pxeboot chain
This commit is contained in:
parent
5ee0a9c5cf
commit
acace867a8
6 changed files with 105 additions and 21 deletions
108
common.nix
108
common.nix
|
|
@ -26,9 +26,14 @@
|
||||||
users.users.root.hashedPasswordFile = "/secrets/user/root-pw";
|
users.users.root.hashedPasswordFile = "/secrets/user/root-pw";
|
||||||
networking = {
|
networking = {
|
||||||
firewall = {
|
firewall = {
|
||||||
allowedTCPPorts = [ 53 80 ];
|
allowedTCPPorts = [ 53 80 2049 ];
|
||||||
allowedUDPPorts = [ 53 67 69 547 ];
|
allowedUDPPorts = [ 53 67 69 547 ];
|
||||||
};
|
};
|
||||||
|
nat = {
|
||||||
|
enable = true;
|
||||||
|
enableIPv6 = true;
|
||||||
|
internalInterfaces = [ "enp1s0" ];
|
||||||
|
};
|
||||||
wg-quick.interfaces.awg0 = {
|
wg-quick.interfaces.awg0 = {
|
||||||
type = "amneziawg";
|
type = "amneziawg";
|
||||||
peers = [ {
|
peers = [ {
|
||||||
|
|
@ -40,19 +45,35 @@
|
||||||
enable = true;
|
enable = true;
|
||||||
ensureProfiles = {
|
ensureProfiles = {
|
||||||
environmentFiles = [ "/secrets/wifi.env" ];
|
environmentFiles = [ "/secrets/wifi.env" ];
|
||||||
profiles.home-wifi = {
|
profiles = {
|
||||||
wifi-security.key-mgmt = "sae";
|
ethernet = {
|
||||||
connection = {
|
ipv6 = {
|
||||||
id = "home-wifi";
|
method = "manual";
|
||||||
type = "wifi";
|
addresses = "fc02::1/64";
|
||||||
|
};
|
||||||
|
ipv4 = {
|
||||||
|
method = "manual";
|
||||||
|
addresses = "10.2.0.1/16";
|
||||||
|
};
|
||||||
|
connection = {
|
||||||
|
id = "ethernet";
|
||||||
|
type = "802-3-ethernet";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
ipv6 = {
|
wifi = {
|
||||||
method = "manual";
|
wifi-security.key-mgmt = "sae";
|
||||||
gateway = "fc01::1";
|
ipv6 = {
|
||||||
};
|
method = "manual";
|
||||||
ipv4 = {
|
gateway = "fc01::1";
|
||||||
method = "manual";
|
};
|
||||||
gateway = "10.1.0.1";
|
ipv4 = {
|
||||||
|
method = "manual";
|
||||||
|
gateway = "10.1.0.1";
|
||||||
|
};
|
||||||
|
connection = {
|
||||||
|
id = "wifi";
|
||||||
|
type = "802-11-wireless";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
@ -60,7 +81,11 @@
|
||||||
};
|
};
|
||||||
environment.systemPackages = with pkgs; [
|
environment.systemPackages = with pkgs; [
|
||||||
jq
|
jq
|
||||||
|
_7zz
|
||||||
sbctl
|
sbctl
|
||||||
|
dracut
|
||||||
|
openssl
|
||||||
|
grub2_efi
|
||||||
];
|
];
|
||||||
services = {
|
services = {
|
||||||
logind.settings.Login.HandleLidSwitch = "ignore";
|
logind.settings.Login.HandleLidSwitch = "ignore";
|
||||||
|
|
@ -76,6 +101,15 @@
|
||||||
recommendedProxySettings = true;
|
recommendedProxySettings = true;
|
||||||
recommendedBrotliSettings = true;
|
recommendedBrotliSettings = true;
|
||||||
};
|
};
|
||||||
|
nfs.server = {
|
||||||
|
enable = true;
|
||||||
|
exports = let
|
||||||
|
clients."10.2.0.0/16" = [ "mp" "rw" "no_root_squash" ];
|
||||||
|
in {
|
||||||
|
"/srv/nfs/arch/root" = clients;
|
||||||
|
"/srv/nfs/fedora/root" = clients;
|
||||||
|
};
|
||||||
|
};
|
||||||
dnsmasq = {
|
dnsmasq = {
|
||||||
enable = true;
|
enable = true;
|
||||||
settings = {
|
settings = {
|
||||||
|
|
@ -90,9 +124,53 @@
|
||||||
dhcp-boot = "grubx64.efi";
|
dhcp-boot = "grubx64.efi";
|
||||||
