diff --git a/hosts/vps/default.nix b/hosts/vps/default.nix index 618cf2b..e23fd51 100644 --- a/hosts/vps/default.nix +++ b/hosts/vps/default.nix @@ -5,6 +5,7 @@ ./hardware-configuration.nix ../../modules/profiles/server.nix ../../modules/system/home-profile.nix + ../../modules/system/nix-ld.nix ../../modules/system/packages.nix ]; @@ -19,7 +20,9 @@ prefixLength = 27; gateway = "23.175.41.225"; nameservers = [ "1.1.1.1" "1.0.0.1" ]; + onlinkGateway = true; }; + extraTcpPorts = [ 80 443 ]; extraUdpPorts = [ 51822 ]; sshAllowUsers = [ "emmatherock" ]; diff --git a/modules/system/networking.nix b/modules/system/networking.nix index 0e5fc83..2771333 100644 --- a/modules/system/networking.nix +++ b/modules/system/networking.nix @@ -63,6 +63,11 @@ in default = [ "1.1.1.1" "8.8.8.8" ]; description = "DNS nameservers to use."; }; + onlinkGateway = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether the gateway lies outside the interface's subnet, requiring the onlink flag on the default route."; + }; }; }); default = null; @@ -133,9 +138,19 @@ in address = cfg.staticIp.address; prefixLength = cfg.staticIp.prefixLength; }]; - defaultGateway = cfg.staticIp.gateway; nameservers = cfg.staticIp.nameservers; }) + (lib.mkIf (cfg.staticIp != null && !cfg.staticIp.onlinkGateway) { + defaultGateway = cfg.staticIp.gateway; + }) + (lib.mkIf (cfg.staticIp != null && cfg.staticIp.onlinkGateway) { + interfaces.${cfg.staticIp.interface}.ipv4.routes = [{ + address = "0.0.0.0"; + prefixLength = 0; + via = cfg.staticIp.gateway; + options.onlink = "true"; + }]; + }) (lib.mkIf cfg.wireguard.enable { wireguard.interfaces."wg-${cfg.hostName}" = { ips = cfg.wireguard.ips;