cnx-network 4146f2c -> 596ac1f: allowWan VLANs are now forwarded and masqueraded through stagingPort (lan5) while ppp0 is down, and pppd gets `defaultroute-metric 0` so the PPPoE route is installed next to the staging DHCP route instead of being refused. Also makes CrowdSec opt-in upstream (stellio leaves it off). The nixpkgs Blocky config check runs the aarch64 binary, which an x86_64 builder without binfmt cannot execute (`--max-jobs 0`); validate the same YAML with the build host's blocky until the router service carries this.
53 lines
1.7 KiB
Nix
53 lines
1.7 KiB
Nix
{
|
|
config,
|
|
inputs,
|
|
lib,
|
|
pkgs,
|
|
...
|
|
}:
|
|
{
|
|
imports = [
|
|
inputs.matthew-hardware.nixosModules.mt7986a-glinet-gl-mt6000
|
|
];
|
|
|
|
# matthew-hardware's common/generic-uefi-image.nix still sets
|
|
# `image.repart.enable = true`; nixpkgs removed that option (importing
|
|
# image/repart.nix now always defines system.build.image). Declare it so the
|
|
# definition has somewhere to land. Drop once upstream stops setting it.
|
|
options.image.repart.enable = lib.mkOption {
|
|
type = lib.types.bool;
|
|
default = true;
|
|
internal = true;
|
|
};
|
|
|
|
config = {
|
|
hardware.mt7986a-glinet-gl-mt6000.enable = true;
|
|
hardware.mt7986a-glinet-gl-mt6000.zealous = true;
|
|
hardware.mt7986a-glinet-gl-mt6000.image.repart.enable = true;
|
|
|
|
nixpkgs.hostPlatform.system = "aarch64-linux";
|
|
nixpkgs.buildPlatform.system = "x86_64-linux";
|
|
|
|
system.stateVersion = "26.11";
|
|
clan.core.sops.defaultGroups = [ "admins" ];
|
|
|
|
clan.core.settings.name = "stellio";
|
|
clan.core.settings.machine.description = "Flint-2 router";
|
|
|
|
# nixpkgs' services.blocky check runs the aarch64 blocky in a
|
|
# system.checks derivation, which an x86_64 builder without binfmt cannot
|
|
# execute (`--max-jobs 0` -> Exec format error). Validate the same YAML
|
|
# with the build host's blocky instead. Drop once cnx-network's router
|
|
# service carries this itself (router/dns: validate the Blocky config
|
|
# with the build host's binary).
|
|
services.blocky.enableConfigCheck = false;
|
|
system.checks = [
|
|
(pkgs.runCommand "check-blocky-config" { } ''
|
|
${lib.getExe pkgs.buildPackages.blocky} --config ${
|
|
(pkgs.formats.yaml { }).generate "blocky-config.yaml" config.services.blocky.settings
|
|
} validate && touch $out
|
|
'')
|
|
];
|
|
};
|
|
}
|