Files
nix-config/modules/network/networking.org
T
phundrak ba018ef841 refactor: change to litterate config
Configuration is now held by the `.org` files. All `.nix` files are
tangled from the org-mode files.
2026-10-06 12:40:58 +02:00

152 lines
4.1 KiB
Org Mode
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#+title: Networking
#+setupfile: ../headers
* Networking
This module centralises the basic networking identity of a host —
hostname, host ID, domain, NetworkManager and the firewall — behind a
single =mySystem.networking= namespace. Here’s the skeleton of the
=nixos.networking= module.
#+begin_src nix :tangle yes
{...}: {
flake.modules.nixos.networking = {
lib,
config,
...
}:
with lib; let
cfg = config.mySystem.networking;
in {
<<hostname>>
<<host-id>>
<<domain>>
<<host-files>>
<<wifi-powersave>>
<<firewall-ports>>
<<firewall-port-ranges>>
<<firewall-extra-commands>>
};
}
#+end_src
** Hostname
#+name: hostname
#+begin_src nix
options.mySystem.networking.hostname = mkOption {
type = types.str;
example = "gampo";
};
config.networking.hostName = cfg.hostname;
#+end_src
** Host ID
Every host needs a unique =hostId=; besides identifying the machine on
the network, ZFS also uses it to guard against accidentally importing
a pool that’s still active on another machine (see [[file:../boot/zfs.org][ZFS Support]]).
#+name: host-id
#+begin_src nix
options.mySystem.networking.id = mkOption {
type = types.str;
example = "deadb33f";
};
config.networking.hostId = cfg.id;
#+end_src
** Domain
Not every host needs a domain name, so this defaults to =null=.
#+name: domain
#+begin_src nix
options.mySystem.networking.domain = mkOption {
type = types.nullOr types.str;
example = "phundrak.com";
default = null;
};
config.networking.domain = cfg.domain;
#+end_src
** Extra Host Files
=hostFiles= lets a host point at extra files to merge into =/etc/hosts=,
on top of whatever NixOS generates itself.
#+name: host-files
#+begin_src nix
options.mySystem.networking.hostFiles = mkOption {
type = types.listOf types.path;
example = [/path/to/hostFile];
default = [];
};
config.networking.hostFiles = cfg.hostFiles;
#+end_src
** NetworkManager and WiFi Powersave
NetworkManager is always enabled; the only thing a host can tune here
is WiFi powersave. I mainly need to turn it off on the PineTab2, since
leaving powersave on with its =bes2600= WiFi chip causes stability
issues.
#+name: wifi-powersave
#+begin_src nix
options.mySystem.networking.wifi.disablePowersave = mkEnableOption ''
Disables powersave for Wifi.
Used mainly for the PineTab2, as leaving WiFi powersave with the bes2600 can cause stability issues.
'';
config.networking.networkmanager = {
enable = true;
wifi.powersave = !cfg.wifi.disablePowersave;
};
#+end_src
** Firewall: Ports
This also turns the firewall itself on; =openPorts= is just the plain
list of single ports to open, on both TCP and UDP.
#+name: firewall-ports
#+begin_src nix
options.mySystem.networking.firewall.openPorts = mkOption {
type = types.listOf types.int;
example = [22 80 443];
default = [];
};
config.networking.firewall = {
enable = true;
allowedTCPPorts = cfg.firewall.openPorts;
allowedUDPPorts = cfg.firewall.openPorts;
};
#+end_src
** Firewall: Port Ranges
=openPortRanges= does the same, but for a contiguous range of ports at
once, again on both TCP and UDP.
#+name: firewall-port-ranges
#+begin_src nix
options.mySystem.networking.firewall.openPortRanges = mkOption {
type = types.listOf (types.attrsOf types.port);
default = [];
example = [
{
from = 8080;
to = 8082;
}
];
description = ''
A range of TCP and UDP ports on which incoming connections are
accepted.
'';
};
config.networking.firewall = {
allowedTCPPortRanges = cfg.firewall.openPortRanges;
allowedUDPPortRanges = cfg.firewall.openPortRanges;
};
#+end_src
** Firewall: Extra Commands
For anything the declarative options above can’t express, =extraCommands=
lets a host drop raw =iptables= commands straight into the firewall
setup.
#+name: firewall-extra-commands
#+begin_src nix
options.mySystem.networking.firewall.extraCommands = mkOption {
type = types.nullOr types.lines;
example = "iptables -A INPUTS -p icmp -j ACCEPT";
default = null;
};
config.networking.firewall.extraCommands = mkIf (cfg.firewall.extraCommands != null) cfg.firewall.extraCommands;
#+end_src