mirror of https://gitlab.crans.org/nounous/nixos
vlan conf
parent
2641ecf224
commit
cc4e66ae55
|
|
@ -26,6 +26,7 @@ in
|
|||
./ssh.nix
|
||||
./store.nix
|
||||
./users.nix
|
||||
./vlans.nix
|
||||
./virtualisation.nix
|
||||
];
|
||||
|
||||
|
|
|
|||
|
|
@ -0,0 +1,228 @@
|
|||
{ lib, ... }:
|
||||
let
|
||||
inherit (lib)
|
||||
mkOption
|
||||
types
|
||||
mkDefault
|
||||
mkForce
|
||||
;
|
||||
|
||||
vlanConf = {
|
||||
|
||||
srv = {
|
||||
id = 2;
|
||||
description = "Réseau public";
|
||||
interface = "ens19";
|
||||
ipv4 = {
|
||||
address = mkForce "185.230.79.0";
|
||||
prefixLength = 26;
|
||||
routes = [
|
||||
{
|
||||
address = "0.0.0.0";
|
||||
via = "185.230.79.62";
|
||||
prefixLength = 0;
|
||||
}
|
||||
];
|
||||
};
|
||||
ipv6 = {
|
||||
address = mkForce "2a0c:700:10::";
|
||||
routes = [
|
||||
{
|
||||
address = "::";
|
||||
via = "2a0c:700:2::ff:fe00:9902";
|
||||
prefixLength = 0;
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
srv-nat = {
|
||||
id = 3;
|
||||
description = "Réseau derrière un NAT";
|
||||
interface = "ens19";
|
||||
ipv4.routes = [
|
||||
{
|
||||
address = "0.0.0.0";
|
||||
via = "172.16.3.99";
|
||||
prefixLength = 0;
|
||||
}
|
||||
];
|
||||
ipv6 = {
|
||||
address = mkForce "2a0c:700:3::";
|
||||
routes = [
|
||||
{
|
||||
address = "0.0.0.0";
|
||||
via = "2a0c:700:3::ff:fe00:9903";
|
||||
prefixLength = 0;
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
san = {
|
||||
id = 4;
|
||||
description = "Accès aux baies de stockages";
|
||||
interface = "ens19";
|
||||
};
|
||||
|
||||
ceph = {
|
||||
id = 6;
|
||||
description = "Réseau interne à ceph";
|
||||
interface = "ens20";
|
||||
};
|
||||
|
||||
adm = {
|
||||
id = 10;
|
||||
description = "Réseau interne";
|
||||
interface = "ens18";
|
||||
};
|
||||
|
||||
adh = {
|
||||
id = 12;
|
||||
description = "Réseau adhérent";
|
||||
ipv4 = {
|
||||
address = mkForce "185.230.78.0";
|
||||
routes = [
|
||||
{
|
||||
address = "0.0.0.0";
|
||||
via = "185.230.78.12";
|
||||
prefixLength = 0;
|
||||
}
|
||||
];
|
||||
};
|
||||
ipv6 = {
|
||||
address = mkForce "2a0c:700:12::";
|
||||
prefixLength = 48;
|
||||
routes = [
|
||||
{
|
||||
address = "::";
|
||||
via = "2a0c:700:12::ff:fe00:9912";
|
||||
prefixLength = 0;
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
adh-adm = {
|
||||
id = 13;
|
||||
description = "Réseau d’administration du réseau adhérent";
|
||||
};
|
||||
|
||||
ens = {
|
||||
id = 2751;
|
||||
description = "Interconnexion avec l’ENS.";
|
||||
ipv4 = {
|
||||
address = mkForce "138.231.136.0";
|
||||
prefixLength = 29;
|
||||
};
|
||||
ipv6 = null;
|
||||
};
|
||||
|
||||
ens-clubs = {
|
||||
id = 2754;
|
||||
description = "Réseau clubs interconnecté avec l’ENS";
|
||||
ipv6 = null;
|
||||
};
|
||||
|
||||
ens-lp = {
|
||||
id = 2756;
|
||||
description = "Réseau imprimante interconnecté avec l’ENS";
|
||||
ipv6 = null;
|
||||
};
|
||||
|
||||
};
|
||||
|
||||
ipOpt =
|
||||
v:
|
||||
let
|
||||
maxPrefix = if v == 4 then 32 else 128;
|
||||
in
|
||||
types.submodule {
|
||||
options = {
|
||||
address = mkOption {
|
||||
type = types.str;
|
||||
description = "Adresses IPv${v} du réseau";
|
||||
};
|
||||
|
||||
prefixLength = mkOption {
|
||||
type = types.ints.between 0 maxPrefix;
|
||||
default = if v == 4 then 24 else 64;
|
||||
description = "Prefixe du réseau";
|
||||
};
|
||||
|
||||
routes = mkOption {
|
||||
default = [ ];
|
||||
description = "Routes par défaut";
|
||||
example = [
|
||||
{
|
||||
address = "0.0.0.0";
|
||||
via = "172.16.3.99";
|
||||
prefixLength = 0;
|
||||
}
|
||||
];
|
||||
type = types.listOf (
|
||||
types.submodule {
|
||||
options = {
|
||||
address = mkOption { type = types.str; };
|
||||
via = mkOption { type = types.str; };
|
||||
prefixLength = mkOption { type = types.ints.between 0 maxPrefix; };
|
||||
};
|
||||
}
|
||||
);
|
||||
};
|
||||
};
|
||||
};
|
||||
in
|
||||
{
|
||||
options.crans.vlans = mkOption {
|
||||
type = types.attrsOf (
|
||||
types.submodule {
|
||||
options = {
|
||||
id = mkOption {
|
||||
type = types.int;
|
||||
example = "10";
|
||||
description = "Id du VLAN";
|
||||
};
|
||||
|
||||
description = mkOption {
|
||||
type = types.str;
|
||||
description = "Description du VLAN";
|
||||
};
|
||||
|
||||
interface = mkOption {
|
||||
type = types.nullOr types.str;
|
||||
default = null;
|
||||
example = "ens19";
|
||||
description = "Interface par défaut du VLAN";
|
||||
};
|
||||
|
||||
ipv4 = mkOption {
|
||||
type = types.nullOr (ipOpt 4);
|
||||
description = "Réseau IPv4 du VLAN.";
|
||||
};
|
||||
|
||||
ipv6 = mkOption {
|
||||
type = types.nullOr (ipOpt 6);
|
||||
description = "Réseau IPv6 du VLAN.";
|
||||
};
|
||||
};
|
||||
}
|
||||
);
|
||||
};
|
||||
|
||||
config.crans.vlans = (
|
||||
builtins.mapAttrs (
|
||||
vlan: conf:
|
||||
let
|
||||
vlan = lib.mod conf.id 100;
|
||||
in
|
||||
lib.mkMerge [
|
||||
conf
|
||||
{
|
||||
ipv4.address = mkDefault "172.16.${toString vlan}.0";
|
||||
ipv6.address = mkDefault "fd00:0:0:${toString vlan}::";
|
||||
}
|
||||
]
|
||||
) vlanConf
|
||||
);
|
||||
}
|
||||
Loading…
Reference in New Issue