From 5642a0f6fc7733fe56826e681503471c55065177 Mon Sep 17 00:00:00 2001 From: kurogeek Date: Thu, 6 Aug 2026 11:23:46 +0700 Subject: [PATCH] mob next [ci-skip] [ci skip] [skip ci] lastFile:machines/gw-cnx-1/configuration.nix --- machines/gw-cnx-1/configuration.nix | 110 ++++++++++++++-------------- 1 file changed, 55 insertions(+), 55 deletions(-) diff --git a/machines/gw-cnx-1/configuration.nix b/machines/gw-cnx-1/configuration.nix index c679df0..4320c31 100644 --- a/machines/gw-cnx-1/configuration.nix +++ b/machines/gw-cnx-1/configuration.nix @@ -4,7 +4,7 @@ { config, lib, ... }: { imports = [ - # ../../modules/router + ../../modules/router ../../modules/monitoring/exporters.nix (import ../../modules/dns/acme-gw-secret.nix "gw-cnx-1") ]; @@ -20,60 +20,60 @@ builtins.hashString "sha256" config.networking.hostName ); - # cnx.router = { - # enable = true; - # site = "cnx"; - # siteId = 1; - # wan.interface = "enp1s0"; - # wan.vlanId = null; # this ISP runs PPPoE untagged on the port - # trunkPorts = [ - # "enp2s0" - # # "enp3s0" # STAGING: serves as the uplink below until cutover - # ]; - # # Dedicated on-site recovery port: untagged mgmt, always available even - # # if the switch config is broken. - # accessPorts.enp4s0 = "mgmt"; - # # Replaces the newedge.house OPNsense box; renumbered to the fleet - # # convention (10.1..0/24, router .1, pool .100-.199). The old - # # untagged LAN becomes tagged mgmt — infra switch ports get PVID 10. - # vlans = { - # mgmt = { - # id = 10; # 10.1.10.0/24 — servers, APs, switches, Omada, admin - # dhcp.reservations.storinator01 = { - # hwAddress = "7c:c2:55:e0:d6:40"; - # ipAddress = "10.1.10.53"; - # }; - # }; - # lan.id = 20; # 10.1.20.0/24 — trusted clients - # iot.id = 40; # 10.1.40.0/24 - # voip.id = 50; # 10.1.50.0/24 - # dmz.id = 60; # 10.1.60.0/24 - # unit1.id = 110; # 10.1.110.0/24 - # unit2.id = 120; # 10.1.120.0/24 - # unit3.id = 130; # 10.1.130.0/24 - # unit4.id = 140; # 10.1.140.0/24 - # unit5 = { - # id = 150; # 10.1.150.0/24 - # dhcp.reservations.newt = { - # hwAddress = "7c:d3:0a:21:58:0b"; - # ipAddress = "10.1.150.22"; - # }; - # }; - # }; - # # This site runs the Omada controller for its APs/switches. - # omada.enable = true; - # - # # Internal reverse proxy: real wildcard cert *.cnx1.cnx.network; Blocky - # # resolves the names to the router's LAN address for mgmt+lan clients. - # proxy = { - # enable = true; - # services.omada = { - # # Omada's UI is HTTPS with a self-signed cert on the host network. - # backend = "https://127.0.0.1:8043"; - # insecureSkipVerify = true; - # }; - # }; - # }; + cnx.router = { + enable = true; + site = "cnx"; + siteId = 1; + wan.interface = "enp1s0"; + wan.vlanId = null; # this ISP runs PPPoE untagged on the port + trunkPorts = [ + "enp2s0" + # "enp3s0" # STAGING: serves as the uplink below until cutover + ]; + # Dedicated on-site recovery port: untagged mgmt, always available even + # if the switch config is broken. + accessPorts.enp4s0 = "mgmt"; + # Replaces the newedge.house OPNsense box; renumbered to the fleet + # convention (10.1..0/24, router .1, pool .100-.199). The old + # untagged LAN becomes tagged mgmt — infra switch ports get PVID 10. + vlans = { + mgmt = { + id = 10; # 10.1.10.0/24 — servers, APs, switches, Omada, admin + dhcp.reservations.storinator01 = { + hwAddress = "7c:c2:55:e0:d6:40"; + ipAddress = "10.1.10.53"; + }; + }; + lan.id = 20; # 10.1.20.0/24 — trusted clients + iot.id = 40; # 10.1.40.0/24 + voip.id = 50; # 10.1.50.0/24 + dmz.id = 60; # 10.1.60.0/24 + unit1.id = 110; # 10.1.110.0/24 + unit2.id = 120; # 10.1.120.0/24 + unit3.id = 130; # 10.1.130.0/24 + unit4.id = 140; # 10.1.140.0/24 + unit5 = { + id = 150; # 10.1.150.0/24 + dhcp.reservations.newt = { + hwAddress = "7c:d3:0a:21:58:0b"; + ipAddress = "10.1.150.22"; + }; + }; + }; + # This site runs the Omada controller for its APs/switches. + omada.enable = true; + + # Internal reverse proxy: real wildcard cert *.cnx1.cnx.network; Blocky + # resolves the names to the router's LAN address for mgmt+lan clients. + proxy = { + enable = true; + services.omada = { + # Omada's UI is HTTPS with a self-signed cert on the host network. + backend = "https://127.0.0.1:8043"; + insecureSkipVerify = true; + }; + }; + }; # STAGING (remove at cutover, and restore enp3s0 to trunkPorts): DHCP-client # uplink into the existing OPNsense LAN so the box has internet + mesh while