Author SHA1 Message Date
kurogeek 1cadef7550 mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/dns-dhcp.nix
2026-08-07 18:22:19 +07:00
kurogeek c0dc72176e mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/default.nix
2026-08-07 17:50:15 +07:00
kurogeek aef99a7ff3 mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/dns-dhcp.nix
2026-08-07 17:50:04 +07:00
kurogeek 62ac5c7912 mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/firewall.nix
2026-08-07 17:37:07 +07:00
kurogeek 48d7de24c5 mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/default.nix
2026-08-07 17:32:38 +07:00
kurogeek d85844084c mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/firewall.nix
2026-08-07 17:32:11 +07:00
kurogeek 93ef72810d mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/default.nix
2026-08-07 17:18:13 +07:00
kurogeek 553f9a653d mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/crowdsec.nix
2026-08-07 17:03:30 +07:00
kurogeek 578632e828 mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/crowdsec.nix
2026-08-07 16:23:49 +07:00
kurogeek 414b262310 mob next [ci-skip] [ci skip] [skip ci]
lastFile:machines/gw-cnx-1/configuration.nix
2026-08-07 14:52:51 +07:00
kurogeek d9a33d6aa7 mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/default.nix
2026-08-07 14:52:27 +07:00
kurogeek b10343c194 mob next [ci-skip] [ci skip] [skip ci]
lastFile:clan.nix
2026-08-07 14:50:25 +07:00
kurogeek 73a2f737c3 mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/default.nix
2026-08-06 18:17:44 +07:00
kurogeek 2e8fb9f1dc mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/default.nix
2026-08-06 16:47:24 +07:00
kurogeek 655c6331e9 mob next [ci-skip] [ci skip] [skip ci]
lastFile:clan.nix
2026-08-06 14:42:11 +07:00
kurogeek 0b8f1860fa mob next [ci-skip] [ci skip] [skip ci]
lastFile:clan.nix
2026-08-06 14:02:21 +07:00
kurogeek 17f3860f9b mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/default.nix
2026-08-06 14:01:25 +07:00
kurogeek a97f3f82e5 mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/default.nix
2026-08-06 11:56:42 +07:00
kurogeek a46b83cbc7 mob next [ci-skip] [ci skip] [skip ci]
lastFile:flake.nix
2026-08-06 11:49:57 +07:00
kurogeek 5642a0f6fc mob next [ci-skip] [ci skip] [skip ci]
lastFile:machines/gw-cnx-1/configuration.nix
2026-08-06 11:23:46 +07:00
kurogeek df389266f6 mob next [ci-skip] [ci skip] [skip ci]
lastFile:machines/gw-cnx-1/configuration.nix
2026-08-06 11:23:37 +07:00
kurogeek 81626a75db mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/flake-module.nix
2026-08-06 11:23:14 +07:00
kurogeek 8171207e9c mob next [ci-skip] [ci skip] [skip ci]
lastFile:flake.nix
2026-08-05 11:31:09 +07:00
kurogeek 53c03af2a0 mob next [ci-skip] [ci skip] [skip ci]
lastFile:flake.nix
2026-08-05 10:57:28 +07:00
kurogeek 1a56a2d24b mob next [ci-skip] [ci skip] [skip ci]
lastFile:modules/clan/gw-router/flake-module.nix
2026-08-05 10:21:39 +07:00
kurogeek e316ec56ce flake: use flake-parts 2026-08-05 10:19:32 +07:00
kurogeek 559115e52b inventory.json: update install time of gw-cnx-1 2026-07-31 17:37:47 +07:00
kurogeek 9cfcf91b51 inventory.json: update install time of gw-cnx-1 2026-07-31 16:08:14 +07:00
kurogeek 570fe64497 inventory.json: update install time of gw-cnx-1 2026-07-31 15:09:07 +07:00
kurogeek 2ac4215237 inventory.json: update install time of gw-cnx-1 2026-07-31 13:03:43 +07:00
kurogeek d51a334ec6 inventory.json: update install time of gw-cnx-1 2026-07-31 13:00:57 +07:00
kurogeek b81c0aaa89 machines/gw-cnx-1/facter.json: update hardware configuration 2026-07-31 13:00:57 +07:00
Berwn fcd8e55024 Add untagged access ports and a staging uplink for gw-cnx-1
New cnx.router.accessPorts option pins a port untagged to one VLAN via
bridge PVID/EgressUntagged; convention is the last copper port as an
always-available mgmt recovery port. gw-cnx-1 port roles: enp1s0 WAN,
enp2s0 trunk, enp3s0 temporary DHCP uplink into the old OPNsense LAN
(back to trunk at cutover), enp4s0 untagged mgmt.
2026-07-31 12:57:34 +07:00
Berwn 19e1acda51 Renumber gw-cnx-1 to the fleet addressing scheme (OPNsense replacement)
The newedge.house site adopts the 10.1.<vlanId>.0/24 convention: mgmt 10
(the old untagged LAN), lan 20, iot 40, voip 50, dmz 60, unit1-5 110-150.
PPPoE is untagged at this site. Static leases move to a new per-VLAN
dhcp.reservations option rendered into Kea host reservations.
