diff --git a/AGENTS.md b/AGENTS.md index 901a2eb..bc92c67 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -549,6 +549,23 @@ A host registry may use a specification like this: "interface.minimal" "platform.vm" "workload.remote-access" + "workload.deploy-rs-target" + ]; + }; + + netsrv-01 = { + system = "x86_64-linux"; + stateVersion = "26.05"; + user = "moons"; + path = ./netsrv-01; + + profiles = [ + "base" + "interface.minimal" + "platform.vm" + "workload.remote-access" + "workload.deploy-rs-target" + "workload.server" ]; }; @@ -658,7 +675,8 @@ A host registry may use a specification like this: The current role assignment is intentional: nix-example is the development VM; ops is the minimal-interface remote-access VM with host-specific static -networking; internal-app-01 is the minimal-interface container server VM; +networking; netsrv-01 is the deploy-rs-managed container server VM; +internal-app-01 is the minimal-interface container server VM; nix-builder is the minimal-interface remote Nix build VM with dedicated build and store disks; and installer builds the minimal installation ISO without Home Manager. x1g9 is a full NixOS desktop with niri, @@ -703,6 +721,11 @@ hosts/ │ ├── disko.nix │ ├── hardware-configuration.nix │ └── nixos.nix +├── netsrv-01/ +│ ├── disko.nix +│ ├── hardware-configuration.nix +│ ├── networking.nix +│ └── nixos.nix ├── installer/ │ └── nixos.nix ├── internal-app-01/ @@ -843,8 +866,9 @@ For profile changes, additionally: `homebrew.casks` selection as well as module evaluation. - Preserve the intended host roles: nix-example remains the development VM; ops remains the statically networked remote-access VM; internal-app-01 remains - the container server VM; installer remains the Home Manager-free installation - ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13 + the container server VM; netsrv-01 remains the deploy-rs-managed container + server VM; installer remains the Home Manager-free installation ISO; x1g9 + provides niri, labwc, ly, and the personal application set; x1g13 additionally provides the development, Tailscale client, secrets, Secure Boot, and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development diff --git a/hosts/default.nix b/hosts/default.nix index 17631c5..7754192 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -28,6 +28,22 @@ ]; }; + netsrv-01 = { + system = "x86_64-linux"; + stateVersion = "26.05"; + user = "moons"; + path = ./netsrv-01; + + profiles = [ + "base" + "interface.minimal" + "platform.vm" + "workload.remote-access" + "workload.deploy-rs-target" + "workload.server" + ]; + }; + installer = { system = "x86_64-linux"; stateVersion = "26.05"; diff --git a/hosts/netsrv-01/disko.nix b/hosts/netsrv-01/disko.nix new file mode 100644 index 0000000..e9fe39b --- /dev/null +++ b/hosts/netsrv-01/disko.nix @@ -0,0 +1,30 @@ +_: { + disko.enableConfig = true; + + disko.devices.disk.main = { + type = "disk"; + device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0"; + content = { + type = "gpt"; + partitions = { + ESP = { + size = "512M"; + type = "EF00"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + }; + }; + root = { + size = "100%"; + content = { + type = "filesystem"; + format = "ext4"; + mountpoint = "/"; + }; + }; + }; + }; + }; +} diff --git a/hosts/netsrv-01/hardware-configuration.nix b/hosts/netsrv-01/hardware-configuration.nix new file mode 100644 index 0000000..22f2567 --- /dev/null +++ b/hosts/netsrv-01/hardware-configuration.nix @@ -0,0 +1,27 @@ +# QEMU hardware baseline. Replace this with the output of +# `nixos-generate-config` after provisioning the VM if its hardware differs. +{ + lib, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ + "ata_piix" + "uhci_hcd" + "virtio_pci" + "virtio_scsi" + "sd_mod" + "sr_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} diff --git a/hosts/netsrv-01/networking.nix b/hosts/netsrv-01/networking.nix new file mode 100644 index 0000000..d887b28 --- /dev/null +++ b/hosts/netsrv-01/networking.nix @@ -0,0 +1,30 @@ +{ + networking = { + interfaces = { + ens18 = { + useDHCP = false; + ipv4.addresses = [ + { + address = "10.50.65.11"; + prefixLength = 24; + } + ]; + }; + + ens19 = { + useDHCP = false; + ipv4.addresses = [ + { + address = "10.50.66.10"; + prefixLength = 24; + } + ]; + }; + }; + + defaultGateway = { + address = "10.50.66.1"; + interface = "ens19"; + }; + }; +} diff --git a/hosts/netsrv-01/nixos.nix b/hosts/netsrv-01/nixos.nix new file mode 100644 index 0000000..37acd5a --- /dev/null +++ b/hosts/netsrv-01/nixos.nix @@ -0,0 +1,7 @@ +{ + imports = [ + ./hardware-configuration.nix + ./disko.nix + ./networking.nix + ]; +}