dhcp-range = [ "10.2.0.2,10.2.255.254,12h"
|
dhcp-range = [ "10.2.0.2,10.2.255.254,12h"
|
||||||
"fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ];
|
"fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ];
|
||||||
server = [ "2606:4700:4700::1112" "1.1.1.2"
|
server = [ "1.1.1.2" "2606:4700:4700::1112"
|
||||||
"2606:4700:4700::1002" "1.0.0.2" ];
|
"1.0.0.2" "2606:4700:4700::1002" ];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
systemd.services.pxeboot = {
|
||||||
|
serviceConfig.Type = "oneshot";
|
||||||
|
wantedBy = [ "multi-user.target" ];
|
||||||
|
path = with pkgs; [ xz dracut grub2_efi util-linux ];
|
||||||
|
script = let
|
||||||
|
grubCfg = pkgs.writeText "grub.cfg" ''
|
||||||
|
set timeout=10
|
||||||
|
set path=(http,$net_default_server)/local/boot/pxe
|
||||||
|
set nfs="rw ifname=ens0:$net_default_mac ip=$net_default_ip::$net_default_server:255.255.0.0::ens0:none root=nfs4:$net_default_server:/srv/nfs"
|
||||||
|
menuentry Arch {
|
||||||
|
linux $path/arch/linux $nfs/arch/root
|
||||||
|
initrd $path/arch/initramfs
|
||||||
|
}
|
||||||
|
menuentry Fedora {
|
||||||
|
linux $path/fedora/linux $nfs/fedora/root selinux=0
|
||||||
|
initrd $path/fedora/initramfs
|
||||||
|
}
|
||||||
|
'';
|
||||||
|
in ''
|
||||||
|
if [ ! -e /srv/tftp/grubx64.efi ]; then
|
||||||
|
echo "Building grub"
|
||||||
|
grub-mkstandalone -O x86_64-efi --compress=xz --modules=efinet -o /srv/tftp/grubx64.efi /boot/grub/grub.cfg=${grubCfg}
|
||||||
|
fi
|
||||||
|
for distro in arch:arch/x86_64/airootfs.sfs fedora:LiveOS/squashfs.img; do
|
||||||
|
rootfs=''${distro#*:}
|
||||||
|
distro=''${distro%%:*}
|
||||||
|
cd /srv/nfs/$distro
|
||||||
|
mkdir -p loop lower upper work root
|
||||||
|
mountpoint -q loop || mount $distro.iso loop
|
||||||
|
mountpoint -q lower || mount loop/$rootfs lower
|
||||||
|
mountpoint -q root || mount -t overlay overlay -o lowerdir=lower,upperdir=upper,workdir=work,nfs_export=on root
|
||||||
|
cd /srv/http/local/boot/pxe
|
||||||
|
if [ ! -e $distro ]; then
|
||||||
|
mkdir $distro
|
||||||
|
modsDir=$OLDPWD/lower/usr/lib/modules/*
|
||||||
|
cp $modsDir/vmlinuz $distro/linux
|
||||||
|
dracut -Nvm "network-manager nfs" --zstd --kver $(basename $modsDir) -k $modsDir $distro/initramfs
|
||||||
|
chmod -R 640 $distro
|
||||||
|
chgrp -R php $distro
|
||||||
|
chmod ug+x $distro
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
'';
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -20,7 +20,7 @@
|
||||||
configFile = "/secrets/awg/2.conf";
|
configFile = "/secrets/awg/2.conf";
|
||||||
address = [ "fc00::3/128" "10.0.0.3/32" ];
|
address = [ "fc00::3/128" "10.0.0.3/32" ];
|
||||||
};
|
};
|
||||||
networkmanager.ensureProfiles.profiles.home-wifi = {
|
networkmanager.ensureProfiles.profiles.wifi = {
|
||||||
wifi.ssid = "bogale_5";
|
wifi.ssid = "bogale_5";
|
||||||
ipv6.addresses = "fc01::3/64";
|
ipv6.addresses = "fc01::3/64";
|
||||||
ipv4.addresses = "10.1.0.3/16";
|
ipv4.addresses = "10.1.0.3/16";
|
||||||
|
|
|
||||||
|
|
@ -40,7 +40,7 @@
|
||||||
configFile = "/secrets/awg/1.conf";
|
configFile = "/secrets/awg/1.conf";
|
||||||
address = [ "fc00::2/128" "10.0.0.2/32" ];
|
