diff --git a/nix/modules/hosts/nixos/jubilife/containers.nix b/nix/modules/hosts/nixos/jubilife/containers.nix index 6bea0ea1..34983637 100644 --- a/nix/modules/hosts/nixos/jubilife/containers.nix +++ b/nix/modules/hosts/nixos/jubilife/containers.nix @@ -261,7 +261,7 @@ _: { MAIL_FROM_ADDRESS = "admin"; OBJECTSTORE_S3_AUTOCREATE = "false"; OBJECTSTORE_S3_BUCKET = "aly-nextcloud"; - OBJECTSTORE_S3_HOST = "10.254.0.1"; + OBJECTSTORE_S3_HOST = "host.docker.internal"; OBJECTSTORE_S3_PORT = "3900"; OBJECTSTORE_S3_REGION = "garage"; OBJECTSTORE_S3_SSL = "false"; @@ -286,7 +286,10 @@ _: { NEXTCLOUD_TRUSTED_DOMAINS = "nextcloud.cute.haus"; }; environmentFiles = [config.sops.templates.nextcloud-environment.path]; - extraOptions = ["--memory=4g"]; + extraOptions = [ + "--add-host=host.docker.internal:172.19.0.1" + "--memory=4g" + ]; ports = ["10.254.0.1:8081:80"]; volumes = ["/mnt/Data/nextcloud/html:/var/www/html"]; }; @@ -304,7 +307,10 @@ _: { REDIS_HOST_PORT = "6379"; }; environmentFiles = [config.sops.templates.nextcloud-environment.path]; - extraOptions = ["--user=33:33"]; + extraOptions = [ + "--add-host=host.docker.internal:172.19.0.1" + "--user=33:33" + ]; volumes = ["/mnt/Data/nextcloud/html:/var/www/html"]; }; }; @@ -355,7 +361,7 @@ _: { ]; path = [pkgs.docker]; - script = "docker network inspect nextcloud >/dev/null 2>&1 || docker network create nextcloud"; + script = "docker network inspect nextcloud >/dev/null 2>&1 || docker network create --driver bridge --subnet 172.19.0.0/16 --opt com.docker.network.bridge.name=nextcloud0 nextcloud"; serviceConfig = { Type = "oneshot"; RemainAfterExit = true; @@ -402,6 +408,10 @@ _: { echo "Nextcloud database host is neither the cluster nor local PostgreSQL" >&2 exit 1 fi + + ${pkgs.gnused}/bin/sed -i \ + "s/10\\.254\\.0\\.1/host.docker.internal/g" \ + "$config_file" ''; unitConfig = { ConditionPathExists = "/mnt/Data/nextcloud/.local-postgres-ready"; diff --git a/nix/modules/hosts/nixos/jubilife/firewall.nix b/nix/modules/hosts/nixos/jubilife/firewall.nix index 3574e037..c14bb284 100644 --- a/nix/modules/hosts/nixos/jubilife/firewall.nix +++ b/nix/modules/hosts/nixos/jubilife/firewall.nix @@ -8,6 +8,7 @@ _: { -s 10.42.0.0/16 -p tcp --dport 2049 -j ACCEPT -s 10.42.0.0/16 -p udp --dport 2049 -j ACCEPT ''; + interfaces.nextcloud0.allowedTCPPorts = [3900]; }; }; } diff --git a/nix/modules/hosts/nixos/jubilife/garage.nix b/nix/modules/hosts/nixos/jubilife/garage.nix index d6c79658..43209d8a 100644 --- a/nix/modules/hosts/nixos/jubilife/garage.nix +++ b/nix/modules/hosts/nixos/jubilife/garage.nix @@ -32,6 +32,7 @@ _: { owner = "garage"; group = "garage"; mode = "0400"; + restartUnits = ["garage.service"]; content = '' metadata_dir = "${dataDirectory}/garage/meta" data_dir = "${dataDirectory}/garage/data" @@ -42,7 +43,8 @@ _: { rpc_secret = "${config.sops.placeholder.garageRpcSecret}" [s3_api] - api_bind_addr = "10.254.0.1:3900" + # The firewall limits S3 access to k3s and the local Nextcloud network. + api_bind_addr = "[::]:3900" s3_region = "garage" ''; };