2026-07-31 11:39:54 +07:00
Berwn f5b6b4b55e Serve newedge.house from the fleet nameservers 2026-07-31 11:39:54 +07:00
19 changed files with 4953 additions and 151 deletions
+184 -72
View File
@@ -1,3 +1,4 @@
{ inputs, self, ... }:
let let
hosts = import ./modules/hosts.nix; hosts = import ./modules/hosts.nix;
@@ -17,83 +18,194 @@ let
}; };
in in
{ {
# Ensure this is unique among all clans you want to use. clan = {
meta.name = "cnx-network-clan"; # Ensure this is unique among all clans you want to use.
meta.domain = "cnx-network.internal"; meta.name = "cnx-network-clan";
meta.domain = "cnx-network.internal";
inventory.machines = fleet; specialArgs = { inherit inputs self; };
inventory.instances = { # Customize nixpkgs
# pkgsForSystem =
# system:
# import nixpkgs {
# inherit system;
# config = {
# allowUnfree = true;
# };
# overlays = [];
# };
secrets.age.plugins = [
"age-plugin-yubikey"
"age-plugin-fido2-hmac"
];
# Admin SSH keys + root password, split per the clan-core migration off inventory.machines = fleet;
# the deprecated `admin` service (sshd handles keys, users the password).
sshd = { inventory.instances = {
roles.server.tags.all = { };
roles.server.settings.authorizedKeys = { # Admin SSH keys + root password, split per the clan-core migration off
"berwn" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIENAjhGQGraQoAjJzsomKP8GAmQPeGL1rNRNHgRcLqtT"; # the deprecated `admin` service (sshd handles keys, users the password).
"kurogeek" = sshd = {
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcZ/p1Ofa9liwIzPWzNtONhJ7+FUWd2lCz33r81t8+w kurogeek@kurogeek"; roles.server.tags.all = { };
roles.server.settings.authorizedKeys = {
"berwn" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIENAjhGQGraQoAjJzsomKP8GAmQPeGL1rNRNHgRcLqtT";
"kurogeek" =
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcZ/p1Ofa9liwIzPWzNtONhJ7+FUWd2lCz33r81t8+w kurogeek@kurogeek";
};
};
gw-router = {
module = {
name = "gw-router";
input = "self";
};
roles.default.machines."gw-cnx-1" = {
settings = {
wan = {
interface = "enp1s0";
vlanId = null;
};
vlans = {
mgmt = {
id = 10;
address = "10.1.10.1";
prefixLength = 24;
subnet = "10.1.10.0/24";
dhcp.fixedIPs.storinator01 = {
hwAddress = "7c:c2:55:e0:d6:40";
ipAddress = "10.1.10.53";
};
};
lan = {
id = 20;
address = "10.1.20.1";
prefixLength = 24;
subnet = "10.1.20.0/24";
};
iot = {
id = 40;
address = "10.1.40.1";
prefixLength = 24;
subnet = "10.1.40.0/24";
};
voip = {
id = 50;
address = "10.1.50.1";
prefixLength = 24;
subnet = "10.1.50.0/24";
};
dmz = {
id = 60;
address = "10.1.60.1";
prefixLength = 24;
subnet = "10.1.60.0/24";
};
unit1 = {
id = 110;
address = "10.1.110.1";
prefixLength = 24;
subnet = "10.1.110.0/24";
};
unit2 = {
id = 120;
address = "10.1.120.1";
prefixLength = 24;
subnet = "10.1.120.0/24";
};
unit3 = {
id = 130;
address = "10.1.130.1";
prefixLength = 24;
subnet = "10.1.130.0/24";
};
unit4 = {
id = 140;
address = "10.1.140.1";
prefixLength = 24;
subnet = "10.1.140.0/24";
};
unit5 = {
id = 150;
address = "10.1.150.1";
prefixLength = 24;
subnet = "10.1.150.0/24";
dhcp.fixedIPs.newt = {
hwAddress = "7c:d3:0a:21:58:0b";
ipAddress = "10.1.150.22";
};
};
};
trunkPorts = [ "enp2s0" ];
accessPorts = {
enp4s0.vlanId = 10;
};
upLinkPorts = [ "enp3s0" ];
};
};
};
root-user = {
module = {
name = "users";
input = "clan-core";
};
roles.default.tags.all = { };
roles.default.settings = {
user = "root";
prompt = false; # auto-generate, like the old admin service
share = false; # per-machine password, not fleet-wide
};
};
zerotier = {
roles.controller.machines."control" = { };
roles.peer.tags.all = { };
# External members admitted by ZeroTier node id (stable per device).
# Inventory machines are auto-accepted; this is only for peers outside the
# clan. Node id comes from `zerotier-cli info` on the joining device.
roles.controller.settings.allowedIds = [
"8802c8d7e0" # alex-nixos
"2bd36db8cc" # kurogeek-thinkpad
];
};
tor = {
roles.server.tags.nixos = { };
};
# Direct SSH to public IPs — clan's priority-1 connection path, with the
# ZeroTier mesh and Tor kept as automatic fallbacks. Raw IPs (from
# modules/hosts.nix, not the ns1/ns2 DNS names) so reaching these hosts never
# depends on their own DNS being up.
internet.roles.default.machines = builtins.mapAttrs (_: h: {
settings.host = h.ipv4;
}) hosts;
# Recovery root password for console access when a machine fails to boot.
emergency-access = {
roles.default.tags.nixos = { };
};
# Encrypted, deduplicating backups. control hosts the repos; ns1 is the
# only client, backing up its declared clan.core.state (the Knot DNSSEC
# keystore) over the mesh. Repo lives at /var/lib/borgbackup/ns1 on control.
# Cross-host so an ns1 loss is recoverable; repokey encryption means control
# never holds plaintext. Run `clan vars generate ns1` (YubiKey) before deploy.
borgbackup = {
roles.server.machines.control = { };
roles.client.machines.ns1 = { };
}; };
}; };
root-user = { # Fleet-wide baseline applied to every machine. Secrets minted by
module = { # `clan vars generate` are encrypted for the admins group from the very
name = "users"; # first run — generating before this took effect is what forced the
input = "clan-core"; # re-encryption dance (`clan vars fix`) on gw-cnx-1.
