mirror of https://gitlab.crans.org/nounous/nixos
Networking
parent
cc4e66ae55
commit
b9d3ed71a5
|
|
@ -6,7 +6,7 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat.enable = true;
|
srv-nat.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
resticClient.when = "01:23";
|
resticClient.when = "01:23";
|
||||||
|
|
|
||||||
|
|
@ -6,9 +6,8 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat.enable = true;
|
srv-nat.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
resticClient.enable = false;
|
resticClient.enable = false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,9 +1,10 @@
|
||||||
{
|
{
|
||||||
name = "jitsi";
|
name = "jitsi";
|
||||||
description = "Machine qui gère Jitsi";
|
description = "Machine qui gère Jitsi";
|
||||||
|
|
||||||
id = 163;
|
id = 163;
|
||||||
|
|
||||||
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
adm.enable = true;
|
adm.enable = true;
|
||||||
srv = {
|
srv = {
|
||||||
|
|
|
||||||
|
|
@ -6,9 +6,8 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat.enable = true;
|
srv-nat.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
resticClient.when = "03:45";
|
resticClient.when = "03:45";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -17,7 +17,7 @@
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
id = 144;
|
id = 144;
|
||||||
srvNat.enable = true;
|
srv-nat.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
# Enable when deploying the real mediakiwi
|
# Enable when deploying the real mediakiwi
|
||||||
|
|
|
||||||
|
|
@ -1,9 +1,10 @@
|
||||||
{
|
{
|
||||||
name = "neo";
|
name = "neo";
|
||||||
description = "Matrix du Crans et bridge IRC/Matrix";
|
description = "Matrix du Crans et bridge IRC/Matrix";
|
||||||
enable = true;
|
|
||||||
id = 141;
|
id = 141;
|
||||||
|
|
||||||
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srv = {
|
srv = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
|
||||||
|
|
@ -6,7 +6,7 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat = {
|
srv-nat = {
|
||||||
enable = true;
|
enable = true;
|
||||||
interface = "ens20";
|
interface = "ens20";
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -6,9 +6,8 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat.enable = true;
|
srv-nat.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
resticClient.when = "02:56";
|
resticClient.when = "02:56";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -6,7 +6,7 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat.enable = true;
|
srv-nat.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
resticClient.when = "06:18";
|
resticClient.when = "06:18";
|
||||||
|
|
|
||||||
|
|
@ -6,7 +6,7 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat.enable = true;
|
srv-nat.enable = true;
|
||||||
srv = {
|
srv = {
|
||||||
enable = true;
|
enable = true;
|
||||||
interface = "ens20";
|
interface = "ens20";
|
||||||
|
|
@ -17,4 +17,3 @@
|
||||||
resticClient.when = "03:42";
|
resticClient.when = "03:42";
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -6,7 +6,7 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat = {
|
srv-nat = {
|
||||||
enable = true;
|
enable = true;
|
||||||
interface = "ens19";
|
interface = "ens19";
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -6,7 +6,7 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
srvNat.enable = true;
|
srv-nat.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
resticClient.when = "04:44";
|
resticClient.when = "04:44";
|
||||||
|
|
|
||||||
|
|
@ -78,7 +78,7 @@ in
|
||||||
homeNounou.enable = lib.mkDefault true;
|
homeNounou.enable = lib.mkDefault true;
|
||||||
monitoring.enable = true;
|
monitoring.enable = true;
|
||||||
networking = {
|
