feat(networking): enable useNetworkd option for static IP configuration
This commit is contained in:
1 parent
40f0dc0d45
commit
2ecc910de4
2 files changed
+81
-55
No files matched your search
@@ -14,6 +14,7 @@
|
|||||||
myNetworking = {
|
myNetworking = {
|
||||||
hostName = "vps";
|
hostName = "vps";
|
||||||
useNetworkManager = false;
|
useNetworkManager = false;
|
||||||
|
useNetworkd = true;
|
||||||
staticIp = {
|
staticIp = {
|
||||||
interface = "ens3";
|
interface = "ens3";
|
||||||
address = "23.175.41.196";
|
address = "23.175.41.196";
|
||||||
|
|||||||
@@ -39,6 +39,12 @@ in
|
|||||||
description = "Whether to enable NetworkManager to manage network interfaces.";
|
description = "Whether to enable NetworkManager to manage network interfaces.";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
useNetworkd = lib.mkOption {
|
||||||
|
type = lib.types.bool;
|
||||||
|
default = false;
|
||||||
|
description = "Whether to configure the static IP via systemd-networkd instead of the classic scripted networking backend. Needed for reliable onlink default routes.";
|
||||||
|
};
|
||||||
|
|
||||||
staticIp = lib.mkOption {
|
staticIp = lib.mkOption {
|
||||||
type = lib.types.nullOr (lib.types.submodule {
|
type = lib.types.nullOr (lib.types.submodule {
|
||||||
options = {
|
options = {
|
||||||
@@ -121,62 +127,81 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
config = {
|
config = lib.mkMerge [
|
||||||
networking = lib.mkMerge [
|
{
|
||||||
{
|
networking = lib.mkMerge [
|
||||||
hostName = cfg.hostName;
|
{
|
||||||
networkmanager.enable = cfg.useNetworkManager;
|
hostName = cfg.hostName;
|
||||||
firewall = {
|
networkmanager.enable = cfg.useNetworkManager;
|
||||||
enable = true;
|
firewall = {
|
||||||
allowedUDPPorts = [ config.services.tailscale.port ] ++ cfg.extraUdpPorts;
|
enable = true;
|
||||||
allowedTCPPorts = [ 22 ] ++ cfg.extraTcpPorts;
|
allowedUDPPorts = [ config.services.tailscale.port ] ++ cfg.extraUdpPorts;
|
||||||
};
|
allowedTCPPorts = [ 22 ] ++ cfg.extraTcpPorts;
|
||||||
}
|
};
|
||||||
(lib.mkIf (cfg.staticIp != null) {
|
}
|
||||||
useDHCP = false;
|
(lib.mkIf (cfg.staticIp != null && !cfg.useNetworkd) {
|
||||||
interfaces.${cfg.staticIp.interface}.ipv4.addresses = [{
|
useDHCP = false;
|
||||||
address = cfg.staticIp.address;
|
interfaces.${cfg.staticIp.interface}.ipv4.addresses = [{
|
||||||
prefixLength = cfg.staticIp.prefixLength;
|
address = cfg.staticIp.address;
|
||||||
}];
|
prefixLength = cfg.staticIp.prefixLength;
|
||||||
nameservers = cfg.staticIp.nameservers;
|
}];
|
||||||
})
|
nameservers = cfg.staticIp.nameservers;
|
||||||
(lib.mkIf (cfg.staticIp != null && !cfg.staticIp.onlinkGateway) {
|
})
|
||||||
defaultGateway = cfg.staticIp.gateway;
|
(lib.mkIf (cfg.staticIp != null && !cfg.useNetworkd && !cfg.staticIp.onlinkGateway) {
|
||||||
})
|
defaultGateway = cfg.staticIp.gateway;
|
||||||
