mob next [ci-skip] [ci skip] [skip ci]

lastFile:machines/gw-cnx-1/configuration.nix
This commit is contained in:
2026-08-06 11:23:46 +07:00
parent df389266f6
commit 5642a0f6fc
+55 -55
View File
@@ -4,7 +4,7 @@
{ config, lib, ... }: { config, lib, ... }:
{ {
imports = [ imports = [
# ../../modules/router ../../modules/router
../../modules/monitoring/exporters.nix ../../modules/monitoring/exporters.nix
(import ../../modules/dns/acme-gw-secret.nix "gw-cnx-1") (import ../../modules/dns/acme-gw-secret.nix "gw-cnx-1")
]; ];
@@ -20,60 +20,60 @@
builtins.hashString "sha256" config.networking.hostName builtins.hashString "sha256" config.networking.hostName
); );
# cnx.router = { cnx.router = {
# enable = true; enable = true;
# site = "cnx"; site = "cnx";
# siteId = 1; siteId = 1;
# wan.interface = "enp1s0"; wan.interface = "enp1s0";
# wan.vlanId = null; # this ISP runs PPPoE untagged on the port wan.vlanId = null; # this ISP runs PPPoE untagged on the port
# trunkPorts = [ trunkPorts = [
# "enp2s0" "enp2s0"
# # "enp3s0" # STAGING: serves as the uplink below until cutover # "enp3s0" # STAGING: serves as the uplink below until cutover
# ]; ];
# # Dedicated on-site recovery port: untagged mgmt, always available even # Dedicated on-site recovery port: untagged mgmt, always available even
# # if the switch config is broken. # if the switch config is broken.
# accessPorts.enp4s0 = "mgmt"; accessPorts.enp4s0 = "mgmt";
# # Replaces the newedge.house OPNsense box; renumbered to the fleet # Replaces the newedge.house OPNsense box; renumbered to the fleet
# # convention (10.1.<vlanId>.0/24, router .1, pool .100-.199). The old # convention (10.1.<vlanId>.0/24, router .1, pool .100-.199). The old
# # untagged LAN becomes tagged mgmt — infra switch ports get PVID 10. # untagged LAN becomes tagged mgmt — infra switch ports get PVID 10.
# vlans = { vlans = {
# mgmt = { mgmt = {
# id = 10; # 10.1.10.0/24 — servers, APs, switches, Omada, admin id = 10; # 10.1.10.0/24 — servers, APs, switches, Omada, admin
# dhcp.reservations.storinator01 = { dhcp.reservations.storinator01 = {
# hwAddress = "7c:c2:55:e0:d6:40"; hwAddress = "7c:c2:55:e0:d6:40";
# ipAddress = "10.1.10.53"; ipAddress = "10.1.10.53";
# }; };
# }; };
# lan.id = 20; # 10.1.20.0/24 — trusted clients lan.id = 20; # 10.1.20.0/24 — trusted clients
# iot.id = 40; # 10.1.40.0/24 iot.id = 40; # 10.1.40.0/24
# voip.id = 50; # 10.1.50.0/24 voip.id = 50; # 10.1.50.0/24
# dmz.id = 60; # 10.1.60.0/24 dmz.id = 60; # 10.1.60.0/24
# unit1.id = 110; # 10.1.110.0/24 unit1.id = 110; # 10.1.110.0/24
# unit2.id = 120; # 10.1.120.0/24 unit2.id = 120; # 10.1.120.0/24
# unit3.id = 130; # 10.1.130.0/24 unit3.id = 130; # 10.1.130.0/24
# unit4.id = 140; # 10.1.140.0/24 unit4.id = 140; # 10.1.140.0/24
# unit5 = { unit5 = {
# id = 150; # 10.1.150.0/24 id = 150; # 10.1.150.0/24
# dhcp.reservations.newt = { dhcp.reservations.newt = {
# hwAddress = "7c:d3:0a:21:58:0b"; hwAddress = "7c:d3:0a:21:58:0b";
# ipAddress = "10.1.150.22"; ipAddress = "10.1.150.22";
# }; };
# }; };
# }; };
# # This site runs the Omada controller for its APs/switches. # This site runs the Omada controller for its APs/switches.
# omada.enable = true; omada.enable = true;
#
# # Internal reverse proxy: real wildcard cert *.cnx1.cnx.network; Blocky # Internal reverse proxy: real wildcard cert *.cnx1.cnx.network; Blocky
# # resolves the names to the router's LAN address for mgmt+lan clients. # resolves the names to the router's LAN address for mgmt+lan clients.
# proxy = { proxy = {
# enable = true; enable = true;
# services.omada = { services.omada = {
# # Omada's UI is HTTPS with a self-signed cert on the host network. # Omada's UI is HTTPS with a self-signed cert on the host network.
# backend = "https://127.0.0.1:8043"; backend = "https://127.0.0.1:8043";
# insecureSkipVerify = true; insecureSkipVerify = true;
# }; };
# }; };
# }; };
# STAGING (remove at cutover, and restore enp3s0 to trunkPorts): DHCP-client # STAGING (remove at cutover, and restore enp3s0 to trunkPorts): DHCP-client
# uplink into the existing OPNsense LAN so the box has internet + mesh while # uplink into the existing OPNsense LAN so the box has internet + mesh while