networking = {
|
||||||
enable = true;
|
enable = lib.mkDefault true;
|
||||||
adm.enable = lib.mkDefault true;
|
adm.enable = lib.mkDefault true;
|
||||||
};
|
};
|
||||||
resticClient.enable = lib.mkDefault true;
|
resticClient.enable = lib.mkDefault true;
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,9 @@
|
||||||
{ lib, config, hosts, ... }:
|
{
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
hosts,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
let
|
let
|
||||||
cfg = config.crans;
|
cfg = config.crans;
|
||||||
|
|
@ -8,249 +13,114 @@ let
|
||||||
mkEnableOption
|
mkEnableOption
|
||||||
mkIf
|
mkIf
|
||||||
mkOption
|
mkOption
|
||||||
|
mkDefault
|
||||||
types
|
types
|
||||||
mod
|
mod
|
||||||
|
mapAttrs
|
||||||
|
mapAttrs'
|
||||||
|
filterAttrs
|
||||||
|
mergeAttrsList
|
||||||
|
optional
|
||||||
|
fixedWidthString
|
||||||
|
nameValuePair
|
||||||
;
|
;
|
||||||
|
|
||||||
idString = toString cfg.id;
|
|
||||||
hostId = lib.mod cfg.id 100;
|
|
||||||
hostIdString = lib.fixedWidthString 2 "0" (toString hostId);
|
|
||||||
isVm = cfg.id >= 100;
|
|
||||||
isVmString = toString isVm;
|
|
||||||
get_mac = id: vlan_num:
|
|
||||||
"02:00:00:0${toString (id >= 100)}:${toString (mod id 100)}:${lib.fixedWidthString 2 "0" (toString vlan_num)}";
|
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
options.crans.networking = {
|
options.crans.networking = {
|
||||||
enable = mkEnableOption "Configuration réseaux commune à toutes les machines du Crans.";
|
enable = mkEnableOption "Configuration réseaux commune à toutes les machines du Crans.";
|
||||||
|
}
|
||||||
adm = {
|
// mapAttrs (
|
||||||
enable = mkEnableOption "Configuration du VLAN adm.";
|
vlan: conf:
|
||||||
|
let
|
||||||
|
vlanId = mod conf.id 100;
|
||||||
|
in
|
||||||
|
mergeAttrsList (
|
||||||
|
[
|
||||||
|
{
|
||||||
|
enable = mkEnableOption "Activation du réseau ${vlan}";
|
||||||
|
|
||||||
interface = mkOption {
|
interface = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
default = "ens18";
|
description = "Interface pour le réseau ${vlan}";
|
||||||
example = "ens20";
|
default = conf.interface;
|
||||||
description = "Nom de l'interface réseau sur laquelle est située le VLAN adm.";
|
|
||||||
};
|
};
|
||||||
|
|
||||||
|
defaultRoutes = mkOption {
|
||||||
|
type = types.bool;
|
||||||
|
default = true;
|
||||||
|
description = "Configuration par défaut des routes de ${vlan}";
|
||||||
|
};
|
||||||
|
}
|
||||||
|
]
|
||||||
|
++ optional ((conf.ipv4 or true) != null) {
|
||||||
ipv4 = mkOption {
|
ipv4 = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
example = "176.16.10.102";
|
description = "Adresse IPv4 de la machine sur le réseau ${vlan}";
|
||||||
default = "172.16.10.${idString}";
|
default = "172.16.${toString vlanId}.${toString cfg.id}";
|
||||||
description = "Adresse IPv4 de la machine sur le VLAN adm";
|
|
||||||
};
|
};
|
||||||
|
}
|
||||||
|
++ optional ((conf.ipv6 or true) != null) (
|
||||||
|
let
|
||||||
|
# XXX: Utilisation du masque pour le déterminer à la place ?
|
||||||
|
prefix =
|
||||||
|
if lib.hasPrefix "2a0c:700" conf.ipv6.address then
|
||||||
|
"2a0c:700"
|
||||||
|
else if lib.hasPrefix "fd00:0:0" conf.ipv6.address then
|
||||||
|
"fd00:0:0"
|
||||||
|
else
|
||||||
|
(builtins.warn "Le prefixe de ${conf.ipv6.address} n’est pas reconnu");
|
||||||
|
in
|
||||||
|
{
|
||||||
ipv6 = mkOption {
|
ipv6 = mkOption {
|
||||||
type = types.str;
|
type = types.str;
|
||||||
example = "fd00::10:0:ff:fe01:0210";
|
description = "Adresse IPv6 de la machine sur le réseau ${vlan}";
|
||||||
default = "fd00::10:0:ff:fe0${isVmString}:${hostIdString}10";
|