}; machines = builtins.mapAttrs (_: _: {
roles.default.tags.all = { }; clan.core.sops.defaultGroups = [ "admins" ];
roles.default.settings = { }) fleet;
user = "root";
prompt = false; # auto-generate, like the old admin service
share = false; # per-machine password, not fleet-wide
};
};
zerotier = {
roles.controller.machines."control" = { };
roles.peer.tags.all = { };
# External members admitted by ZeroTier node id (stable per device).
# Inventory machines are auto-accepted; this is only for peers outside the
# clan. Node id comes from `zerotier-cli info` on the joining device.
roles.controller.settings.allowedIds = [
"8802c8d7e0" # alex-nixos
"2bd36db8cc" # kurogeek-thinkpad
];
};
tor = {
roles.server.tags.nixos = { };
};
# Direct SSH to public IPs — clan's priority-1 connection path, with the
# ZeroTier mesh and Tor kept as automatic fallbacks. Raw IPs (from
# modules/hosts.nix, not the ns1/ns2 DNS names) so reaching these hosts never
# depends on their own DNS being up.
internet.roles.default.machines = builtins.mapAttrs (_: h: {
settings.host = h.ipv4;
}) hosts;
# Recovery root password for console access when a machine fails to boot.
emergency-access = {
roles.default.tags.nixos = { };
};
# Encrypted, deduplicating backups. control hosts the repos; ns1 is the
# only client, backing up its declared clan.core.state (the Knot DNSSEC
# keystore) over the mesh. Repo lives at /var/lib/borgbackup/ns1 on control.
# Cross-host so an ns1 loss is recoverable; repokey encryption means control
# never holds plaintext. Run `clan vars generate ns1` (YubiKey) before deploy.
borgbackup = {
roles.server.machines.control = { };
roles.client.machines.ns1 = { };
};
}; };
# Fleet-wide baseline applied to every machine. Secrets minted by
# `clan vars generate` are encrypted for the admins group from the very
# first run — generating before this took effect is what forced the
# re-encryption dance (`clan vars fix`) on gw-cnx-1.
machines = builtins.mapAttrs (_: _: {
clan.core.sops.defaultGroups = [ "admins" ];
}) fleet;
} }
+8 -4
View File
@@ -13,7 +13,7 @@ Naming: `gw-<city>-<n>`, e.g. `gw-cnx-1`.
| Function | Implementation | | Function | Implementation |
| ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| WAN | PPPoE (`pppd`), per-site ISP credentials via clan vars prompts; `wan.vlanId` when the ISP tags the session (AIS: 10); `wan.macAddress` to clone the old router's MAC if the ISP has it pinned | | WAN | PPPoE (`pppd`), per-site ISP credentials via clan vars prompts; `wan.vlanId` when the ISP tags the session (AIS: 10); `wan.macAddress` to clone the old router's MAC if the ISP has it pinned |
| LAN | VLAN-filtering bridge `br0` over the trunk ports (networkd) | | LAN | VLAN-filtering bridge `br0` over the trunk ports (networkd); `accessPorts` pin a port untagged to one VLAN — convention: the last copper port is an untagged `mgmt` recovery port |
| Firewall/NAT | nftables: default-deny WAN, no inter-VLAN, MSS clamp, v4 NAT | | Firewall/NAT | nftables: default-deny WAN, no inter-VLAN, MSS clamp, v4 NAT |
| DHCP | Kea, one subnet per VLAN | | DHCP | Kea, one subnet per VLAN |
| DNS | Blocky (blocklist resolver), metrics on :4000 scraped by control | | DNS | Blocky (blocklist resolver), metrics on :4000 scraped by control |
@@ -42,9 +42,13 @@ should also shorten `dhcp.leaseTime` (default 86400 s) so the pool recycles.
First user: `gw-cnx-2` (site 2) runs the public WiFi — guest VLAN 30 at First user: `gw-cnx-2` (site 2) runs the public WiFi — guest VLAN 30 at
`10.2.128.0/22`, pool `10.2.128.100 10.2.131.250`, `dhcp.leaseTime = 3600`. `10.2.128.0/22`, pool `10.2.128.100 10.2.131.250`, `dhcp.leaseTime = 3600`.
| Site | siteId | mgmt | lan | | Site | siteId | mgmt | lan | site-specific VLANs |
| ---- | ------ | -------------- | -------------- | | ---- | ------ | -------------- | -------------- | --------------------------------------------------------------- |
| cnx | 1 | `10.1.10.0/24` | `10.1.20.0/24` | | cnx | 1 | `10.1.10.0/24` | `10.1.20.0/24` | iot 40, voip 50, dmz 60, unit15 110/120/130/140/150 (all /24s) |
Static DHCP leases are declared per VLAN via `dhcp.reservations` (attribute
name = hostname, plus `hwAddress`/`ipAddress`); park them outside the pool,
in the `.2.99` infra range or `.200.254`.
Trust model: mgmt → everything; other VLANs → router DNS/DHCP + internet only Trust model: mgmt → everything; other VLANs → router DNS/DHCP + internet only
(no inter-VLAN); WAN → nothing inbound; mesh → SSH, metrics, Omada UI. (no inter-VLAN); WAN → nothing inbound; mesh → SSH, metrics, Omada UI.
Generated
+4
View File
@@ -247,6 +247,10 @@
"root": { "root": {
"inputs": { "inputs": {
"clan-core": "clan-core", "clan-core": "clan-core",
"flake-parts": [
"clan-core",
"flake-parts"
],
"nixos-mailserver": "nixos-mailserver", "nixos-mailserver": "nixos-mailserver",
"nixpkgs": [ "nixpkgs": [
"clan-core", "clan-core",
+27 -46
View File
@@ -7,67 +7,43 @@
inputs.nixos-mailserver.url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05"; inputs.nixos-mailserver.url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05";
inputs.nixos-mailserver.inputs.nixpkgs.follows = "nixpkgs"; inputs.nixos-mailserver.inputs.nixpkgs.follows = "nixpkgs";
inputs.flake-parts.follows = "clan-core/flake-parts";
outputs = outputs =
{ inputs@{
self, self,
clan-core, clan-core,
nixpkgs, flake-parts,
... ...
