Configuration is now held by the `.org` files. All `.nix` files are tangled from the org-mode files.
4.1 KiB
Networking
Networking
This module centralises the basic networking identity of a host —
hostname, host ID, domain, NetworkManager and the firewall — behind a
single mySystem.networking namespace. Here’s the skeleton of the
nixos.networking module.
{...}: {
flake.modules.nixos.networking = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.networking;
in {
<<hostname>>
<<host-id>>
<<domain>>
<<host-files>>
<<wifi-powersave>>
<<firewall-ports>>
<<firewall-port-ranges>>
<<firewall-extra-commands>>
};
}
Hostname
options.mySystem.networking.hostname = mkOption {
type = types.str;
example = "gampo";
};
config.networking.hostName = cfg.hostname;
Host ID
Every host needs a unique hostId; besides identifying the machine on
the network, ZFS also uses it to guard against accidentally importing
a pool that’s still active on another machine (see ZFS Support).
options.mySystem.networking.id = mkOption {
type = types.str;
example = "deadb33f";
};
config.networking.hostId = cfg.id;
Domain
Not every host needs a domain name, so this defaults to null.
options.mySystem.networking.domain = mkOption {
type = types.nullOr types.str;
example = "phundrak.com";
default = null;
};
config.networking.domain = cfg.domain;
Extra Host Files
hostFiles lets a host point at extra files to merge into /etc/hosts,
on top of whatever NixOS generates itself.
options.mySystem.networking.hostFiles = mkOption {
type = types.listOf types.path;
example = [/path/to/hostFile];
default = [];
};
config.networking.hostFiles = cfg.hostFiles;
NetworkManager and WiFi Powersave
NetworkManager is always enabled; the only thing a host can tune here
is WiFi powersave. I mainly need to turn it off on the PineTab2, since
leaving powersave on with its bes2600 WiFi chip causes stability
issues.
options.mySystem.networking.wifi.disablePowersave = mkEnableOption ''
Disables powersave for Wifi.
Used mainly for the PineTab2, as leaving WiFi powersave with the bes2600 can cause stability issues.
'';
config.networking.networkmanager = {
enable = true;
wifi.powersave = !cfg.wifi.disablePowersave;
};
Firewall: Ports
This also turns the firewall itself on; openPorts is just the plain
list of single ports to open, on both TCP and UDP.
options.mySystem.networking.firewall.openPorts = mkOption {
type = types.listOf types.int;
example = [22 80 443];
default = [];
};
config.networking.firewall = {
enable = true;
allowedTCPPorts = cfg.firewall.openPorts;
allowedUDPPorts = cfg.firewall.openPorts;
};
Firewall: Port Ranges
openPortRanges does the same, but for a contiguous range of ports at
once, again on both TCP and UDP.
options.mySystem.networking.firewall.openPortRanges = mkOption {
type = types.listOf (types.attrsOf types.port);
default = [];
example = [
{
from = 8080;
to = 8082;
}
];
description = ''
A range of TCP and UDP ports on which incoming connections are
accepted.
'';
};
config.networking.firewall = {
allowedTCPPortRanges = cfg.firewall.openPortRanges;
allowedUDPPortRanges = cfg.firewall.openPortRanges;
};
Firewall: Extra Commands
For anything the declarative options above can’t express, extraCommands
lets a host drop raw iptables commands straight into the firewall
setup.
options.mySystem.networking.firewall.extraCommands = mkOption {
type = types.nullOr types.lines;
example = "iptables -A INPUTS -p icmp -j ACCEPT";
default = null;
};
config.networking.firewall.extraCommands = mkIf (cfg.firewall.extraCommands != null) cfg.firewall.extraCommands;