diff options
author | Gregor Kleen <gkleen@yggdrasil.li> | 2021-12-31 15:13:52 +0100 |
---|---|---|
committer | Gregor Kleen <gkleen@yggdrasil.li> | 2021-12-31 15:13:52 +0100 |
commit | f4301a77c9410f931c61b851bc5c1076d25dae80 (patch) | |
tree | 7245a5387860fe748c25aaf0a3569d1a5564a852 /hosts/vidhar/default.nix | |
parent | 80023979b3541bfb6881fe939dda0f9ed5a687b4 (diff) | |
download | nixos-f4301a77c9410f931c61b851bc5c1076d25dae80.tar nixos-f4301a77c9410f931c61b851bc5c1076d25dae80.tar.gz nixos-f4301a77c9410f931c61b851bc5c1076d25dae80.tar.bz2 nixos-f4301a77c9410f931c61b851bc5c1076d25dae80.tar.xz nixos-f4301a77c9410f931c61b851bc5c1076d25dae80.zip |
vidhar: ...
Diffstat (limited to 'hosts/vidhar/default.nix')
-rw-r--r-- | hosts/vidhar/default.nix | 334 |
1 files changed, 1 insertions, 333 deletions
diff --git a/hosts/vidhar/default.nix b/hosts/vidhar/default.nix index 933f5af9..a2764158 100644 --- a/hosts/vidhar/default.nix +++ b/hosts/vidhar/default.nix | |||
@@ -1,7 +1,7 @@ | |||
1 | { hostName, flake, config, pkgs, lib, ... }: | 1 | { hostName, flake, config, pkgs, lib, ... }: |
2 | { | 2 | { |
3 | imports = with flake.nixosModules.systemProfiles; [ | 3 | imports = with flake.nixosModules.systemProfiles; [ |
4 | ./zfs.nix ./dsl.nix | 4 | ./zfs.nix ./network.nix ./samba.nix ./dns.nix |
5 | initrd-all-crypto-modules default-locale openssh rebuild-machines | 5 | initrd-all-crypto-modules default-locale openssh rebuild-machines |
6 | build-server | 6 | build-server |
7 | initrd-ssh | 7 | initrd-ssh |
@@ -63,218 +63,6 @@ | |||
63 | options = [ "mode=0755" ]; | 63 | options = [ "mode=0755" ]; |
64 | }; | 64 | }; |
65 | }; | 65 | }; |
66 | |||
67 | networking = { | ||
68 | hostName = "vidhar"; | ||
69 | domain = "yggdrasil"; | ||
70 | search = [ "yggdrasil" ]; | ||
71 | |||
72 | useDHCP = false; | ||
73 | useNetworkd = true; | ||
74 | |||
75 | interfaces."lan" = { | ||
76 | ipv4.addresses = [ | ||
77 | { address = "10.141.0.1"; prefixLength = 24; } | ||
78 | ]; | ||
79 | }; | ||
80 | interfaces."mgmt" = { | ||
81 | ipv4.addresses = [ | ||
82 | { address = "10.141.1.1"; prefixLength = 24; } | ||
83 | ]; | ||
84 | }; | ||
85 | |||
86 | vlans = { | ||
87 | mgmt = { | ||
88 | id = 2; | ||
89 | interface = "eno2"; | ||
90 | }; | ||
91 | lan = { | ||
92 | id = 3; | ||
93 | interface = "eno2"; | ||
94 | }; | ||
95 | }; | ||
96 | |||
97 | firewall.enable = false; | ||
98 | nftables = { | ||
99 | enable = true; | ||
100 | rulesetFile = ./ruleset.nft; | ||
101 | }; | ||
102 | }; | ||
103 | |||
104 | services.resolved = { | ||
105 | llmnr = "false"; | ||
106 | }; | ||
107 | |||
108 | services.dhcpd4 = { | ||
109 | enable = true; | ||
110 | interfaces = [ "lan" "mgmt" ]; | ||
111 | extraConfig = '' | ||
112 | subnet 10.141.0.0 netmask 255.255.255.0 { | ||
113 | range 10.141.0.128 10.141.0.254; | ||
114 | option domain-name-servers 10.141.0.1; | ||
115 | option broadcast-address 10.141.0.255; | ||
116 | option routers 10.141.0.1; | ||
117 | option domain-name "yggdrasil"; | ||
118 | } | ||
119 | |||
120 | subnet 10.141.1.0 netmask 255.255.255.0 { | ||