}@inputs: }:
let let
# Usage see: https://docs.clan.lol in
clan = clan-core.lib.clan { flake-parts.lib.mkFlake { inherit inputs; } {
inherit self;
imports = [ ./clan.nix ];
specialArgs = { inherit inputs; };
# Customize nixpkgs
# pkgsForSystem =
# system:
# import nixpkgs {
# inherit system;
# config = {
# allowUnfree = true;
# };
# overlays = [];
# };
secrets.age.plugins = [
"age-plugin-yubikey"
"age-plugin-fido2-hmac"
];
};
systems = [ systems = [
"x86_64-linux" "x86_64-linux"
"aarch64-linux" "aarch64-linux"
"aarch64-darwin" "aarch64-darwin"
"x86_64-darwin" "x86_64-darwin"
]; ];
forAllSystems = nixpkgs.lib.genAttrs systems;
pkgsFor = system: clan-core.inputs.nixpkgs.legacyPackages.${system};
treefmtFor = system: inputs.treefmt-nix.lib.evalModule (pkgsFor system) ./fmt.nix;
in
{
inherit (clan.config) nixosConfigurations nixosModules clanInternals;
clan = clan.config;
# `nix fmt` and the `nix flake check` formatting gate. imports = [
formatter = forAllSystems (system: (treefmtFor system).config.build.wrapper); inputs.clan-core.flakeModules.default
checks = forAllSystems (system: {
formatting = (treefmtFor system).config.build.check self;
});
# Add the Clan cli tool to the dev shell. ./clan.nix
# Use "nix develop" to enter the dev shell. ./modules/clan/flake-module.nix
devShells = forAllSystems ( ];
system:
perSystem =
{ system, ... }:
let let
pkgs = clan-core.inputs.nixpkgs.legacyPackages.${system};
treefmtEval = inputs.treefmt-nix.lib.evalModule pkgs ./fmt.nix;
clanCli = clan-core.packages.${system}.clan-cli; clanCli = clan-core.packages.${system}.clan-cli;
# `clan machines update a b c` normally runs machines in parallel, # `clan machines update a b c` normally runs machines in parallel,
# which interleaves their output and buries the YubiKey PIN prompts. # which interleaves their output and buries the YubiKey PIN prompts.
# This wrapper (first in PATH) runs them one at a time instead; any # This wrapper (first in PATH) runs them one at a time instead; any
# flags fall through to the real CLI untouched. # flags fall through to the real CLI untouched.
clanSequential = (pkgsFor system).writeShellScriptBin "clan" '' clanSequential = pkgs.writeShellScriptBin "clan" ''
if [ "$#" -gt 3 ] && [ "$1" = machines ] && [ "$2" = update ]; then if [ "$#" -gt 3 ] && [ "$1" = machines ] && [ "$2" = update ]; then
shift 2 shift 2
for arg in "$@"; do for arg in "$@"; do
@@ -84,14 +60,19 @@
''; '';
in in
{ {
default = (pkgsFor system).mkShell { # `nix fmt` and the `nix flake check` formatting gate.
formatter = treefmtEval.config.build.wrapper;
checks.formatting = treefmtEval.config.build.check self;
# Add the Clan cli tool to the dev shell.
# Use "nix develop" to enter the dev shell.
devShells.default = pkgs.mkShell {
packages = [ packages = [
clanSequential clanSequential
clanCli clanCli
(treefmtFor system).config.build.wrapper treefmtEval.config.build.wrapper
]; ];
}; };
} };
);
}; };
} }
+3
View File
@@ -14,6 +14,9 @@
}, },
"web01": { "web01": {
"installedAt": 1781983723 "installedAt": 1781983723
},
"gw-cnx-1": {
"installedAt": 1785494267
} }
} }
} }
+65 -29
View File
@@ -4,7 +4,7 @@
{ config, lib, ... }: { config, lib, ... }:
{ {
imports = [ imports = [
../../modules/router # ../../modules/router
../../modules/monitoring/exporters.nix ../../modules/monitoring/exporters.nix
(import ../../modules/dns/acme-gw-secret.nix "gw-cnx-1") (import ../../modules/dns/acme-gw-secret.nix "gw-cnx-1")
]; ];
@@ -20,35 +20,71 @@
builtins.hashString "sha256" config.networking.hostName builtins.hashString "sha256" config.networking.hostName
); );
cnx.router = { # cnx.router = {
enable = true; # enable = true;
site = "cnx"; # site = "cnx";
siteId = 1; # siteId = 1;
wan.interface = "enp1s0"; # wan.interface = "enp1s0";
wan.vlanId = 10; # AIS delivers PPPoE tagged on VLAN 10 # wan.vlanId = null; # this ISP runs PPPoE untagged on the port
trunkPorts = [ # trunkPorts = [
"enp2s0" # "enp2s0"
"enp3s0" # # "enp3s0" # STAGING: serves as the uplink below until cutover
"enp4s0" # ];
]; # # Dedicated on-site recovery port: untagged mgmt, always available even
vlans = { # # if the switch config is broken.
mgmt.id = 10; # 10.1.10.0/24 — APs, switches, Omada, admin # accessPorts.enp4s0 = "mgmt";
lan.id = 20; # 10.1.20.0/24 — trusted clients # # Replaces the newedge.house OPNsense box; renumbered to the fleet
}; # # convention (10.1.<vlanId>.0/24, router .1, pool .100-.199). The old
# This site runs the Omada controller for its APs/switches. # # untagged LAN becomes tagged mgmt — infra switch ports get PVID 10.