(lib.mkIf (cfg.staticIp != null && cfg.staticIp.onlinkGateway) {
|
})
|
||||||
interfaces.${cfg.staticIp.interface}.ipv4.routes = [{
|
(lib.mkIf cfg.wireguard.enable {
|
||||||
address = "0.0.0.0";
|
wireguard.interfaces."wg-${cfg.hostName}" = {
|
||||||
prefixLength = 0;
|
ips = cfg.wireguard.ips;
|
||||||
via = cfg.staticIp.gateway;
|
privateKeyFile = cfg.wireguard.privateKeyFile;
|
||||||
options.onlink = "true";
|
listenPort = cfg.wireguard.listenPort;
|
||||||
}];
|
peers = map (peer: {
|
||||||
})
|
inherit (peer) publicKey allowedIPs;
|
||||||
(lib.mkIf cfg.wireguard.enable {
|
} // lib.optionalAttrs (peer.endpoint != null) {
|
||||||
wireguard.interfaces."wg-${cfg.hostName}" = {
|
inherit (peer) endpoint;
|
||||||
ips = cfg.wireguard.ips;
|
} // lib.optionalAttrs (peer.persistentKeepalive != null) {
|
||||||
privateKeyFile = cfg.wireguard.privateKeyFile;
|
inherit (peer) persistentKeepalive;
|
||||||
listenPort = cfg.wireguard.listenPort;
|
}) cfg.wireguard.peers;
|
||||||
peers = map (peer: {
|
};
|
||||||
inherit (peer) publicKey allowedIPs;
|
})
|
||||||
} // lib.optionalAttrs (peer.endpoint != null) {
|
];
|
||||||
inherit (peer) endpoint;
|
|
||||||
} // lib.optionalAttrs (peer.persistentKeepalive != null) {
|
|
||||||
inherit (peer) persistentKeepalive;
|
|
||||||
}) cfg.wireguard.peers;
|
|
||||||
};
|
|
||||||
})
|
|
||||||
];
|
|
||||||
|
|
||||||
services.tailscale.enable = true;
|
services.tailscale.enable = true;
|
||||||
|
|
||||||
services.openssh = {
|
services.openssh = {
|
||||||
enable = true;
|
enable = true;
|
||||||
settings = {
|
settings = {
|
||||||
PermitRootLogin = "no";
|
PermitRootLogin = "no";
|
||||||
PasswordAuthentication = false;
|
PasswordAuthentication = false;
|
||||||
} // lib.optionalAttrs (cfg.sshAllowUsers != [ ]) {
|
} // lib.optionalAttrs (cfg.sshAllowUsers != [ ]) {
|
||||||
AllowUsers = cfg.sshAllowUsers;
|
AllowUsers = cfg.sshAllowUsers;
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
}
|
||||||
};
|
|
||||||
|
(lib.mkIf (cfg.staticIp != null && cfg.useNetworkd) {
|
||||||
|
networking.useDHCP = false;
|
||||||
|
systemd.network.enable = true;
|
||||||
|
services.resolved.enable = true;
|
||||||
|
|
||||||
|
systemd.network.networks."10-${cfg.staticIp.interface}" = {
|
||||||
|
matchConfig.Name = cfg.staticIp.interface;
|
||||||
|
address = [ "${cfg.staticIp.address}/${toString cfg.staticIp.prefixLength}" ];
|
||||||
|
dns = cfg.staticIp.nameservers;
|
||||||
|
routes = [
|
||||||
|
({
|
||||||
|
routeConfig = {
|
||||||
|
Gateway = cfg.staticIp.gateway;
|
||||||
|
} // lib.optionalAttrs cfg.staticIp.onlinkGateway {
|
||||||
|
GatewayOnLink = true;
|
||||||
|
};
|
||||||
|
})
|
||||||
|
];
|
||||||
|
networkConfig = {
|
||||||
|
DHCP = "no";
|
||||||
|
};
|
||||||
|
linkConfig.RequiredForOnline = "routable";
|
||||||
|
};
|
||||||
|
})
|
||||||
|
];
|
||||||
}
|
}
|
||||||
Reference in new issue
Block a user