121 | range 10.141.1.128 10.141.1.254; | ||
122 | } | ||
123 | ''; | ||
124 | machines = [ | ||
125 | { | ||
126 | ethernetAddress = "50:d4:f7:f3:0f:7e"; | ||
127 | hostName = "gauss-ap01"; | ||
128 | ipAddress = "10.141.0.64"; | ||
129 | } | ||
130 | { | ||
131 | ethernetAddress = "60:a4:b7:53:94:b5"; | ||
132 | hostName = "switch01"; | ||
133 | ipAddress = "10.141.1.2"; | ||
134 | } | ||
135 | ]; | ||
136 | }; | ||
137 | services.corerad = { | ||
138 | enable = true; | ||
139 | settings = { | ||
140 | interfaces = [ | ||
141 | { name = config.networking.pppInterface; | ||
142 | monitor = true; | ||
143 | verbose = true; | ||
144 | } | ||
145 | { name = "lan"; | ||
146 | advertise = true; | ||
147 | verbose = true; | ||
148 | prefix = [{ prefix = "::/64"; }]; | ||
149 | route = [{ prefix = "::/0"; }]; | ||
150 | rdnss = [{ servers = ["::"]; }]; | ||
151 | dnssl = [{ domain_names = ["yggdrasil"]; }]; | ||
152 | } | ||
153 | ]; | ||
154 | }; | ||
155 | }; | ||
156 | services.ndppd = { | ||
157 | enable = true; | ||
158 | proxies = { | ||
159 | ${config.networking.pppInterface} = { | ||
160 | router = true; | ||
161 | rules.lan = { | ||
162 | method = "iface"; | ||
163 | interface = "lan"; | ||
164 | network = "::/0"; | ||
165 | }; | ||
166 | }; | ||
167 | }; | ||
168 | }; | ||
169 | boot.kernel.sysctl = { | ||
170 | "net.ipv6.conf.all.forwarding" = true; | ||
171 | "net.ipv6.conf.default.forwarding" = true; | ||
172 | "net.ipv4.conf.all.forwarding" = true; | ||
173 | "net.ipv4.conf.default.forwarding" = true; | ||
174 | |||
175 | "net.core.rmem_max" = "4194304"; | ||
176 | "net.core.wmem_max" = "4194304"; | ||
177 | }; | ||
178 | systemd.network.networks = { | ||
179 | "eno2" = { | ||
180 | matchConfig.Name = "eno2"; | ||
181 | networkConfig.LinkLocalAddressing = "no"; | ||
182 | }; | ||
183 | "telekom" = { | ||
184 | matchConfig.Name = "telekom"; | ||
185 | networkConfig.LinkLocalAddressing = "no"; | ||
186 | }; | ||
187 | }; | ||
188 | systemd.services."pppd-telekom" = { | ||
189 | bindsTo = [ "sys-subsystem-net-devices-telekom.device" ]; | ||
190 | after = [ "sys-subsystem-net-devices-telekom.device" ]; | ||
191 | }; | ||
192 | systemd.services."dhcpcd-telekom" = { | ||
193 | wantedBy = [ "multi-user.target" "network-online.target" "pppd-telekom.service" ]; | ||
194 | bindsTo = [ "pppd-telekom.service" "sys-subsystem-net-devices-dsl.device" ]; | ||
195 | after = [ "pppd-telekom.service" "sys-subsystem-net-devices-dsl.device" ]; | ||
196 | wants = [ "network.target" ]; | ||
197 | before = [ "network-online.target" ]; | ||
198 | |||
199 | path = with pkgs; [ dhcpcd nettools openresolv ]; | ||
200 | unitConfig.ConditionCapability = "CAP_NET_ADMIN"; | ||
201 | |||
202 | stopIfChanged = false; | ||
203 | |||
204 | preStart = '' | ||
205 | i=0 | ||
206 | |||
207 | while [[ -z "$(${pkgs.iproute2}/bin/ip -6 addr show dev ${config.networking.pppInterface} scope link)" ]]; do | ||
208 | ${pkgs.coreutils}/bin/sleep 0.1 | ||
209 | i=$((i + 1)) | ||
210 | if [[ "$i" -ge 10 ]]; then | ||
211 | exit 1 | ||
212 | fi | ||
213 | done | ||
214 | ''; | ||
