feat: enable better seperation of lxc dependencies

This commit is contained in:
silver 2023-11-16 01:09:35 +00:00
parent 4a95e48179
commit 4c0f3a1645
13 changed files with 196 additions and 101 deletions

View file

@ -0,0 +1,93 @@
/*
Once https://github.com/NixOS/nixpkgs/pull/267764 is merged this can be removed
*/
{
config,
pkgs,
lib,
...
}:
with lib; {
options.proxmoxLXC = {
enable = mkOption {
default = true;
type = types.bool;
description = lib.mdDoc "Whether to enable the ProxmoxLXC.";
};
privileged = mkOption {
type = types.bool;
default = false;
description = lib.mdDoc ''
Whether to enable privileged mounts
'';
};
manageNetwork = mkOption {
type = types.bool;
default = false;
description = lib.mdDoc ''
Whether to manage network interfaces through nix options
When false, systemd-networkd is enabled to accept network
configuration from proxmox.
'';
};
manageHostName = mkOption {
type = types.bool;
default = false;
description = lib.mdDoc ''
Whether to manage hostname through nix options
When false, the hostname is picked up from /etc/hostname
populated by proxmox.
'';
};
};
config = let
cfg = config.proxmoxLXC;
in
mkIf cfg.enable {
system.build.tarball = pkgs.callPackage ../../lib/make-system-tarball.nix {
storeContents = [
{
object = config.system.build.toplevel;
symlink = "none";
}
];
contents = [
{
source = config.system.build.toplevel + "/init";
target = "/sbin/init";
}
];
extraCommands = "mkdir -p root etc/systemd/network";
};
boot = {
isContainer = true;
loader.initScript.enable = true;
};
networking = mkIf (!cfg.manageNetwork) {
useDHCP = false;
useHostResolvConf = false;
useNetworkd = true;
# pick up hostname from /etc/hostname generated by proxmox
hostName = mkIf (!cfg.manageHostName) (mkForce "");
};
services.openssh = {
enable = mkDefault true;
startWhenNeeded = mkDefault true;
};
systemd.mounts =
mkIf (!cfg.privileged)
[
{
where = "/sys/kernel/debug";
enable = false;
}
];
};
}

View file

@ -4,9 +4,17 @@
config, config,
options, options,
inputs, inputs,
lib,
... ...
}: { }:
with lib; let
cfg = config.skynet;
in {
imports = [ imports = [
# custom lxc mocule until the patch gets merged in
../applications/proxmox-lxc.nix
# (modulesPath + "/virtualisation/proxmox-lxc.nix")
# for the secrets # for the secrets
inputs.agenix.nixosModules.default inputs.agenix.nixosModules.default
@ -23,7 +31,18 @@
../applications/restic.nix ../applications/restic.nix
]; ];
boot.kernelPackages = pkgs.linuxPackages_latest; options.skynet = {
lxc = mkOption {
type = types.bool;
# most of our servers are lxc so its true by default
default = true;
description = mdDoc "Is this a Linux Container?";
};
};
config = {
# if its a lxc enable
proxmoxLXC.enable = cfg.lxc;
nix = { nix = {
settings = { settings = {
@ -113,4 +132,5 @@
pkgs.openldap pkgs.openldap
pkgs.screen pkgs.screen
]; ];
};
} }

View file

@ -12,7 +12,6 @@ Notes:
pkgs, pkgs,
lib, lib,
nodes, nodes,
modulesPath,
... ...
}: let }: let
# name of the server, sets teh hostname and record for it # name of the server, sets teh hostname and record for it
@ -21,7 +20,6 @@ Notes:
hostname = "${name}.skynet.ie"; hostname = "${name}.skynet.ie";
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/nextcloud.nix ../applications/nextcloud.nix
]; ];

View file

@ -13,7 +13,6 @@ Notes:
lib, lib,
nodes, nodes,
inputs, inputs,
modulesPath,
... ...
}: let }: let
name = "earth"; name = "earth";
@ -21,7 +20,6 @@ Notes:
hostname = "${name}.skynet.ie"; hostname = "${name}.skynet.ie";
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/skynet.ie.nix ../applications/skynet.ie.nix
]; ];

View file

@ -13,7 +13,6 @@ Notes:
lib, lib,
nodes, nodes,
config, config,
modulesPath,
... ...
}: let }: let
# name of the server, sets teh hostname and record for it # name of the server, sets teh hostname and record for it
@ -22,7 +21,6 @@ Notes:
hostname = "${name}.skynet.ie"; hostname = "${name}.skynet.ie";
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/ulfm.nix ../applications/ulfm.nix
]; ];

View file

@ -12,7 +12,6 @@ Notes:
pkgs, pkgs,
lib, lib,
nodes, nodes,
modulesPath,
... ...
}: let }: let
# name of the server, sets teh hostname and record for it # name of the server, sets teh hostname and record for it
@ -22,7 +21,6 @@ Notes:
#hostname = ip_pub; #hostname = ip_pub;
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/email.nix ../applications/email.nix
]; ];

View file

@ -13,7 +13,6 @@ Notes: Each user has roughly 20gb os storage
pkgs, pkgs,
lib, lib,
nodes, nodes,
modulesPath,
... ...
}: let }: let
# name of the server, sets teh hostname and record for it # name of the server, sets teh hostname and record for it
@ -22,7 +21,6 @@ Notes: Each user has roughly 20gb os storage
hostname = "${name}.skynet.ie"; hostname = "${name}.skynet.ie";
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/gitlab.nix ../applications/gitlab.nix
]; ];

View file

@ -11,6 +11,8 @@ with lib; let
has_ip = interface: (length config.networking.interfaces."${interface}".ipv4.addresses) != 0; has_ip = interface: (length config.networking.interfaces."${interface}".ipv4.addresses) != 0;
in { in {
config = { config = {
skynet.lxc = false;
assertions = [ assertions = [
{ {
assertion = lists.any has_ip interfaces; assertion = lists.any has_ip interfaces;

View file

@ -12,7 +12,6 @@ Notes:
pkgs, pkgs,
lib, lib,
nodes, nodes,
modulesPath,
... ...
}: let }: let
# name of the server, sets teh hostname and record for it # name of the server, sets teh hostname and record for it
@ -22,7 +21,6 @@ Notes:
#hostname = ip_pub; #hostname = ip_pub;
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/ldap/server.nix ../applications/ldap/server.nix
../applications/discord.nix ../applications/discord.nix
../applications/bitwarden/vaultwarden.nix ../applications/bitwarden/vaultwarden.nix

View file

@ -13,7 +13,6 @@ Notes:
lib, lib,
nodes, nodes,
arion, arion,
modulesPath,
... ...
}: let }: let
# name of the server, sets teh hostname and record for it # name of the server, sets teh hostname and record for it
@ -22,7 +21,6 @@ Notes:
hostname = "${name}.skynet.ie"; hostname = "${name}.skynet.ie";
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/games.nix ../applications/games.nix
]; ];

View file

@ -13,7 +13,6 @@ Notes: Does not host offical sites
lib, lib,
nodes, nodes,
inputs, inputs,
modulesPath,
... ...
}: let }: let
name = "skynet"; name = "skynet";
@ -23,7 +22,6 @@ Notes: Does not host offical sites
hostname = "${name}.skynet.ie"; hostname = "${name}.skynet.ie";
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/skynet_users.nix ../applications/skynet_users.nix
]; ];

View file

@ -12,7 +12,6 @@ Notes:
pkgs, pkgs,
lib, lib,
nodes, nodes,
modulesPath,
... ...
}: let }: let
name = "vigil"; name = "vigil";
@ -20,7 +19,6 @@ Notes:
hostname = "${name}.skynet.ie"; hostname = "${name}.skynet.ie";
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
]; ];
deployment = { deployment = {

View file

@ -12,7 +12,6 @@ Notes:
pkgs, pkgs,
lib, lib,
nodes, nodes,
modulesPath,
... ...
}: let }: let
# name of the server, sets teh hostname and record for it # name of the server, sets teh hostname and record for it
@ -21,7 +20,6 @@ Notes:
hostname = "${name}.skynet.ie"; hostname = "${name}.skynet.ie";
in { in {
imports = [ imports = [
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../applications/gitlab_runner.nix ../applications/gitlab_runner.nix
]; ];