diff --git a/modules/nixos/hardware/cloud/default.nix b/modules/nixos/hardware/cloud/default.nix index 0303e9d5..1650d933 100644 --- a/modules/nixos/hardware/cloud/default.nix +++ b/modules/nixos/hardware/cloud/default.nix @@ -2,9 +2,9 @@ imports = [ # keep-sorted start ./hetzner - ./oracle.nix + ./oracle ./overrides.nix - ./upcloud.nix + ./upcloud # keep-sorted end ]; } diff --git a/modules/nixos/hardware/cloud/hetzner/networking.nix b/modules/nixos/hardware/cloud/hetzner/networking.nix index 9735fd51..275ab803 100644 --- a/modules/nixos/hardware/cloud/hetzner/networking.nix +++ b/modules/nixos/hardware/cloud/hetzner/networking.nix @@ -50,6 +50,10 @@ in dhcpcd.enable = mkForce false; usePredictableInterfaceNames = mkForce false; + # since we are statically configuring networking we can drop + # network manager + networkmanager.enable = mkForce false; + interfaces = { eth0 = { ipv4 = { diff --git a/modules/nixos/hardware/cloud/oracle/default.nix b/modules/nixos/hardware/cloud/oracle/default.nix new file mode 100644 index 00000000..a510b8a0 --- /dev/null +++ b/modules/nixos/hardware/cloud/oracle/default.nix @@ -0,0 +1,8 @@ +{ + imports = [ + # keep-sorted start + ./garden.nix + ./networking.nix + # keep-sorted end + ]; +} diff --git a/modules/nixos/hardware/cloud/oracle.nix b/modules/nixos/hardware/cloud/oracle/garden.nix similarity index 100% rename from modules/nixos/hardware/cloud/oracle.nix rename to modules/nixos/hardware/cloud/oracle/garden.nix diff --git a/modules/nixos/hardware/cloud/oracle/networking.nix b/modules/nixos/hardware/cloud/oracle/networking.nix new file mode 100644 index 00000000..92d39055 --- /dev/null +++ b/modules/nixos/hardware/cloud/oracle/networking.nix @@ -0,0 +1,84 @@ +{ lib, config, ... }: +let + inherit (lib.modules) mkIf mkForce; + inherit (lib.options) mkOption; + inherit (lib.types) str; + + cfg = config.garden.profiles.oracle; +in +{ + options.garden.profiles.oracle = { + ipv4 = mkOption { + type = str; + description = '' + The private IPv4 address to assign to the vnic. + Oracle NATs the public address to this, so it is never seen by the os. + ''; + }; + + ipv6 = mkOption { + type = str; + description = '' + The IPv6 address to assign to the vnic. + Oracle hands this out as a /128 over dhcpv6. + ''; + }; + }; + + # + config = mkIf cfg.enable { + networking = { + networkmanager.enable = mkForce false; + + nameservers = [ "169.254.169.254" ]; + search = [ "vcn04081257.oraclevcn.com" ]; + + defaultGateway = { + address = "10.0.0.1"; + interface = "eth0"; + }; + + defaultGateway6 = { + address = "fe80::200:17ff:feb0:5c74"; + interface = "eth0"; + }; + + interfaces.eth0 = { + mtu = 9000; + + ipv4 = { + addresses = [ + { + address = cfg.ipv4; + prefixLength = 24; + } + ]; + + # the resolver sits on a link local address, so it needs a route + routes = [ + { + address = "169.254.0.0"; + prefixLength = 16; + } + ]; + }; + + ipv6 = { + addresses = [ + { + address = cfg.ipv6; + prefixLength = 128; + } + ]; + + routes = [ + { + address = "2603:c020:c011:9c00::"; + prefixLength = 64; + } + ]; + }; + }; + }; + }; +} diff --git a/modules/nixos/hardware/cloud/upcloud/default.nix b/modules/nixos/hardware/cloud/upcloud/default.nix new file mode 100644 index 00000000..a510b8a0 --- /dev/null +++ b/modules/nixos/hardware/cloud/upcloud/default.nix @@ -0,0 +1,8 @@ +{ + imports = [ + # keep-sorted start + ./garden.nix + ./networking.nix + # keep-sorted end + ]; +} diff --git a/modules/nixos/hardware/cloud/upcloud.nix b/modules/nixos/hardware/cloud/upcloud/garden.nix similarity index 100% rename from modules/nixos/hardware/cloud/upcloud.nix rename to modules/nixos/hardware/cloud/upcloud/garden.nix diff --git a/modules/nixos/hardware/cloud/upcloud/networking.nix b/modules/nixos/hardware/cloud/upcloud/networking.nix new file mode 100644 index 00000000..34ed618c --- /dev/null +++ b/modules/nixos/hardware/cloud/upcloud/networking.nix @@ -0,0 +1,44 @@ +{ lib, config, ... }: +let + inherit (lib.modules) mkIf mkForce; +in +{ + # + config = mkIf config.garden.profiles.upcloud.enable { + networking.networkmanager.enable = mkForce false; + + systemd.network.networks = { + "10-eth0" = { + matchConfig.Name = "eth0"; + + networkConfig = { + DHCP = "ipv4"; + IPv6AcceptRA = false; + }; + + linkConfig.RequiredForOnline = "routable"; + }; + + "20-eth1" = { + matchConfig.Name = "eth1"; + + networkConfig = { + DHCP = "ipv4"; + IPv6AcceptRA = false; + }; + + dhcpV4Config.UseGateway = false; + + linkConfig.RequiredForOnline = "no"; + }; + + "30-eth2" = { + matchConfig.Name = "eth2"; + + networkConfig.IPv6AcceptRA = true; + + linkConfig.RequiredForOnline = "no"; + }; + }; + }; +} diff --git a/systems/skadi/default.nix b/systems/skadi/default.nix index 2f3ff8ac..0f262a55 100644 --- a/systems/skadi/default.nix +++ b/systems/skadi/default.nix @@ -5,7 +5,13 @@ profiles = { headless.enable = true; server.enable = true; - oracle.enable = true; + + oracle = { + enable = true; + + ipv4 = "10.0.0.11"; + ipv6 = "2603:c020:c011:9c00:0:c069:1ff7:1ff3"; + }; }; device = {