refactor: change to litterate config

Configuration is now held by the `.org` files. All `.nix` files are
tangled from the org-mode files.
This commit is contained in:
2026-10-06 12:40:58 +02:00
parent 5f4a7a4a42
commit ba018ef841
62 changed files with 2374 additions and 519 deletions
+61 -65
View File
@@ -7,74 +7,70 @@
with lib; let
cfg = config.mySystem.networking;
in {
options.mySystem.networking = with types; {
hostname = mkOption {
type = str;
example = "gampo";
};
id = mkOption {
type = str;
example = "deadb33f";
};
domain = mkOption {
type = nullOr str;
example = "phundrak.com";
default = null;
};
hostFiles = mkOption {
type = listOf path;
example = [/path/to/hostFile];
default = [];
};
firewall = {
openPorts = mkOption {
type = listOf int;
example = [22 80 443];
default = [];
};
openPortRanges = mkOption {
type = listOf (attrsOf port);
default = [];
example = [
{
from = 8080;
to = 8082;
}
];
description = ''
A range of TCP and UDP ports on which incoming connections are
accepted.
'';
};
extraCommands = mkOption {
type = nullOr lines;
example = "iptables -A INPUTS -p icmp -j ACCEPT";
default = null;
};
};
wifi.disablePowersave = mkEnableOption ''
Disables powersave for Wifi.
options.mySystem.networking.hostname = mkOption {
type = types.str;
example = "gampo";
};
config.networking.hostName = cfg.hostname;
options.mySystem.networking.id = mkOption {
type = types.str;
example = "deadb33f";
};
config.networking.hostId = cfg.id;
options.mySystem.networking.domain = mkOption {
type = types.nullOr types.str;
example = "phundrak.com";
default = null;
};
config.networking.domain = cfg.domain;
options.mySystem.networking.hostFiles = mkOption {
type = types.listOf types.path;
example = [/path/to/hostFile];
default = [];
};
config.networking.hostFiles = cfg.hostFiles;
options.mySystem.networking.wifi.disablePowersave = mkEnableOption ''
Disables powersave for Wifi.
Used mainly for the PineTab2, as leaving WiFi powersave with the bes2600 can cause stability issues.
Used mainly for the PineTab2, as leaving WiFi powersave with the bes2600 can cause stability issues.
'';
config.networking.networkmanager = {
enable = true;
wifi.powersave = !cfg.wifi.disablePowersave;
};
options.mySystem.networking.firewall.openPorts = mkOption {
type = types.listOf types.int;
example = [22 80 443];
default = [];
};
config.networking.firewall = {
enable = true;
allowedTCPPorts = cfg.firewall.openPorts;
allowedUDPPorts = cfg.firewall.openPorts;
};
options.mySystem.networking.firewall.openPortRanges = mkOption {
type = types.listOf (types.attrsOf types.port);
default = [];
example = [
{
from = 8080;
to = 8082;
}
];
description = ''
A range of TCP and UDP ports on which incoming connections are
accepted.
'';
};
config.networking = {
hostName = cfg.hostname; # Define your hostname.
hostId = cfg.id;
networkmanager = {
enable = true;
wifi.powersave = ! cfg.wifi.disablePowersave;
};
inherit (cfg) hostFiles domain;
firewall = {
enable = true;
allowedTCPPorts = cfg.firewall.openPorts;
allowedUDPPorts = cfg.firewall.openPorts;
allowedTCPPortRanges = cfg.firewall.openPortRanges;
allowedUDPPortRanges = cfg.firewall.openPortRanges;
extraCommands = (mkIf (cfg.firewall.extraCommands != null)) cfg.firewall.extraCommands;
};
config.networking.firewall = {
allowedTCPPortRanges = cfg.firewall.openPortRanges;
allowedUDPPortRanges = cfg.firewall.openPortRanges;
};
options.mySystem.networking.firewall.extraCommands = mkOption {
type = types.nullOr types.lines;
example = "iptables -A INPUTS -p icmp -j ACCEPT";
default = null;
};
config.networking.firewall.extraCommands = mkIf (cfg.firewall.extraCommands != null) cfg.firewall.extraCommands;
};
}
+151
View File
@@ -0,0 +1,151 @@
#+title: Networking
#+setupfile: ../headers
* Networking
This module centralises the basic networking identity of a host —
hostname, host ID, domain, NetworkManager and the firewall — behind a
single =mySystem.networking= namespace. Here’s the skeleton of the
=nixos.networking= module.
#+begin_src nix :tangle yes
{...}: {
flake.modules.nixos.networking = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.networking;
in {
<<hostname>>
<<host-id>>
<<domain>>
<<host-files>>
<<wifi-powersave>>
<<firewall-ports>>
<<firewall-port-ranges>>
<<firewall-extra-commands>>
};
}
#+end_src
** Hostname
#+name: hostname
#+begin_src nix
options.mySystem.networking.hostname = mkOption {
type = types.str;
example = "gampo";
};
config.networking.hostName = cfg.hostname;
#+end_src
** Host ID
Every host needs a unique =hostId=; besides identifying the machine on
the network, ZFS also uses it to guard against accidentally importing
a pool that’s still active on another machine (see [[file:../boot/zfs.org][ZFS Support]]).
