netsrv-01

This commit is contained in:
2026-09-04 01:04:52 +09:00
parent 2d9154614b
commit 7d670b03b2
6 changed files with 137 additions and 3 deletions
+27 -3
View File
@@ -549,6 +549,23 @@ A host registry may use a specification like this:
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
];
};
netsrv-01 = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./netsrv-01;
profiles = [
"base"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
"workload.server"
];
};
@@ -658,7 +675,8 @@ A host registry may use a specification like this:
The current role assignment is intentional: nix-example is the development VM;
ops is the minimal-interface remote-access VM with host-specific static
networking; internal-app-01 is the minimal-interface container server VM;
networking; netsrv-01 is the deploy-rs-managed container server VM;
internal-app-01 is the minimal-interface container server VM;
nix-builder is the minimal-interface remote Nix build VM with dedicated build
and store disks; and installer builds the minimal installation ISO without Home
Manager. x1g9 is a full NixOS desktop with niri,
@@ -703,6 +721,11 @@ hosts/
│ ├── disko.nix
│ ├── hardware-configuration.nix
│ └── nixos.nix
├── netsrv-01/
│ ├── disko.nix
│ ├── hardware-configuration.nix
│ ├── networking.nix
│ └── nixos.nix
├── installer/
│ └── nixos.nix
├── internal-app-01/
@@ -843,8 +866,9 @@ For profile changes, additionally:
`homebrew.casks` selection as well as module evaluation.
- Preserve the intended host roles: nix-example remains the development VM;
ops remains the statically networked remote-access VM; internal-app-01 remains
the container server VM; installer remains the Home Manager-free installation
ISO; x1g9 provides niri, labwc, ly, and the personal application set; x1g13
the container server VM; netsrv-01 remains the deploy-rs-managed container
server VM; installer remains the Home Manager-free installation ISO; x1g9
provides niri, labwc, ly, and the personal application set; x1g13
additionally provides the development, Tailscale client, secrets, Secure Boot,
and TPM storage roles; galleria remains the Intel/NVIDIA dual-boot desktop
with LUKS, Secure Boot, and TPM storage; m2 remains the daily-use development
+16
View File
@@ -28,6 +28,22 @@
];
};
netsrv-01 = {
system = "x86_64-linux";
stateVersion = "26.05";
user = "moons";
path = ./netsrv-01;
profiles = [
"base"
"interface.minimal"
"platform.vm"
"workload.remote-access"
"workload.deploy-rs-target"
"workload.server"
];
};
installer = {
system = "x86_64-linux";
stateVersion = "26.05";
+30
View File
@@ -0,0 +1,30 @@
_: {
disko.enableConfig = true;
disko.devices.disk.main = {
type = "disk";
device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
size = "100%";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
};
};
};
}
@@ -0,0 +1,27 @@
# QEMU hardware baseline. Replace this with the output of
# `nixos-generate-config` after provisioning the VM if its hardware differs.
{
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [
"ata_piix"
"uhci_hcd"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
+30
View File
@@ -0,0 +1,30 @@
{
networking = {
interfaces = {
ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.65.11";
prefixLength = 24;
}
];
};
ens19 = {
useDHCP = false;
ipv4.addresses = [
{
address = "10.50.66.10";
prefixLength = 24;
}
];
};
};
defaultGateway = {
address = "10.50.66.1";
interface = "ens19";
};
};
}
+7
View File
@@ -0,0 +1,7 @@
{
imports = [
./hardware-configuration.nix
./disko.nix
./networking.nix
];
}