default = "${prefix}:${toString vlanId}::ff:fe0${toString (cfg.id / 100)}:${toString (mod cfg.id 100)}${
|
||||||
description = "Adresse IPv6 de la machine sur le VLAN adm";
|
fixedWidthString 2 "0" (toString vlanId)
|
||||||
};
|
}";
|
||||||
|
|
||||||
};
|
|
||||||
|
|
||||||
srv = {
|
|
||||||
enable = mkEnableOption "Configuration du VLAN srv.";
|
|
||||||
|
|
||||||
interface = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
default = "ens19";
|
|
||||||
example = "ens20";
|
|
||||||
description = "Nom de l'interface réseau sur laquelle est située le VLAN srv.";
|
|
||||||
};
|
|
||||||
|
|
||||||
ipv4 = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
example = "185.230.79.1";
|
|
||||||
description = "Adresse IPv4 de la machine.";
|
|
||||||
};
|
|
||||||
|
|
||||||
ipv6 = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
example = "2a0c:700:2::ff:fe01:0202";
|
|
||||||
default = "2a0c:700:2::ff:fe0${isVmString}:${hostIdString}02";
|
|
||||||
description = "Adresse IPv6 de la machine sur le VLAN srv.";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
srvNat = {
|
|
||||||
enable = mkEnableOption "Configuration du VLAN srv-nat.";
|
|
||||||
|
|
||||||
interface = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
default = "ens19";
|
|
||||||
example = "ens20";
|
|
||||||
description = "Nom de l'interface réseau sur laquelle est située le VLAN srv-nat.";
|
|
||||||
};
|
|
||||||
|
|
||||||
ipv4 = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
example = "176.16.3.102";
|
|
||||||
default = "172.16.3.${idString}";
|
|
||||||
description = "Adresse IPv4 de la machine sur le VLAN srv-nat.";
|
|
||||||
};
|
|
||||||
|
|
||||||
ipv6 = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
example = "2a0c:700:3::ff:fe01:0203";
|
|
||||||
default = "2a0c:700:3::ff:fe0${isVmString}:${hostIdString}03";
|
|
||||||
description = "Adresse IPv6 de la machine sur le VLAN srv-nat.";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
san = {
|
|
||||||
enable = mkEnableOption "Configuration du VLAN san.";
|
|
||||||
|
|
||||||
interface = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
example = "ens19";
|
|
||||||
description = "Nom de l'interface réseau sur laquelle est située le VLAN san.";
|
|
||||||
};
|
|
||||||
|
|
||||||
ipv4 = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
example = "176.16.4.102";
|
|
||||||
default = "172.16.4.${idString}";
|
|
||||||
description = "Adresse IPv4 de la machine sur le VLAN srv-nat.";
|
|
||||||
};
|
|
||||||
|
|
||||||
ipv6 = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
example = "fd00::4:0:ff:fe01:0204";
|
|
||||||
default = "fd00::4:0:ff:fe0${isVmString}:${hostIdString}04";
|
|
||||||
description = "Adresse IPv6 de la machine sur le VLAN san.";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
|
}
|
||||||
|
)
|
||||||
|
)
|
||||||
|
) cfg.vlans;
|
||||||
|
|
||||||
config = mkIf cfg-net.enable {
|
config = mkIf cfg-net.enable {
|
||||||
networking = {
|
networking = {
|
||||||
hostName = cfg.name;
|
hostName = cfg.name;
|
||||||
useDHCP = false;
|
useDHCP = false;
|
||||||
firewall.enable = lib.mkDefault false;
|
firewall.enable = mkDefault false;
|
||||||
nameservers = [ "172.16.10.128" ];
|
nameservers = [
|
||||||
|
# Romanesco via adm
|
||||||
|
"172.16.10.128"
|
||||||
|
"fd00::10:0:ff:fe01:2810"
|
||||||
|
];
|
||||||
|
|
||||||
# La configuration des interfaces se fait de la manière suivante :
|
interfaces = mapAttrs' (
|
||||||
# elle est écrite de manière générique pour toutes les machines, puis
|
vlan: vconf:
|
||||||
# on filtre pour ne garder que les interfaces activées. nix fait de
|
let
|
||||||
# l'évaluation paresseuse donc ça fonctionne bien !
|
conf = cfg-net.${vlan};
