From 1c52f8a6b97825756a903e53dd9df4b630cf5da5 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 28 Jul 2026 22:42:21 -0500 Subject: [PATCH] chore: baseline nixos for proxmox configuration --- hosts/unstable/builder2/default.nix | 63 ++++++++++++++++++++++++----- 1 file changed, 52 insertions(+), 11 deletions(-) diff --git a/hosts/unstable/builder2/default.nix b/hosts/unstable/builder2/default.nix index 12b9be9..dcbefe5 100644 --- a/hosts/unstable/builder2/default.nix +++ b/hosts/unstable/builder2/default.nix @@ -1,19 +1,60 @@ -{ config, modulesPath, pkgs, lib, ... }: { - imports = [ (modulesPath + "/virtualisation/proxmox-lxc.nix") ]; - nix.settings = { sandbox = false; }; - proxmoxLXC = { - manageNetwork = false; - privileged = true; + config, + metadata, + modulesPath, + ... +}: +{ + # Then build nixosConfiguration..config.system.build.images.proxmox + # SCP that to /var/lib/vz/dumps on the Proxmox host + imports = [ "${modulesPath}/virtualisation/proxmox-image.nix" ]; + greg = { + home = true; + nebula.enable = true; }; - services.fstrim.enable = false; # Let Proxmox host handle fstrim - services.openssh = { - enable = true; - openFirewall = true; - settings = { + networking = { + defaultGateway = metadata.infra.gw; + nameservers = [ metadata.infra.dns ]; + interfaces.ens18 = { + useDHCP = false; + ipv4.addresses = [ + { + address = metadata.hosts."${config.networking.hostName}".ip; + prefixLength = 16; + } + ]; + }; + }; + virtualisation.diskSize = 20480; # Size in mebbibytes for the base disk image + # Use these instead of the above to run an LXC image + # The main reason I wouldn't use these is because Proxmox LXC does + # not seem to be well supported by either Nebula VPN or Tailscale, + # both of which I use for my mesh networking. If there isn't a need + # for the service to run on those networks, then by all means go ahead + # and use LXC! + # imports = [ (modulesPath + "/virtualisation/proxmox-lxc.nix") ]; + # proxmoxLXC = { + # manageNetwork = false; + # privileged = true; + # }; + # systemd.suppressedSystemUnits = [ + # "dev-mqueue.mount" + # "sys-kernel-debug.mount" + # "sys-fs-fuse-connections.mount" + # ]; + nix.settings = { + sandbox = false; + }; + services = { + fstrim.enable = false; # Let Proxmox host handle fstrim + openssh = { + enable = true; + openFirewall = true; + settings = { PermitRootLogin = "yes"; PasswordAuthentication = true; PermitEmptyPasswords = "yes"; + }; }; }; }