Files
nix-config/modules/network/networking.org
T
phundrak ba018ef841 refactor: change to litterate config
Configuration is now held by the `.org` files. All `.nix` files are
tangled from the org-mode files.
2026-10-06 12:40:58 +02:00

4.1 KiB
Raw Blame History

Networking

Networking

This module centralises the basic networking identity of a host — hostname, host ID, domain, NetworkManager and the firewall — behind a single mySystem.networking namespace. Here’s the skeleton of the nixos.networking module.

{...}: {
  flake.modules.nixos.networking = {
    lib,
    config,
    ...
  }:
    with lib; let
      cfg = config.mySystem.networking;
    in {
      <<hostname>>
      <<host-id>>
      <<domain>>
      <<host-files>>
      <<wifi-powersave>>
      <<firewall-ports>>
      <<firewall-port-ranges>>
      <<firewall-extra-commands>>
    };
}

Hostname

options.mySystem.networking.hostname = mkOption {
  type = types.str;
  example = "gampo";
};
config.networking.hostName = cfg.hostname;

Host ID

Every host needs a unique hostId; besides identifying the machine on the network, ZFS also uses it to guard against accidentally importing a pool that’s still active on another machine (see ZFS Support).

options.mySystem.networking.id = mkOption {
  type = types.str;
  example = "deadb33f";
};
config.networking.hostId = cfg.id;

Domain

Not every host needs a domain name, so this defaults to null.

options.mySystem.networking.domain = mkOption {
  type = types.nullOr types.str;
  example = "phundrak.com";
  default = null;
};
config.networking.domain = cfg.domain;

Extra Host Files

hostFiles lets a host point at extra files to merge into /etc/hosts, on top of whatever NixOS generates itself.

options.mySystem.networking.hostFiles = mkOption {
  type = types.listOf types.path;
  example = [/path/to/hostFile];
  default = [];
};
config.networking.hostFiles = cfg.hostFiles;

NetworkManager and WiFi Powersave

NetworkManager is always enabled; the only thing a host can tune here is WiFi powersave. I mainly need to turn it off on the PineTab2, since leaving powersave on with its bes2600 WiFi chip causes stability issues.

options.mySystem.networking.wifi.disablePowersave = mkEnableOption ''
  Disables powersave for Wifi.

    Used mainly for the PineTab2, as leaving WiFi powersave with the bes2600 can cause stability issues.
'';
config.networking.networkmanager = {
  enable = true;
  wifi.powersave = !cfg.wifi.disablePowersave;
};

Firewall: Ports

This also turns the firewall itself on; openPorts is just the plain list of single ports to open, on both TCP and UDP.

options.mySystem.networking.firewall.openPorts = mkOption {
  type = types.listOf types.int;
  example = [22 80 443];
  default = [];
};
config.networking.firewall = {
  enable = true;
  allowedTCPPorts = cfg.firewall.openPorts;
  allowedUDPPorts = cfg.firewall.openPorts;
};

Firewall: Port Ranges

openPortRanges does the same, but for a contiguous range of ports at once, again on both TCP and UDP.

options.mySystem.networking.firewall.openPortRanges = mkOption {
  type = types.listOf (types.attrsOf types.port);
  default = [];
  example = [
    {
      from = 8080;
      to = 8082;
    }
  ];
  description = ''
    A range of TCP and UDP ports on which incoming connections are
    accepted.
  '';
};
config.networking.firewall = {
  allowedTCPPortRanges = cfg.firewall.openPortRanges;
  allowedUDPPortRanges = cfg.firewall.openPortRanges;
};

Firewall: Extra Commands

For anything the declarative options above can’t express, extraCommands lets a host drop raw iptables commands straight into the firewall setup.

options.mySystem.networking.firewall.extraCommands = mkOption {
  type = types.nullOr types.lines;
  example = "iptables -A INPUTS -p icmp -j ACCEPT";
  default = null;
};
config.networking.firewall.extraCommands = mkIf (cfg.firewall.extraCommands != null) cfg.firewall.extraCommands;