|
||||||
interfaces =
|
in
|
||||||
# On change le nom des interfaces de "adm", "srv", ... pour leur vrai
|
nameValuePair conf.interface (
|
||||||
# nom (on ne le met pas directement pour faire fonctionner le filter
|
# On itère ipv4 / ipv6
|
||||||
# plus bas).
|
builtins.mapAttrs
|
||||||
lib.attrsets.mapAttrs'
|
|
||||||
(interface: conf: {
|
|
||||||
name = cfg-net."${interface}".interface;
|
|
||||||
value = conf;
|
|
||||||
})
|
|
||||||
(
|
(
|
||||||
# On filtre sur les interfaces activées
|
ipvx: _:
|
||||||
lib.attrsets.filterAttrs (interface: _: cfg-net."${interface}".enable) {
|
mkIf (vconf.${ipvx} != null) {
|
||||||
# Configuration du VLAN adm
|
|
||||||
adm = {
|
|
||||||
ipv4.addresses = [
|
|
||||||
{
|
|
||||||
address = cfg-net.adm.ipv4;
|
|
||||||
prefixLength = 24;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
|
|
||||||
ipv6.addresses = [
|
|
||||||
{
|
|
||||||
address = cfg-net.adm.ipv6;
|
|
||||||
prefixLength = 64;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
# Configuration du VLAN srv
|
|
||||||
srv = {
|
|
||||||
ipv4 = {
|
|
||||||
addresses = [
|
addresses = [
|
||||||
{
|
{
|
||||||
address = cfg-net.srv.ipv4;
|
address = conf.${ipvx};
|
||||||
prefixLength = 26;
|
prefixLength = vconf.${ipvx}.prefixLength;
|
||||||
}
|
|
||||||
];
|
|
||||||
routes = [
|
|
||||||
{
|
|
||||||
address = "0.0.0.0";
|
|
||||||
via = "185.230.79.62";
|
|
||||||
prefixLength = 0;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
ipv6 = {
|
|
||||||
addresses = [
|
|
||||||
{
|
|
||||||
address = cfg-net.srv.ipv6;
|
|
||||||
prefixLength = 64;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
routes = [
|
|
||||||
{
|
|
||||||
address = "::";
|
|
||||||
via = "2a0c:700:2::ff:fe00:9902";
|
|
||||||
prefixLength = 0;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
# Configuration du VLAN srv-nat
|
|
||||||
srvNat = {
|
|
||||||
ipv4 = {
|
|
||||||
addresses = [
|
|
||||||
{
|
|
||||||
address = cfg-net.srvNat.ipv4;
|
|
||||||
prefixLength = 24;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
routes = [
|
|
||||||
{
|
|
||||||
address = "0.0.0.0";
|
|
||||||
via = "172.16.3.99";
|
|
||||||
prefixLength = 0;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
ipv6 = {
|
|
||||||
addresses = [
|
|
||||||
{
|
|
||||||
address = cfg-net.srvNat.ipv6;
|
|
||||||
prefixLength = 64;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
routes = [
|
|
||||||
{
|
|
||||||
address = "::";
|
|
||||||
via = "2a0c:700:3::ff:fe00:9903";
|
|
||||||
prefixLength = 0;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
# Configuration du VLAN san
|
|
||||||
san = {
|
|
||||||
ipv4.addresses = [
|
|
||||||
{
|
|
||||||
address = cfg-net.san.ipv4;
|
|
||||||
prefixLength = 24;
|
|
||||||
}
|
}
|
||||||
];
|
];
|
||||||
|
|
||||||
ipv6.addresses = [
|
routes = mkIf conf.defaultRoutes vconf.${ipvx}.routes;
|
||||||
|
}
|
||||||
|
)
|
||||||
{
|
{
|
||||||
address = cfg-net.san.ipv6;
|
"ipv4" = null;
|
||||||
prefixLength = 64;
|
"ipv6" = null;
|
||||||
}
|
}
|
||||||
];
|
)
|
||||||
};
|
) (filterAttrs (n: _: cfg-net.${n}.enable) cfg.vlans); # On filtre les interfaces désactivées.
|
||||||
}
|
|
||||||
);
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -216,13 +216,15 @@ in
|
||||||
let
|
let
|
||||||
vlan = lib.mod conf.id 100;
|
vlan = lib.mod conf.id 100;
|
||||||
in
|
in
|
||||||
lib.mkMerge [
|
lib.mkMerge (
|
||||||
conf
|
[ conf ]
|
||||||
{
|
++ lib.optional ((conf.ipv4 or true) != null) {
|
||||||
ipv4.address = mkDefault "172.16.${toString vlan}.0";
|
ipv4.address = mkDefault "172.16.${toString vlan}.0";
|
||||||
|
}
|
||||||
|
++ lib.optional ((conf.ipv6 or true) != null) {
|
||||||
ipv6.address = mkDefault "fd00:0:0:${toString vlan}::";
|
ipv6.address = mkDefault "fd00:0:0:${toString vlan}::";
|
||||||
}
|
}
|
||||||
]
|
)
|
||||||
) vlanConf
|
) vlanConf
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue