From 271e8b069ee8bb69655ca4a3d53f7ee0588e733a Mon Sep 17 00:00:00 2001 From: Noah Pederson Date: Fri, 2 Jan 2026 22:43:31 -0600 Subject: [PATCH] Make nftables optional --- flake.nix | 5 +++-- services.nix | 17 +++++++++-------- 2 files changed, 12 insertions(+), 10 deletions(-) diff --git a/flake.nix b/flake.nix index 8112f8c..277b74a 100644 --- a/flake.nix +++ b/flake.nix @@ -54,12 +54,12 @@ unstable ? false, extraGroups ? [ ], overlays ? [ ], - ... + enableNFTables ? true, }: inputs.nixpkgs.lib.nixosSystem { inherit system; specialArgs = { - inherit inputs extraGroups; + inherit inputs extraGroups enableNFTables; } // nixpkgs.lib.optionalAttrs unstable { unstable = import nixpkgs-unstable { @@ -145,6 +145,7 @@ ./host-specific/touma-wsl.nix nixos-wsl.nixosModules.default ]; + enableNFTables = false; }; nixosConfigurations.edge = basicSystem { unstable = true; diff --git a/services.nix b/services.nix index 1eee565..1527451 100644 --- a/services.nix +++ b/services.nix @@ -1,4 +1,4 @@ -{ ... }: +{ enableNFTables, lib, ... }: { # Some programs need SUID wrappers, can be configured further or are @@ -8,18 +8,11 @@ # Fish shell, the best programs.fish.enable = true; - # Use nftables - networking.nftables.enable = true; - # Tailscale services.tailscale = { enable = true; openFirewall = true; }; - # Support native nftables in tailscale - systemd.services.tailscaled.serviceConfig.Environment = [ - "TS_DEBUG_FIREWALL_MODE=nftables" - ]; # Don't wait for networks on boot, should speed up boot systemd.network.wait-online.enable = false; boot.initrd.systemd.network.wait-online.enable = false; @@ -35,3 +28,11 @@ # MOSH, SSH over flakey connections programs.mosh.enable = true; } +// lib.optionalAttrs enableNFTables { + # Use nftables + networking.nftables.enable = true; + # Support native nftables in tailscale + systemd.services.tailscaled.serviceConfig.Environment = [ + "TS_DEBUG_FIREWALL_MODE=nftables" + ]; +} -- 2.51.2