address = [ "fc00::2/128" "10.0.0.2/32" ];
|
||||||
};
|
};
|
||||||
networkmanager.ensureProfiles.profiles.home-wifi = {
|
networkmanager.ensureProfiles.profiles.wifi = {
|
||||||
wifi.ssid = "bogale_2.4";
|
wifi.ssid = "bogale_2.4";
|
||||||
ipv6.addresses = "fc01::2/64";
|
ipv6.addresses = "fc01::2/64";
|
||||||
ipv4.addresses = "10.1.0.2/16";
|
ipv4.addresses = "10.1.0.2/16";
|
||||||
|
|
|
||||||
|
|
@ -33,17 +33,21 @@ in {
|
||||||
smtpd_sasl_path = "${postfixDir}/auth";
|
smtpd_sasl_path = "${postfixDir}/auth";
|
||||||
milter_macro_daemon_name = "ORIGINATING";
|
milter_macro_daemon_name = "ORIGINATING";
|
||||||
smtpd_client_restrictions = "permit_sasl_authenticated,reject";
|
smtpd_client_restrictions = "permit_sasl_authenticated,reject";
|
||||||
smtpd_tls_chain_files = "${sslCertDir}/key.pem,${sslCertDir}/fullchain.pem";
|
|
||||||
};
|
};
|
||||||
settings.main = {
|
settings.main = {
|
||||||
smtp_tls_wrappermode = true;
|
smtp_tls_wrappermode = true;
|
||||||
smtp_sasl_auth_enable = true;
|
smtp_sasl_auth_enable = true;
|
||||||
smtp_tls_security_level = "verify";
|
smtp_tls_security_level = "verify";
|
||||||
|
smtpd_tls_security_level = "encrypt";
|
||||||
relayhost = [ "smtp.resend.com:2465" ];
|
relayhost = [ "smtp.resend.com:2465" ];
|
||||||
virtual_mailbox_domains = "bogaledev.ru";
|
virtual_mailbox_domains = "bogaledev.ru";
|
||||||
smtp_sasl_tls_security_options = "noanonymous";
|
smtp_sasl_tls_security_options = "noanonymous";
|
||||||
virtual_transport = "lmtp:unix:${postfixDir}/lmtp";
|
virtual_transport = "lmtp:unix:${postfixDir}/lmtp";
|
||||||
smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd";
|
smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd";
|
||||||
|
smtpd_tls_chain_files = [
|
||||||
|
"${sslCertDir}/key.pem"
|
||||||
|
"${sslCertDir}/fullchain.pem"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
dovecot2 = {
|
dovecot2 = {
|
||||||
|
|
|
||||||
|
|
@ -71,7 +71,7 @@
|
||||||
failures=$((1+$(cat /run/network.failures)))
|
failures=$((1+$(cat /run/network.failures)))
|
||||||
fi
|
fi
|
||||||
if [ $failures -ge $limit ]; then
|
if [ $failures -ge $limit ]; then
|
||||||
echo "<4>restarting NetworkManager"
|
echo "<4>restarting network"
|
||||||
systemctl restart NetworkManager.service
|
systemctl restart NetworkManager.service
|
||||||
[ $limit -lt 360 ] && limit=$((2*$limit))
|
[ $limit -lt 360 ] && limit=$((2*$limit))
|
||||||
failures=0
|
failures=0
|
||||||
|
|
|
||||||
|
|
@ -77,15 +77,17 @@
|
||||||
'';
|
'';
|
||||||
localNetworks = ''
|
localNetworks = ''
|
||||||
allow fc00::/64;
|
allow fc00::/64;
|
||||||
allow fc01::/120;
|
allow fc01::/96;
|
||||||
|
allow fc02::/64;
|
||||||
allow 10.0.0.0/16;
|
allow 10.0.0.0/16;
|
||||||
allow 10.1.0.0/24;
|
allow 10.1.0.0/24;
|
||||||
|
allow 10.2.0.0/16;
|
||||||
deny all;
|
deny all;
|
||||||
'';
|
'';
|
||||||
in {
|
in {
|
||||||
quic = true;
|
quic = true;
|
||||||
|
addSSL = true;
|
||||||
default = true;
|
default = true;
|
||||||
forceSSL = true;
|
|
||||||
root = "/srv/http";
|
root = "/srv/http";
|
||||||
useACMEHost = "bogaledev.ru";
|
useACMEHost = "bogaledev.ru";
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue