From b9d3ed71a59f6aa51403ec501bf182ce4da3bc47 Mon Sep 17 00:00:00 2001 From: Pyjacpp Date: Tue, 8 Sep 2026 13:33:25 +0200 Subject: [PATCH] Networking --- hosts/vm/apprentix/info.nix | 22 +-- hosts/vm/collabora/info.nix | 3 +- hosts/vm/jitsi/info.nix | 5 +- hosts/vm/livre/info.nix | 3 +- hosts/vm/mediakiwi/default.nix | 2 +- hosts/vm/neo/info.nix | 3 +- hosts/vm/nextcloud/info.nix | 32 ++-- hosts/vm/periodique/info.nix | 3 +- hosts/vm/redite/info.nix | 2 +- hosts/vm/reverseproxy/info.nix | 3 +- hosts/vm/two/info.nix | 4 +- hosts/vm/vaultwarden/info.nix | 4 +- modules/crans/default.nix | 2 +- modules/crans/networking.nix | 318 ++++++++++----------------------- modules/crans/vlans.nix | 10 +- 15 files changed, 143 insertions(+), 273 deletions(-) diff --git a/hosts/vm/apprentix/info.nix b/hosts/vm/apprentix/info.nix index 22e47f2..f569b99 100644 --- a/hosts/vm/apprentix/info.nix +++ b/hosts/vm/apprentix/info.nix @@ -1,17 +1,17 @@ { - name = "apprentix"; - description = "VM pour les apprenti⋅es"; - id = 150; - - enable = true; + name = "apprentix"; + description = "VM pour les apprenti⋅es"; + id = 150; - networking = { - srvNat.enable = true; - }; + enable = true; - resticClient.when = "01:23"; + networking = { + srv-nat.enable = true; + }; - homeNounou.enable = false; + resticClient.when = "01:23"; - users.root.passwordFile = ../../../secrets/apprentix/root.age; + homeNounou.enable = false; + + users.root.passwordFile = ../../../secrets/apprentix/root.age; } diff --git a/hosts/vm/collabora/info.nix b/hosts/vm/collabora/info.nix index 85052e9..c68b81f 100644 --- a/hosts/vm/collabora/info.nix +++ b/hosts/vm/collabora/info.nix @@ -6,9 +6,8 @@ enable = true; networking = { - srvNat.enable = true; + srv-nat.enable = true; }; resticClient.enable = false; } - diff --git a/hosts/vm/jitsi/info.nix b/hosts/vm/jitsi/info.nix index 5818ab2..d9c3c5c 100644 --- a/hosts/vm/jitsi/info.nix +++ b/hosts/vm/jitsi/info.nix @@ -1,9 +1,10 @@ { name = "jitsi"; description = "Machine qui gère Jitsi"; - id = 163; + enable = true; + networking = { adm.enable = true; srv = { @@ -23,5 +24,5 @@ # ]; public-ssh = ""; - + } diff --git a/hosts/vm/livre/info.nix b/hosts/vm/livre/info.nix index 7eba0c0..1632dd6 100644 --- a/hosts/vm/livre/info.nix +++ b/hosts/vm/livre/info.nix @@ -6,9 +6,8 @@ enable = true; networking = { - srvNat.enable = true; + srv-nat.enable = true; }; resticClient.when = "03:45"; } - diff --git a/hosts/vm/mediakiwi/default.nix b/hosts/vm/mediakiwi/default.nix index e4a80a0..c5318e2 100644 --- a/hosts/vm/mediakiwi/default.nix +++ b/hosts/vm/mediakiwi/default.nix @@ -17,7 +17,7 @@ networking = { id = 144; - srvNat.enable = true; + srv-nat.enable = true; }; # Enable when deploying the real mediakiwi diff --git a/hosts/vm/neo/info.nix b/hosts/vm/neo/info.nix index e234b09..ad068b7 100644 --- a/hosts/vm/neo/info.nix +++ b/hosts/vm/neo/info.nix @@ -1,9 +1,10 @@ { name = "neo"; description = "Matrix du Crans et bridge IRC/Matrix"; - enable = true; id = 141; + enable = true; + networking = { srv = { enable = true; diff --git a/hosts/vm/nextcloud/info.nix b/hosts/vm/nextcloud/info.nix index d23079d..598f79a 100644 --- a/hosts/vm/nextcloud/info.nix +++ b/hosts/vm/nextcloud/info.nix @@ -1,22 +1,22 @@ { - name = "nextcloud"; - description = "Nextcloud du Crans"; - id = 146; - - enable = true; + name = "nextcloud"; + description = "Nextcloud du Crans"; + id = 146; - networking = { - srvNat = { - enable = true; - interface = "ens20"; - }; - san = { - enable = true; - interface = "ens19"; - }; + enable = true; + + networking = { + srv-nat = { + enable = true; + interface = "ens20"; }; + san = { + enable = true; + interface = "ens19"; + }; + }; - homeAdh.enable = true; + homeAdh.enable = true; - resticClient.enable = false; + resticClient.enable = false; } diff --git a/hosts/vm/periodique/info.nix b/hosts/vm/periodique/info.nix index faf99e8..489eaff 100644 --- a/hosts/vm/periodique/info.nix +++ b/hosts/vm/periodique/info.nix @@ -6,9 +6,8 @@ enable = true; networking = { - srvNat.enable = true; + srv-nat.enable = true; }; resticClient.when = "02:56"; } - diff --git a/hosts/vm/redite/info.nix b/hosts/vm/redite/info.nix index 78094da..74298d9 100644 --- a/hosts/vm/redite/info.nix +++ b/hosts/vm/redite/info.nix @@ -6,7 +6,7 @@ enable = true; networking = { - srvNat.enable = true; + srv-nat.enable = true; }; resticClient.when = "06:18"; diff --git a/hosts/vm/reverseproxy/info.nix b/hosts/vm/reverseproxy/info.nix index 4481c49..e2bcf3f 100644 --- a/hosts/vm/reverseproxy/info.nix +++ b/hosts/vm/reverseproxy/info.nix @@ -6,7 +6,7 @@ enable = true; networking = { - srvNat.enable = true; + srv-nat.enable = true; srv = { enable = true; interface = "ens20"; @@ -17,4 +17,3 @@ resticClient.when = "03:42"; } - diff --git a/hosts/vm/two/info.nix b/hosts/vm/two/info.nix index 2b833b5..c345d86 100644 --- a/hosts/vm/two/info.nix +++ b/hosts/vm/two/info.nix @@ -2,11 +2,11 @@ name = "two"; description = "VM de test"; id = 135; - + enable = true; networking = { - srvNat = { + srv-nat = { enable = true; interface = "ens19"; }; diff --git a/hosts/vm/vaultwarden/info.nix b/hosts/vm/vaultwarden/info.nix index 953a611..1cf8489 100644 --- a/hosts/vm/vaultwarden/info.nix +++ b/hosts/vm/vaultwarden/info.nix @@ -2,11 +2,11 @@ name = "vaultwarden"; description = "Vaultarden du crans, gestionnaire de mot de passe"; id = 159; - + enable = true; networking = { - srvNat.enable = true; + srv-nat.enable = true; }; resticClient.when = "04:44"; diff --git a/modules/crans/default.nix b/modules/crans/default.nix index 0e077fa..4f28495 100644 --- a/modules/crans/default.nix +++ b/modules/crans/default.nix @@ -78,7 +78,7 @@ in homeNounou.enable = lib.mkDefault true; monitoring.enable = true; networking = { - enable = true; + enable = lib.mkDefault true; adm.enable = lib.mkDefault true; }; resticClient.enable = lib.mkDefault true; diff --git a/modules/crans/networking.nix b/modules/crans/networking.nix index 0cceae0..99e20b1 100644 --- a/modules/crans/networking.nix +++ b/modules/crans/networking.nix @@ -1,4 +1,9 @@ -{ lib, config, hosts, ... }: +{ + lib, + config, + hosts, + ... +}: let cfg = config.crans; @@ -8,249 +13,114 @@ let mkEnableOption mkIf mkOption + mkDefault types mod + mapAttrs + mapAttrs' + filterAttrs + mergeAttrsList + optional + fixedWidthString + nameValuePair ; - - idString = toString cfg.id; - hostId = lib.mod cfg.id 100; - hostIdString = lib.fixedWidthString 2 "0" (toString hostId); - isVm = cfg.id >= 100; - isVmString = toString isVm; - get_mac = id: vlan_num: - "02:00:00:0${toString (id >= 100)}:${toString (mod id 100)}:${lib.fixedWidthString 2 "0" (toString vlan_num)}"; in { options.crans.networking = { enable = mkEnableOption "Configuration réseaux commune à toutes les machines du Crans."; + } + // mapAttrs ( + vlan: conf: + let + vlanId = mod conf.id 100; + in + mergeAttrsList ( + [ + { + enable = mkEnableOption "Activation du réseau ${vlan}"; - adm = { - enable = mkEnableOption "Configuration du VLAN adm."; + interface = mkOption { + type = types.str; + description = "Interface pour le réseau ${vlan}"; + default = conf.interface; + }; - interface = mkOption { - type = types.str; - default = "ens18"; - example = "ens20"; - description = "Nom de l'interface réseau sur laquelle est située le VLAN adm."; - }; - - ipv4 = mkOption { - type = types.str; - example = "176.16.10.102"; - default = "172.16.10.