#+name: host-id
#+begin_src nix
options.mySystem.networking.id = mkOption {
type = types.str;
example = "deadb33f";
};
config.networking.hostId = cfg.id;
#+end_src
** Domain
Not every host needs a domain name, so this defaults to =null=.
#+name: domain
#+begin_src nix
options.mySystem.networking.domain = mkOption {
type = types.nullOr types.str;
example = "phundrak.com";
default = null;
};
config.networking.domain = cfg.domain;
#+end_src
** Extra Host Files
=hostFiles= lets a host point at extra files to merge into =/etc/hosts=,
on top of whatever NixOS generates itself.
#+name: host-files
#+begin_src nix
options.mySystem.networking.hostFiles = mkOption {
type = types.listOf types.path;
example = [/path/to/hostFile];
default = [];
};
config.networking.hostFiles = cfg.hostFiles;
#+end_src
** NetworkManager and WiFi Powersave
NetworkManager is always enabled; the only thing a host can tune here
is WiFi powersave. I mainly need to turn it off on the PineTab2, since
leaving powersave on with its =bes2600= WiFi chip causes stability
issues.
#+name: wifi-powersave
#+begin_src nix
options.mySystem.networking.wifi.disablePowersave = mkEnableOption ''
Disables powersave for Wifi.
Used mainly for the PineTab2, as leaving WiFi powersave with the bes2600 can cause stability issues.
'';
config.networking.networkmanager = {
enable = true;
wifi.powersave = !cfg.wifi.disablePowersave;
};
#+end_src
** Firewall: Ports
This also turns the firewall itself on; =openPorts= is just the plain
list of single ports to open, on both TCP and UDP.
#+name: firewall-ports
#+begin_src nix
options.mySystem.networking.firewall.openPorts = mkOption {
type = types.listOf types.int;
example = [22 80 443];
default = [];
};
config.networking.firewall = {
enable = true;
allowedTCPPorts = cfg.firewall.openPorts;
allowedUDPPorts = cfg.firewall.openPorts;
};
#+end_src
** Firewall: Port Ranges
=openPortRanges= does the same, but for a contiguous range of ports at
once, again on both TCP and UDP.
#+name: firewall-port-ranges
#+begin_src nix
options.mySystem.networking.firewall.openPortRanges = mkOption {
type = types.listOf (types.attrsOf types.port);
default = [];
example = [
{
from = 8080;
to = 8082;
}
];
description = ''
A range of TCP and UDP ports on which incoming connections are
accepted.
'';
};
config.networking.firewall = {
allowedTCPPortRanges = cfg.firewall.openPortRanges;
allowedUDPPortRanges = cfg.firewall.openPortRanges;
};
#+end_src
** Firewall: Extra Commands
For anything the declarative options above can’t express, =extraCommands=
lets a host drop raw =iptables= commands straight into the firewall
setup.
#+name: firewall-extra-commands
#+begin_src nix
options.mySystem.networking.firewall.extraCommands = mkOption {
type = types.nullOr types.lines;
example = "iptables -A INPUTS -p icmp -j ACCEPT";
default = null;
};
config.networking.firewall.extraCommands = mkIf (cfg.firewall.extraCommands != null) cfg.firewall.extraCommands;
#+end_src
+9 -22
View File
@@ -1,25 +1,12 @@
{...}: {
{
flake.modules.nixos.tailscale = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.network.tailscale;
in {
options.mySystem.network.tailscale = {
enable = mkOption {
type = types.bool;
default = true;
};
};
config.services.tailscale = {
inherit (cfg) enable;
extraSetFlags = [
"--accept-dns"
"--accept-routes"
"--ssh"
];
};
services.tailscale = {
enable = true;
extraSetFlags = [
"--accept-dns"
"--accept-routes"
"--ssh"
];
};
};
}
+52
View File
@@ -0,0 +1,52 @@
#+title: Tailscale
#+setupfile: ../headers
* Tailscale
I use [[https://tailscale.com/][Tailscale]] as the mesh VPN tying all my machines together. Here’s
the =nixos.tailscale= module.
#+begin_src nix :tangle yes
{
flake.modules.nixos.tailscale = {
services.tailscale = {
<<enable>>
<<extra-flags>>
};
};
}
#+end_src
** Enabling Tailscale
#+name: enable
#+begin_src nix
enable = true;
#+end_src
** Extra Flags
I add some extra flags for Tailscale.
#+name: flags
| Flag | Why |
|-----------------+---------------------------------------------------------|
| =--accept-dns= | Turns on MagicDNS |
| =--accept-routes= | Let this machine use subnets advertised by other nodes |
| =--ssh= | Turns on Tailscale’s own SSH server for easy SSH access |
#+name: make-flags
#+begin_src emacs-lisp :exports none :var flags=flags :cache yes
(mapconcat (lambda (flag)
(replace-regexp-in-string "=" "\"" (car flag)))
flags
"\n")
#+end_src
#+RESULTS[4969e8a817fa6617e136b57d47a43d6e21ce2a7b]: make-flags
: "--accept-dns"
: "--accept-routes"
: "--ssh"
#+name: extra-flags
#+begin_src nix
extraSetFlags = [
<<make-flags()>>
];
#+end_src