omada.enable = true; # vlans = {
# mgmt = {
# id = 10; # 10.1.10.0/24 — servers, APs, switches, Omada, admin
# dhcp.reservations.storinator01 = {
# hwAddress = "7c:c2:55:e0:d6:40";
# ipAddress = "10.1.10.53";
# };
# };
# lan.id = 20; # 10.1.20.0/24 — trusted clients
# iot.id = 40; # 10.1.40.0/24
# voip.id = 50; # 10.1.50.0/24
# dmz.id = 60; # 10.1.60.0/24
# unit1.id = 110; # 10.1.110.0/24
# unit2.id = 120; # 10.1.120.0/24
# unit3.id = 130; # 10.1.130.0/24
# unit4.id = 140; # 10.1.140.0/24
# unit5 = {
# id = 150; # 10.1.150.0/24
# dhcp.reservations.newt = {
# hwAddress = "7c:d3:0a:21:58:0b";
# ipAddress = "10.1.150.22";
# };
# };
# };
# # This site runs the Omada controller for its APs/switches.
# omada.enable = true;
#
# # Internal reverse proxy: real wildcard cert *.cnx1.cnx.network; Blocky
# # resolves the names to the router's LAN address for mgmt+lan clients.
# proxy = {
# enable = true;
# services.omada = {
# # Omada's UI is HTTPS with a self-signed cert on the host network.
# backend = "https://127.0.0.1:8043";
# insecureSkipVerify = true;
# };
# };
# };
# Internal reverse proxy: real wildcard cert *.cnx1.cnx.network; Blocky # STAGING (remove at cutover, and restore enp3s0 to trunkPorts): DHCP-client
# resolves the names to the router's LAN address for mgmt+lan clients. # uplink into the existing OPNsense LAN so the box has internet + mesh while
proxy = { # it runs alongside the old router. Default-deny firewall on this interface
enable = true; # (it's in no VLAN zone); PPPoE simply retries until the WAN port is cabled.
services.omada = { # Do NOT connect the trunk ports to the production switch while staging —
# Omada's UI is HTTPS with a self-signed cert on the host network. # Kea on tag 10 would fight the OPNsense LAN DHCP in one broadcast domain.
backend = "https://127.0.0.1:8043"; # systemd.network.networks."05-staging" = {
insecureSkipVerify = true; # matchConfig.Name = "enp3s0";
}; # networkConfig.DHCP = "ipv4";
}; # };
};
time.timeZone = "Etc/GMT-7"; # UTC+7 (Thailand, fixed offset, no DST) time.timeZone = "Etc/GMT-7"; # UTC+7 (Thailand, fixed offset, no DST)
services.chrony.enable = true; services.chrony.enable = true;
File diff suppressed because it is too large Load Diff
+26
View File
@@ -0,0 +1,26 @@
{
inputs,
...
}:
{
imports =
let
# Get all subdirectories in the current directory
dirContents = builtins.readDir ./.;
# Filter to include only directories that have a flake-module.nix file
# and exclude special directories like 'result'
validModuleDirs = builtins.filter (
name:
name != "result"
&& dirContents.${name} == "directory"
&& builtins.pathExists (./. + "/${name}/flake-module.nix")
) (builtins.attrNames dirContents);
# Create import paths for each valid directory
imports = (map (name: ./. + "/${name}/flake-module.nix") validModuleDirs) ++ [
inputs.clan-core.flakeModules.testModule
];
in
imports;
}
+59
View File
@@ -0,0 +1,59 @@
{
roles.default.perInstance = { ... }: {
nixosModule =
{
config,
...
}:
let
dir = config.clan.core.settings.directory;
instance = "zerotier";
networkId = builtins.readFile "${dir}/vars/shared/zerotier-network-${instance}/network-id/value";
full = "fd" + networkId + "9993";
hextet = i: builtins.substring (i * 4) 4 full;
subnetZtier = "${hextet 0}:${hextet 1}:${hextet 2}:${hextet 3}:${hextet 4}:${builtins.substring 20 2 full}00::/88";
in
{
services.crowdsec = {
enable = true;
autoUpdateService = true;
hub.collections = [
"crowdsecurity/linux"
"crowdsecurity/sshd"
];
localConfig = {
acquisitions = [
{
source = "journalctl";
journalctl_filter = [ "_SYSTEMD_UNIT=sshd.service" ];
labels.type = "syslog";
}
];
# Never ban the ZeroTier mesh — it is the only admin path to these
# boxes (no public SSH), so a false positive would lock us out.
# Parser-stage whitelist: mesh events are dropped before any scenario.
parsers.s02Enrich = [
{
name = "cnx/mesh-whitelist";
description = "Whitelist the ZeroTier management mesh";
whitelist = {
reason = "ZeroTier mesh is the admin path";
cidr = [ subnetZtier ];
};
}
];
};
};
services.crowdsec-firewall-bouncer = {
enable = true;
registerBouncer.enable = true;
settings.mode = "nftables";
};
};
};
}
+311
View File
@@ -0,0 +1,311 @@
{ ... }:
{
_class = "clan.service";
manifest.name = "gw-router";
manifest.description = "A gateway router service to configure most of a router features";
manifest.readme = "A gateway router service to configure most of a router features";
manifest.categories = [ "System" ];
roles.default = {
description = "Site gateway router role";
interface =
{ lib, config, ... }:
let
vlanModule =
{ ... }:
{
options = {
id = lib.mkOption {
type = lib.types.ints.between 1 4094;
description = "802.1Q VLAN id.";
};
address = lib.mkOption {
type = lib.types.str;
example = "10.0.10.1";
description = "Router address on this VLAN.";
};
prefixLength = lib.mkOption {
type = lib.types.ints.between 8 30;
default = 24;
};
subnet = lib.mkOption {
type = lib.types.str;
example = "10.0.10.0/24";
description = "The VLAN's network in CIDR form (must contain `address`).";
};
dhcp = {
enable = lib.mkOption {
type = lib.types.bool;
default = true;
};
pool = {
from = lib.mkOption {
type = lib.types.str;
example = "10.0.10.100";
};
to = lib.mkOption {
type = lib.types.str;
example = "10.0.10.199";
};
};
leaseTime = lib.mkOption {
type = lib.types.ints.positive;
default = 86400;
description = ''
Lease validity in seconds. Lower it for high-churn networks,
e.g. public-WiFi guest VLANs (3600-7200), so the pool recycles.
'';
};
fixedIPs = lib.mkOption {
type = lib.types.attrsOf (
lib.types.submodule {
options = {
hwAddress = lib.mkOption {
type = lib.types.str;
example = "aa:bb:cc:dd:ee:ff";
description = "Client MAC address.";
};
ipAddress = lib.mkOption {
type = lib.types.str;
description = "Fixed address handed to this client (inside the VLAN's subnet, outside the pool).";
};
};
}
);
default = { };
description = "Static DHCP leases; the attribute name becomes the client's hostname.";
};
};
allowedWAN = lib.mkOption {
type = lib.types.bool;
default = true;
description = "Whether clients on this VLAN may reach the internet.";
};
};
};
in
{
options = {
wan = {
interface = lib.mkOption {
type = lib.types.str;
description = "Physical WAN port the PPPoE session runs on.";
};
vlanId = lib.mkOption {
type = lib.types.nullOr (lib.types.ints.between 1 4094);
default = null;
description = ''
802.1Q tag the ISP requires for the PPPoE session (AIS Thailand: 10);
null for untagged PPPoE directly on the port. Unrelated to the LAN
VLANs this tag exists only on the WAN port.
'';
};
macAddress = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
example = "aa:bb:cc:dd:ee:ff";
description = ''
Spoofed MAC for the WAN port, e.g. to keep the MAC the ISP has
pinned (cloned from the old router). null keeps the hardware MAC.
'';
};
};
vlans = lib.mkOption {
type = lib.types.attrsOf (lib.types.submodule vlanModule);
description = "VLANs setup for this router";
};
trunkPorts = lib.mkOption {
type = lib.types.listOf lib.types.str;
description = "LAN ports carrying all VLANs tagged (incl. any 10G SFP+ ports).";
};
accessPorts = lib.mkOption {
type = lib.types.attrsOf (
lib.types.submodule {
options = {
vlanId = lib.mkOption {
type = lib.types.int;
description = "Untagged traffic in from the device gets tagged VLANs inside the bridge, and VLANs traffic going back out to the device gets untagged, so the device itself never has to know VLANs exist.";
};
};
}
);
description = ''
Ports acting as untagged access ports on a single VLAN (port name ->
VLAN id). Frames are untagged on the wire; the bridge tags them with
the VLAN's PVID. Use for an always-available on-site mgmt port.
'';
};
upLinkPorts = lib.mkOption {
type = lib.types.listOf lib.types.str;
description = "DHCP-client uplink into the existing router LAN so this machine has internet";
};
};
};
perInstance =
{ settings, ... }:
{
nixosModule =
{
pkgs,
lib,
...
}:
let
vlanIf = name: "vlan=${name}";
in
{
networking.useNetworkd = true;
networking.useDHCP = false;
systemd.network.enable = true;
systemd.network.netdevs = {
"20-br0" = {
netdevConfig = {
Name = "br0";
Kind = "bridge";
};
bridgeConfig = {
VLANFiltering = true;
};
};
}
// lib.optionalAttrs (settings.wan.vlanId != null) {
"15-wan-lan" = {
netdevConfig = {
Name = "wan-vlan";
Kind = "vlan";
};
vlanConfig.Id = settings.wan.vlanId;
};
}
// lib.mapAttrs' (
name: vlan:
lib.nameValuePair "30-${vlanIf name}" {
netdevConfig = {
Name = vlanIf name;
Kind = "vlan";
};
vlanConfig.Id = vlan.id;
}
) settings.vlans;
systemd.network.networks =
let
allVLANs = lib.mapAttrsToList (_: vlan: { VLAN = vlan.id; }) settings.vlans;
in
{
"10-wan" = {
matchConfig.Name = settings.wan.interface;
networkConfig.LinkLocalAddressing = "no";
vlan = lib.optional (settings.wan.vlanId != null) "wan-wlan";
linkConfig = {
RequiredForOnline = "carrier";
}
// lib.optionalAttrs (settings.wan.macAddress != null) {
MACAddress = settings.wan.macAddress;
};
};
}
// lib.optionalAttrs (settings.wan.vlanId != null) {
"15-wan-lan" = {
matchConfig.Name = "wan-vlan";
networkConfig.LinkLocalAddressing = "no";
linkConfig.RequiredForOnline = "no";
};
}
// {
"20-br0" = {
matchConfig.Name = "br0";
networkConfig.LinkLocalAddressing = "no";
vlan = lib.mapAttrsToList (name: _: vlanIf name) settings.vlans;
bridgeVLANs = allVLANs;
linkConfig.RequiredForOnline = "no";
};
}
// lib.listToAttrs (
map (port: {
name = "25-trunk-${port}";
value = {
matchConfig.Name = port;
networkConfig.Bridge = "br0";
bridgeVLANs = allVLANs;
linkConfig.RequiredForOnline = "no";
};
}) settings.trunkPorts
)
// lib.mapAttrs' (
iface: port:
lib.nameValuePair "25-access-${iface}" {
matchConfig.Name = iface;
networkConfig.Bridge = "br0";
bridgeVLANs = [
{
VLAN = port.vlanId;
PVID = port.vlanId;
EgressUntagged = port.vlanId;
}
];
linkConfig.RequiredForOnline = "no";
}
) settings.accessPorts
// lib.mapAttrs' (
name: vlan:
lib.nameValuePair "40-${vlanIf name}" {
matchConfig.Name = vlanIf name;
address = [ "${vlan.address}/${toString vlan.prefixLength}" ];
networkConfig = {
IPv6AcceptRA = false;
IPv6SendRA = true;
DHCPPrefixDelegation = true;
};
dhcpPrefixDelegationConfig.SubnetId = "auto";
linkConfig.RequiredForOnline = "no";
}
) settings.vlans
// lib.listToAttrs (
map (port: {
name = "15-uplink-${port}";
value = {
matchConfig.Name = "${port}";
networkConfig.DHCP = "ipv4";
};
}) settings.upLinkPorts
);
environment.systemPackages = with pkgs; [
tcpdump
mtr
ethtool
conntrack-tools
knot-dns
iftop
librespeed-cli
];
};
};
};
imports = [
./ipv6.nix
./firewall.nix
./dns-dhcp.nix
./pppoe.nix
./crowdsec.nix
];
}
+81
View File
@@ -0,0 +1,81 @@
{
roles.default.perInstance = { settings, ... }: {
nixosModule =
{
lib,
...
