chore: baseline nixos for proxmox configuration

This commit is contained in:
Greg Hellings
2026-07-28 22:42:21 -05:00
parent d9334a237d
commit 1c52f8a6b9
+52 -11
View File
@@ -1,19 +1,60 @@
{ config, modulesPath, pkgs, lib, ... }:
{ {
imports = [ (modulesPath + "/virtualisation/proxmox-lxc.nix") ]; config,
nix.settings = { sandbox = false; }; metadata,
proxmoxLXC = { modulesPath,
manageNetwork = false; ...
privileged = true; }:
{
# Then build nixosConfiguration.<host>.config.system.build.images.proxmox
# SCP that to /var/lib/vz/dumps on the Proxmox host
imports = [ "${modulesPath}/virtualisation/proxmox-image.nix" ];
greg = {
home = true;
nebula.enable = true;
}; };
services.fstrim.enable = false; # Let Proxmox host handle fstrim networking = {
services.openssh = { defaultGateway = metadata.infra.gw;
enable = true; nameservers = [ metadata.infra.dns ];
openFirewall = true; interfaces.ens18 = {
settings = { useDHCP = false;
ipv4.addresses = [
{
address = metadata.hosts."${config.networking.hostName}".ip;
prefixLength = 16;
}
];
};
};
virtualisation.diskSize = 20480; # Size in mebbibytes for the base disk image
# Use these instead of the above to run an LXC image
# The main reason I wouldn't use these is because Proxmox LXC does
# not seem to be well supported by either Nebula VPN or Tailscale,
# both of which I use for my mesh networking. If there isn't a need
# for the service to run on those networks, then by all means go ahead
# and use LXC!
# imports = [ (modulesPath + "/virtualisation/proxmox-lxc.nix") ];
# proxmoxLXC = {
# manageNetwork = false;
# privileged = true;
# };
# systemd.suppressedSystemUnits = [
# "dev-mqueue.mount"
# "sys-kernel-debug.mount"
# "sys-fs-fuse-connections.mount"
# ];
nix.settings = {
sandbox = false;
};
services = {
fstrim.enable = false; # Let Proxmox host handle fstrim
openssh = {
enable = true;
openFirewall = true;
settings = {
PermitRootLogin = "yes"; PermitRootLogin = "yes";
PasswordAuthentication = true; PasswordAuthentication = true;
PermitEmptyPasswords = "yes"; PermitEmptyPasswords = "yes";
};
}; };
}; };
} }