md
+++ b/nixos/doc/manual/release-notes/rl-2205.section.md
@@ -27,6 +27,8 @@ In addition to numerous new and upgraded packages, this release has the followin
- [maddy](https://maddy.email), a composable all-in-one mail server. Available as [services.maddy](options.html#opt-services.maddy.enable).
+- [tetrd](https://tetrd.app), share your internet connection from your device to your PC and vice versa through a USB cable. Available at [services.tetrd](#opt-services.tetrd.enable).
+
## Backward Incompatibilities {#sec-release-22.05-incompatibilities}
- `pkgs.ghc` now refers to `pkgs.targetPackages.haskellPackages.ghc`.
diff --git a/nixos/modules/services/networking/tetrd.nix b/nixos/modules/services/networking/tetrd.nix
new file mode 100644
index 000000000000..ead73c497764
--- /dev/null
+++ b/nixos/modules/services/networking/tetrd.nix
@@ -0,0 +1,96 @@
+{ config, lib, pkgs, ... }:
+
+{
+ options.services.tetrd.enable = lib.mkEnableOption pkgs.tetrd.meta.description;
+
+ config = lib.mkIf config.services.tetrd.enable {
+ environment = {
+ systemPackages = [ pkgs.tetrd ];
+ etc."resolv.conf".source = "/etc/tetrd/resolv.conf";
+ };
+
+ systemd = {
+ tmpfiles.rules = [ "f /etc/tetrd/resolv.conf - - -" ];
+
+ services.tetrd = {
+ description = pkgs.tetrd.meta.description;
+ wantedBy = [ "multi-user.target" ];
+
+ serviceConfig = {
+ ExecStart = "${pkgs.tetrd}/opt/Tetrd/bin/tetrd";
+ Restart = "always";
+ RuntimeDirectory = "tetrd";
+ RootDirectory = "/run/tetrd";
+ DynamicUser = true;
+ UMask = "006";
+ DeviceAllow = "usb_device";
+ LockPersonality = true;
+ MemoryDenyWriteExecute = true;
+ NoNewPrivileges = true;
+ PrivateMounts = true;
+ PrivateNetwork = lib.mkDefault false;
+ PrivateTmp = true;
+ PrivateUsers = lib.mkDefault false;
+ ProtectClock = lib.mkDefault false;
+ ProtectControlGroups = true;
+ ProtectHome = true;
+ ProtectHostname = true;
+ ProtectKernelLogs = true;
+ ProtectKernelModules = true;
+ ProtectKernelTunables = true;
+ ProtectProc = "invisible";
+ ProtectSystem = "strict";
+ RemoveIPC = true;
+ RestrictAddressFamilies = [ "AF_UNIX" "AF_INET" "AF_INET6" "AF_NETLINK" ];
+ RestrictNamespaces = true;
+ RestrictRealtime = true;
+ RestrictSUIDSGID = true;
+ SystemCallArchitectures = "native";
+
+ SystemCallFilter = [
+ "@system-service"
+ "~@aio"
+ "~@chown"
+ "~@clock"
+ "~@cpu-emulation"
+ "~@debug"
+ "~@keyring"
+ "~@memlock"
+ "~@module"
+ "~@mount"
+ "~@obsolete"
+ "~@pkey"
+ "~@raw-io"
+ "~@reboot"
+ "~@swap"
+ "~@sync"
+ ];
+
+ BindReadOnlyPaths = [
+ builtins.storeDir
+ "/etc/ssl"
+ "/etc/static/ssl"
+ "${pkgs.nettools}/bin/route:/usr/bin/route"
+ "${pkgs.nettools}/bin/ifconfig:/usr/bin/ifconfig"
+ ];
+
+ BindPaths = [
+ "/etc/tetrd/resolv.conf:/etc/resolv.conf"
+ "/run"
+ "/var/log"
+ ];
+
+ CapabilityBoundingSet = [
+ "CAP_DAC_OVERRIDE"
+ "CAP_NET_ADMIN"
+ ];
+
+ AmbientCapabilities = [
+ "CAP_DAC_OVERRIDE"
+ "CAP_NET_ADMIN"
+ ];
+ };
+ };
+ };
+ };
+}