}:
let
dhcpVlans = lib.filterAttrs (_: vlan: vlan.dhcp.enable) settings.vlans;
in
{
services.kea.dhcp4 = {
enable = true;
settings = {
interfaces-config.interfaces = lib.mapAttrsToList (name: _: "vlan-${name}") dhcpVlans;
lease-database = {
type = "memfile";
persist = true;
name = "/var/lib/kea/dhcp4.leases";
};
valid-lifetime = 86400;
subnet4 = lib.mapAttrsToList (name: vlan: {
id = vlan.id;
subnet = vlan.subnet;
interface = "vlan-${name}";
valid-lifetime = vlan.dhcp.leaseTime;
pools = [ { pool = "${vlan.dhcp.pool.from} - ${vlan.dhcp.pool.to}"; } ];
reservations = lib.mapAttrsToList (host: res: {
hostname = host;
hw-address = res.hwAddress;
ip-address = res.ipAddress;
}) vlan.dhcp.fixedIPs;
option-data = [
{
name = "routers";
data = vlan.address;
}
{
name = "domain-name-servers";
data = vlan.address;
}
];
}) dhcpVlans;
};
};
services.blocky = {
enable = true;
settings = {
ports = {
dns = 53;
http = 4000;
};
upstreams.groups.default = [
"9.9.9.9"
"149.112.112.112"
"2620:fe::fe"
];
blocking = {
denylists.ads = [
"https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts"
];
clientGroupsBlock.default = [ "ads" ];
};
caching = {
minTime = "5m";
prefetching = true;
};
prometheus.enable = true;
};
};
networking.nameservers = [
"9.9.9.9"
"1.1.1.1"
];
};
};
}
+64
View File
@@ -0,0 +1,64 @@
{
roles.default.perInstance = { settings, ... }: {
nixosModule =
{
config,
lib,
...
}:
let
dir = config.clan.core.settings.directory;
instance = "zerotier";
networkId = builtins.readFile "${dir}/vars/shared/zerotier-network-${instance}/network-id/value";
full = "fd" + networkId + "9993";
hextet = i: builtins.substring (i * 4) 4 full;
subnetZtier = "${hextet 0}:${hextet 1}:${hextet 2}:${hextet 3}:${hextet 4}:${builtins.substring 20 2 full}00::/88";
vlanIfs = lib.mapAttrsToList (name: _: "vlan-${name}") settings.vlans;
wanVlanIfs = lib.mapAttrsToList (name: _: "vlan-${name}") (
lib.filterAttrs (_: vlan: vlan.allowedWAN) settings.vlans
);
nonMgmtIfs = lib.filter (i: i != "vlan-mgmt") vlanIfs;
ifSet = ifs: "{ ${lib.concatStringsSep ", " (map (i: "\"${i}\"") ifs)} }";
in
{
networking.nftables.enable = true;
services.openssh.openFirewall = false;
networking.firewall = {
enable = true;
filterForward = true;
trustedInterfaces = [ "vlan-mgmt" ];
interfaces = lib.genAttrs nonMgmtIfs (_: {
allowedTCPPorts = [ 53 ];
allowedUDPPorts = [
53
67
];
});
extraInputRules = ''
ip6 saddr ${subnetZtier} tcp dport 22 accept comment "admin ssh over the mesh"
ip6 saddr ${subnetZtier} tcp dport 4000 accept comment "blocky metrics scrape from control"
'';
extraForwardRules = ''
tcp flags syn tcp option maxseg size set rt mtu comment "MSS clamp for PPPoE mtu 1492"
iifname "vlan-mgmt" accept comment "mgmt reaches all VLANs and the WAN"
iifname ${ifSet wanVlanIfs} oifname "ppp0" accept comment "LAN to internet"
'';
};
networking.nat = {
enable = true;
externalInterface = "ppp0";
internalInterfaces = vlanIfs;
};
};
};
}
+19
View File
@@ -0,0 +1,19 @@
{ self, inputs, ... }:
let
module = ./default.nix;
in
{
clan.modules = {
gw-router = module;
};
# perSystem =
# { ... }:
# {
# clan.nixosTests.service-headplane = {
# imports = [ ./tests/vm/default.nix ];
# _module.args = { inherit self inputs; };
#
# clan.modules."@clan/headplane" = module;
# };
# };
}
+29
View File
@@ -0,0 +1,29 @@
{
roles.default.perInstance = { ... }: {
nixosModule =
{
lib,
...
}:
{
systemd.network.networks."45-ppp0" = {
matchConfig.Name = "ppp0";
networkConfig = {
DHCP = "ipv6";
# pppd owns the v4 address/route on this link; don't let networkd
# tear them down.
KeepConfiguration = "static";
# Default v6 route comes from the ISP's RA when they send one.
IPv6AcceptRA = true;
};