215 | |||
216 | serviceConfig = let | ||
217 | dhcpcdConf = pkgs.writeText "dhcpcd.conf" '' | ||
218 | duid | ||
219 | vendorclassid | ||
220 | ipv6only | ||
221 | |||
222 | nooption domain_name_servers, domain_name, domain_search | ||
223 | option classless_static_routes | ||
224 | option interface_mtu | ||
225 | |||
226 | option host_name | ||
227 | option rapid_commit | ||
228 | require dhcp_server_identifier | ||
229 | slaac private | ||
230 | |||
231 | noipv6rs # disable routing solicitation | ||
232 | nohook resolv.conf | ||
233 | allowinterfaces dsl | ||
234 | interface dsl | ||
235 | ipv6ra_autoconf | ||
236 | iaid 1195061668 | ||
237 | ipv6rs # enable routing solicitation for WAN adapter | ||
238 | ia_pd 1 lan/0/64/0 # request a PD and assign it to the LAN | ||
239 | |||
240 | waitip 6 | ||
241 | ''; | ||
242 | in { | ||
243 | Type = "forking"; | ||
244 | PIDFile = "/run/dhcpcd/pid"; | ||
245 | RuntimeDirectory = "dhcpcd"; | ||
246 | ExecStart = "@${pkgs.dhcpcd}/sbin/dhcpcd dhcpcd -q --config ${dhcpcdConf}"; | ||
247 | ExecReload = "${pkgs.dhcpcd}/sbin/dhcpcd --rebind"; | ||
248 | Restart = "always"; | ||
249 | RestartSec = "5"; | ||
250 | }; | ||
251 | }; | ||
252 | systemd.services.ndppd = { | ||
253 | wantedBy = [ "dhcpcd-telekom.service" ]; | ||
254 | bindsTo = [ "dhcpcd-telekom.service" ]; | ||
255 | after = [ "dhcpcd-telekom.service" ]; | ||
256 | |||
257 | serviceConfig = { | ||
258 | Restart = "always"; | ||
259 | RestartSec = "5"; | ||
260 | }; | ||
261 | }; | ||
262 | systemd.services.corerad = { | ||
263 | wantedBy = [ "dhcpcd-telekom.service" ]; | ||
264 | bindsTo = [ "dhcpcd-telekom.service" ]; | ||
265 | after = [ "dhcpcd-telekom.service" ]; | ||
266 | |||
267 | serviceConfig = { | ||
268 | Restart = lib.mkForce "always"; | ||
269 | RestartSec = "5"; | ||
270 | }; | ||
271 | }; | ||
272 | systemd.services."systemd-networkd".stopIfChanged = false; | ||
273 | users.users.dhcpcd = { | ||
274 | isSystemUser = true; | ||
275 | group = "dhcpcd"; | ||
276 | }; | ||
277 | users.groups.dhcpcd = {}; | ||
278 | 66 | ||
279 | services.timesyncd.enable = false; | 67 | services.timesyncd.enable = false; |
280 | services.chrony = { | 68 | services.chrony = { |
@@ -331,125 +119,5 @@ | |||
331 | 119 | ||
332 | cpuFreqGovernor = "schedutil"; | 120 | cpuFreqGovernor = "schedutil"; |
333 | }; | 121 | }; |
334 | |||
335 | services.unbound = { | ||
336 | enable = true; | ||
337 | resolveLocalQueries = false; | ||
338 | stateDir = "/var/lib/unbound"; | ||
339 | localControlSocketPath = "/run/unbound/unbound.ctl"; | ||
340 | settings = { | ||
341 | server = { | ||
342 | interface = ["127.0.0.1" "10.141.0.1" "::0"]; | ||
343 | access-control = ["0.0.0.0/0 allow" "::/0 allow"]; | ||
344 | root-hints = "${pkgs.dns-root-data}/root.hints"; | ||
345 | |||
346 | num-threads = 12; | ||
347 | so-reuseport = true; | ||
348 | msg-cache-slabs = 16; | ||
349 | rrset-cache-slabs = 16; | ||
350 | infra-cache-slabs = 16; | ||
351 | key-cache-slabs = 16; | ||
352 | |||
353 | rrset-cache-size = "100m"; | ||
354 | msg-cache-size = "50m"; | ||
