Upgrade clan to 26.05

Bump clan-core and nixos-mailserver to 26.05 (NixOS 26.05) and adapt to
the breaking changes surfaced by nix flake check:

- mesh-hosts/clan.nix: read the new shared, instance-scoped zerotier vars
  (zerotier-ip-<machine>-zerotier, zerotier-network-zerotier); admit
  external members via the controller's native allowedIds.
- monitoring/server.nix: Grafana lost its built-in secret_key default;
  mint one via a clan generator and pass it with $__file{}.
- dns/authoritative.nix: services.resolved.extraConfig removed -> settings.
- mail.nix: SNM cert API change (x509.useACMEHost + acme extraDomainNames)
  and accounts/dkim option renames.
- docs: mesh runbook updated for the new var paths and allowedIds.
This commit is contained in:
Berwn
2026-06-25 10:17:32 +07:00
parent 9bcc5ae2e3
commit 48fcc3058b
8 changed files with 98 additions and 108 deletions
+12 -10
View File
@@ -98,29 +98,31 @@ in
mailserver = {
enable = true;
# Fresh install: declare the latest layout the nixos-25.11 branch ships (3),
# Fresh install: declare the latest layout the nixos-26.05 branch ships (3),
# so SNM uses the current dovecot mail directory layout with nothing to migrate.
stateVersion = 3;
inherit fqdn;
domains = [ "cnx.email" ];
inherit loginAccounts;
accounts = loginAccounts;
# Consume a security.acme cert we obtain ourselves via DNS-01 (below); no
# web server and no inbound HTTP needed, so port 80 stays closed. Add the
# MTA-STS host as a SAN so the one cert also covers the policy endpoint.
certificateScheme = "acme";
certificateDomains = [
mtaStsHost
clientHost
];
# web server and no inbound HTTP needed, so port 80 stays closed. The extra
# SAN hosts (MTA-STS, client alias) are attached to that cert via
# security.acme.certs.${fqdn}.extraDomainNames below.
x509.useACMEHost = fqdn;
dkimSelector = "mail";
dkim.defaults.selector = "mail";
};
security.acme = {
acceptTerms = true;
defaults.email = "postmaster@cnx.email";
certs.${fqdn} = {
# The MTA-STS endpoint and client-facing alias ride this one cert as SANs.
extraDomainNames = [
mtaStsHost
clientHost
];
dnsProvider = "rfc2136";
environmentFile = config.clan.core.vars.generators.dns-acme-rfc2136.files."rfc2136.env".path;
# ns1 is the only nameserver that accepts the acme_mx1 UPDATE; check