# Many PPPoE ISPs never send an RA with the M flag; solicit regardless.
dhcpV6Config.WithoutRA = "solicit";
linkConfig.RequiredForOnline = "no";
};
boot.kernel.sysctl."net.ipv6.conf.all.forwarding" = lib.mkDefault 1;
};
};
}
+58
View File
@@ -0,0 +1,58 @@
{
roles.default.perInstance = { settings, ... }: {
nixosModule =
{ config, ... }:
let
creds = config.clan.core.vars.generators.gw-router;
pppInterface = if settings.wan.vlanId == null then settings.wan.interface else "wan-vlan";
in
{
clan.core.vars.generators.gw-router = {
prompts.pppoe-username = {
description = "PPPoE username (from the ISP)";
type = "hidden";
};
prompts.pppoe-password = {
description = "PPPoE password (from the ISP)";
type = "hidden";
};
files."pppoe-username".secret = true;
files."pppoe-password".secret = true;
script = ''
user="$(cat "$prompts"/pppoe-username)"
pass="$(cat "$prompts"/pppoe-password)"
printf 'user "%s"\n' "$user" > "$out"/pppoe-username
printf '"%s" * "%s"\n' "$user" "$pass" > "$out"/pppoe-password
'';
};
services.pppd = {
enable = true;
peers.wan = {
autostart = true;
config = ''
plugin pppoe.so ${pppInterface}
ifname ppp0
file ${creds.files."pppoe-username".path}
noipdefault
defaultroute
noauth
hide-password
persist
maxfail 0
holdoff 5
lcp-echo-interval 15
lcp-echo-failure 3
+ipv6
mtu 1492
mru 1492
'';
};
};
environment.etc."ppp/chap-secrets".source = creds.files."pppoe-password".path;
environment.etc."ppp/pap-secrets".source = creds.files."pppoe-password".path;
};
};
}
+1
View File
@@ -4,4 +4,5 @@
"cnx.network" "cnx.network"
"buildfor.life" "buildfor.life"
"cnx.email" "cnx.email"
"newedge.house"
] ]
+13
View File
@@ -0,0 +1,13 @@
$ORIGIN newedge.house.
$TTL 3600
@ IN SOA ns1.cnx.network. hostmaster.cnx.network. (
2026061401 ; serial (ignored: Knot auto-assigns a dateserial on signing)
3600 ; refresh
900 ; retry
604800 ; expire
300 ) ; negative-cache TTL
; Served by the same nameservers (out-of-bailiwick, no glue needed here).
@ IN NS ns1.cnx.network.
@ IN NS ns2.cnx.network.
+55
View File
@@ -68,6 +68,25 @@ let
e.g. public-WiFi guest VLANs (3600-7200), so the pool recycles. e.g. public-WiFi guest VLANs (3600-7200), so the pool recycles.
''; '';
}; };
reservations = lib.mkOption {
type = lib.types.attrsOf (
lib.types.submodule {
options = {
hwAddress = lib.mkOption {
type = lib.types.str;
example = "aa:bb:cc:dd:ee:ff";
description = "Client MAC address.";
};
ipAddress = lib.mkOption {
type = lib.types.str;
description = "Fixed address handed to this client (inside the VLAN's subnet, outside the pool).";
};
};
}
);
default = { };
description = "Static DHCP leases; the attribute name becomes the client's hostname.";
};
}; };
allowWan = lib.mkOption { allowWan = lib.mkOption {
type = lib.types.bool; type = lib.types.bool;
@@ -141,6 +160,19 @@ in
description = "LAN ports carrying all VLANs tagged (incl. any 10G SFP+ ports)."; description = "LAN ports carrying all VLANs tagged (incl. any 10G SFP+ ports).";
}; };
accessPorts = lib.mkOption {
type = lib.types.attrsOf lib.types.str;
default = { };
example = {
enp4s0 = "mgmt";
};
description = ''
Ports acting as untagged access ports on a single VLAN (port name ->
VLAN name). Frames are untagged on the wire; the bridge tags them with
the VLAN's PVID. Use for an always-available on-site mgmt port.
'';
};
vlans = lib.mkOption { vlans = lib.mkOption {
type = lib.types.attrsOf (lib.types.submodule vlanModule); type = lib.types.attrsOf (lib.types.submodule vlanModule);
description = "VLANs served at this site; `mgmt` and `lan` are mandatory."; description = "VLANs served at this site; `mgmt` and `lan` are mandatory.";
@@ -153,6 +185,14 @@ in
assertion = cfg.vlans ? mgmt && cfg.vlans ? lan; assertion = cfg.vlans ? mgmt && cfg.vlans ? lan;
message = "cnx.router: every site must define the `mgmt` and `lan` VLANs."; message = "cnx.router: every site must define the `mgmt` and `lan` VLANs.";
} }
{
assertion = lib.all (v: cfg.vlans ? ${v}) (lib.attrValues cfg.accessPorts);
message = "cnx.router: every accessPorts value must name a defined VLAN.";
}
{
assertion = lib.all (p: !(cfg.accessPorts ? ${p})) cfg.trunkPorts;
message = "cnx.router: a port cannot be both a trunk and an access port.";
}
]; ];
# Router diagnostics toolkit: packets (tcpdump), path (mtr), link # Router diagnostics toolkit: packets (tcpdump), path (mtr), link
@@ -251,6 +291,21 @@ in
}; };
}) cfg.trunkPorts }) cfg.trunkPorts
) )
// lib.mapAttrs' (
port: vlanName:
lib.nameValuePair "25-access-${port}" {
matchConfig.Name = port;
networkConfig.Bridge = "br0";
bridgeVLANs = [
{
VLAN = cfg.vlans.${vlanName}.id;
PVID = cfg.vlans.${vlanName}.id;
EgressUntagged = cfg.vlans.${vlanName}.id;
}
];
linkConfig.RequiredForOnline = "no";
}
) cfg.accessPorts
// lib.mapAttrs' ( // lib.mapAttrs' (
name: vlan: name: vlan:
lib.nameValuePair "40-${vlanIf name}" { lib.nameValuePair "40-${vlanIf name}" {
+5
View File
@@ -29,6 +29,11 @@ in
interface = "vlan-${name}"; interface = "vlan-${name}";
valid-lifetime = vlan.dhcp.leaseTime; valid-lifetime = vlan.dhcp.leaseTime;
pools = [ { pool = "${vlan.dhcp.pool.from} - ${vlan.dhcp.pool.to}"; } ]; pools = [ { pool = "${vlan.dhcp.pool.from} - ${vlan.dhcp.pool.to}"; } ];
reservations = lib.mapAttrsToList (host: res: {
hostname = host;
hw-address = res.hwAddress;
ip-address = res.ipAddress;
}) vlan.dhcp.reservations;
option-data = [ option-data = [
{ {
name = "routers"; name = "routers";