${idString}"; - description = "Adresse IPv4 de la machine sur le VLAN adm"; - }; - - ipv6 = mkOption { - type = types.str; - example = "fd00::10:0:ff:fe01:0210"; - default = "fd00::10:0:ff:fe0${isVmString}:${hostIdString}10"; - description = "Adresse IPv6 de la machine sur le VLAN adm"; - }; - - }; - - srv = { - enable = mkEnableOption "Configuration du VLAN srv."; - - interface = mkOption { - type = types.str; - default = "ens19"; - example = "ens20"; - description = "Nom de l'interface réseau sur laquelle est située le VLAN srv."; - }; - - ipv4 = mkOption { - type = types.str; - example = "185.230.79.1"; - description = "Adresse IPv4 de la machine."; - }; - - ipv6 = mkOption { - type = types.str; - example = "2a0c:700:2::ff:fe01:0202"; - default = "2a0c:700:2::ff:fe0${isVmString}:${hostIdString}02"; - description = "Adresse IPv6 de la machine sur le VLAN srv."; - }; - }; - - srvNat = { - enable = mkEnableOption "Configuration du VLAN srv-nat."; - - interface = mkOption { - type = types.str; - default = "ens19"; - example = "ens20"; - description = "Nom de l'interface réseau sur laquelle est située le VLAN srv-nat."; - }; - - ipv4 = mkOption { - type = types.str; - example = "176.16.3.102"; - default = "172.16.3.${idString}"; - description = "Adresse IPv4 de la machine sur le VLAN srv-nat."; - }; - - ipv6 = mkOption { - type = types.str; - example = "2a0c:700:3::ff:fe01:0203"; - default = "2a0c:700:3::ff:fe0${isVmString}:${hostIdString}03"; - description = "Adresse IPv6 de la machine sur le VLAN srv-nat."; - }; - }; - - san = { - enable = mkEnableOption "Configuration du VLAN san."; - - interface = mkOption { - type = types.str; - example = "ens19"; - description = "Nom de l'interface réseau sur laquelle est située le VLAN san."; - }; - - ipv4 = mkOption { - type = types.str; - example = "176.16.4.102"; - default = "172.16.4.${idString}"; - description = "Adresse IPv4 de la machine sur le VLAN srv-nat."; - }; - - ipv6 = mkOption { - type = types.str; - example = "fd00::4:0:ff:fe01:0204"; - default = "fd00::4:0:ff:fe0${isVmString}:${hostIdString}04"; - description = "Adresse IPv6 de la machine sur le VLAN san."; - }; - }; - }; + defaultRoutes = mkOption { + type = types.bool; + default = true; + description = "Configuration par défaut des routes de ${vlan}"; + }; + } + ] + ++ optional ((conf.ipv4 or true) != null) { + ipv4 = mkOption { + type = types.str; + description = "Adresse IPv4 de la machine sur le réseau ${vlan}"; + default = "172.16.${toString vlanId}.${toString cfg.id}"; + }; + } + ++ optional ((conf.ipv6 or true) != null) ( + let + # XXX: Utilisation du masque pour le déterminer à la place ? + prefix = + if lib.hasPrefix "2a0c:700" conf.ipv6.address then + "2a0c:700" + else if lib.hasPrefix "fd00:0:0" conf.ipv6.address then + "fd00:0:0" + else + (builtins.warn "Le prefixe de ${conf.ipv6.address} n’est pas reconnu"); + in + { + ipv6 = mkOption { + type = types.str; + description = "Adresse IPv6 de la machine sur le réseau ${vlan}"; + default = "${prefix}:${toString vlanId}::ff:fe0${toString (cfg.id / 100)}:${toString (mod cfg.id 100)}${ + fixedWidthString 2 "0" (toString vlanId) + }"; + }; + } + ) + ) + ) cfg.vlans; config = mkIf cfg-net.enable { networking = { hostName = cfg.name; useDHCP = false; - firewall.enable = lib.mkDefault false; - nameservers = [ "172.16.10.128" ]; + firewall.enable = mkDefault false; + nameservers = [ + # Romanesco via adm + "172.16.10.128" + "fd00::10:0:ff:fe01:2810" + ]; - # La configuration des interfaces se fait de la manière suivante : - # elle est écrite de manière générique pour toutes les machines, puis - # on filtre pour ne garder que les interfaces activées. nix fait de - # l'évaluation paresseuse donc ça fonctionne bien ! - interfaces = - # On change le nom des interfaces de "adm", "srv", ... pour leur vrai - # nom (on ne le met pas directement pour faire fonctionner le filter - # plus bas). - lib.attrsets.mapAttrs' - (interface: conf: { - name = cfg-net."${interface}".interface; - value = conf; - }) - ( - # On filtre sur les interfaces activées - lib.attrsets.filterAttrs (interface: _: cfg-net."${interface}".enable) { - # Configuration du VLAN adm - adm = { - ipv4.addresses = [ + interfaces = mapAttrs' ( + vlan: vconf: + let + conf = cfg-net.${vlan}; + in + nameValuePair conf.interface ( + # On itère ipv4 / ipv6 + builtins.mapAttrs + ( + ipvx: _: + mkIf (vconf.${ipvx} != null) { + addresses = [ { - address = cfg-net.adm.ipv4; - prefixLength = 24; + address = conf.${ipvx}; + prefixLength = vconf.${ipvx}.prefixLength; } ]; - ipv6.addresses = [ - { - address = cfg-net.adm.ipv6; - prefixLength = 64; - } - ]; - }; - - # Configuration du VLAN srv - srv = { - ipv4 = { - addresses = [ - { - address = cfg-net.srv.ipv4; - prefixLength = 26; - } - ]; - routes = [ - { - address = "0.0.0.0"; - via = "185.230.79.62"; - prefixLength = 0; - } - ]; - }; - ipv6 = { - addresses = [ - { - address = cfg-net.srv.ipv6; - prefixLength = 64; - } - ]; - routes = [ - { - address = "::"; - via = "2a0c:700:2::ff:fe00:9902"; - prefixLength = 0; - } - ]; - }; - }; - - # Configuration du VLAN srv-nat - srvNat = { - ipv4 = { - addresses = [ - { - address = cfg-net.srvNat.ipv4; - prefixLength = 24; - } - ]; - routes = [ - { - address = "0.0.0.0"; - via = "172.16.3.99"; - prefixLength = 0; - } - ]; - }; - - ipv6 = { - addresses = [ - { - address = cfg-net.srvNat.ipv6; - prefixLength = 64; - } - ]; - routes = [ - { - address = "::"; - via = "2a0c:700:3::ff:fe00:9903"; - prefixLength = 0; - } - ]; - }; - }; - - # Configuration du VLAN san - san = { - ipv4.addresses = [ - { - address = cfg-net.san.ipv4; - prefixLength = 24; - } - ]; - - ipv6.addresses = [ - { - address = cfg-net.san.ipv6; - prefixLength = 64; - } - ]; - }; + routes = mkIf conf.defaultRoutes vconf.${ipvx}.routes; + } + ) + { + "ipv4" = null; + "ipv6" = null; } - ); + ) + ) (filterAttrs (n: _: cfg-net.${n}.enable) cfg.vlans); # On filtre les interfaces désactivées. }; }; } diff --git a/modules/crans/vlans.nix b/modules/crans/vlans.nix index 468494f..9de7ee6 100644 --- a/modules/crans/vlans.nix +++ b/modules/crans/vlans.nix @@ -216,13 +216,15 @@ in let vlan = lib.mod conf.id 100; in - lib.mkMerge [ - conf - { + lib.mkMerge ( + [ conf ] + ++ lib.optional ((conf.ipv4 or true) != null) { ipv4.address = mkDefault "172.16.${toString vlan}.0"; + } + ++ lib.optional ((conf.ipv6 or true) != null) { ipv6.address = mkDefault "fd00:0:0:${toString vlan}::"; } - ] + ) ) vlanConf ); }