355 | outgoing-range = 8192; | ||
356 | num-queries-per-thread = 4096; | ||
357 | |||
358 | so-rcvbuf = "4m"; | ||
359 | so-sndbuf = "4m"; | ||
360 | |||
361 | serve-expired = true; | ||
362 | serve-expired-ttl = 86400; | ||
363 | serve-expired-reply-ttl = 0; | ||
364 | |||
365 | prefetch = true; | ||
366 | prefetch-key = true; | ||
367 | |||
368 | minimal-responses = false; | ||
369 | |||
370 | extended-statistics = true; | ||
371 | |||
372 | rrset-roundrobin = true; | ||
373 | use-caps-for-id = true; | ||
374 | }; | ||
375 | }; | ||
376 | }; | ||
377 | |||
378 | services.samba = { | ||
379 | enable = true; | ||
380 | securityType = "user"; | ||
381 | extraConfig = '' | ||
382 | domain master = yes | ||
383 | workgroup = WORKGROUP | ||
384 | load printers = no | ||
385 | printing = bsd | ||
386 | printcap name = /dev/null | ||
387 | disable spoolss = yes | ||
388 | guest account = nobody | ||
389 | bind interfaces only = yes | ||
390 | interfaces = lo lan | ||
391 | ''; | ||
392 | shares = { | ||
393 | homes = { | ||
394 | comment = "Home Directories"; | ||
395 | path = "/home/%S"; | ||
396 | browseable = "no"; | ||
397 | "valid users" = "%S"; | ||
398 | "read only" = "no"; | ||
399 | "create mask" = "0700"; | ||
400 | "directory mask" = "0700"; | ||
401 | "vfs objects" = "shadow_copy2"; | ||
402 | "shadow:snapdir" = ".zfs/snapshot"; | ||
403 | "shadow:sort" = "desc"; | ||
404 | "shadow:format" = "%Y-%m-%d-%Hh%MU"; | ||
405 | "shadow:snapprefix" = "^zfs-auto-snap_\(frequent\)\{0,1\}\(hourly\)\{0,1\}\(daily\)\{0,1\}\(monthly\)\{0,1\}"; | ||
406 | "shadow:delimiter" = "-"; | ||
407 | }; | ||
408 | eos = { | ||
409 | comment = "Disk image of eos"; | ||
410 | browseable = true; | ||
411 | "valid users" = "mherold"; | ||
412 | writeable = "true"; | ||
413 | path = "/srv/eos"; | ||
414 | }; | ||
415 | }; | ||
416 | }; | ||
417 | services.samba-wsdd = { | ||
418 | enable = true; | ||
419 | workgroup = "WORKGROUP"; | ||
420 | interface = [ "lo" "lan" ]; | ||
421 | }; | ||
422 | |||
423 | fileSystems."/srv/eos.lower" = { | ||
424 | device = "/dev/zvol/hdd-raid6/safe/home/mherold/eos/base"; | ||
425 | fsType = "ntfs3"; | ||
426 | options = [ "ro" "uid=mherold" "gid=users" "fmask=0177" "dmask=0077" "nofail" "noauto" ]; | ||
427 | }; | ||
428 | |||
429 | fileSystems."/srv/eos.upper" = { | ||
430 | device = "/dev/zvol/hdd-raid6/safe/home/mherold/eos/upper"; | ||
431 | fsType = "ext4"; | ||
432 | options = [ "nofail" "noauto" ]; | ||
433 | }; | ||
434 | |||
435 | systemd.mounts = [ | ||
436 | { | ||
437 | wantedBy = [ "samba-smbd.service" ]; | ||
438 | before = [ "samba-smbd.service" ]; | ||
439 | |||
440 | where = "/srv/eos"; | ||
441 | what = "overlay"; | ||
442 | type = "overlay"; | ||
443 | options = lib.concatStringsSep "," | ||
444 | [ "lowerdir=/srv/eos.lower" | ||
445 | "upperdir=/srv/eos.upper/upper" | ||
446 | "workdir=/srv/eos.upper/work" | ||
447 | ]; | ||
448 | |||
449 | unitConfig = { | ||
450 | RequiresMountsFor = [ "/srv/eos.lower" "/srv/eos.upper" ]; | ||
451 | }; | ||
452 | } | ||
453 | ]; | ||
454 | }; | 122 | }; |
455 | } | 123 | } |