nix: move the in-container modules to nix/container-modules/
Refs #3773
This commit is contained in:
parent
024067f3f8
commit
cce41c1d79
11 changed files with 10 additions and 10 deletions
52
nix/container-modules/swarm-container.nix
Normal file
52
nix/container-modules/swarm-container.nix
Normal file
|
|
@ -0,0 +1,52 @@
|
|||
# What every hyperhive service nixos-container sets for itself, imported
|
||||
# inside the container's own `config`.
|
||||
#
|
||||
# The host module that declares `containers.<name>` sets the options below.
|
||||
# They restate host-side facts the container cannot read on its own: its
|
||||
# evaluation is nested inside `containers.<name>`, and reading the host side
|
||||
# back from in here recurses.
|
||||
{ config, lib, ... }:
|
||||
let
|
||||
cfg = config.services.hyperhive.swarmContainer;
|
||||
in
|
||||
{
|
||||
options.services.hyperhive.swarmContainer = {
|
||||
privateNetwork = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
description = ''
|
||||
Must equal the host-side `containers.<name>.privateNetwork`. When
|
||||
`false` the container shares the host netns, so its own
|
||||
firewall.service would rewrite the HOST ruleset at every boot; the
|
||||
container's firewall is turned off and the host firewall owns all
|
||||
filtering.
|
||||
'';
|
||||
};
|
||||
|
||||
writesOwnResolvConf = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = ''
|
||||
Something in this container writes `/etc/resolv.conf` itself (the
|
||||
`swarm-container-resolver.nix` unit, or a static file), so
|
||||
resolvconf is forced off. Left on, host-tracking would regenerate the
|
||||
file empty, since the host's copy doesn't cross the boundary after
|
||||
start.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkMerge [
|
||||
{
|
||||
# A container that sets its own keeps it. Changing this value changes
|
||||
# it for every container that doesn't, and that is a state migration
|
||||
# for each of them.
|
||||
system.stateVersion = lib.mkDefault "26.05";
|
||||
}
|
||||
(lib.mkIf (!cfg.privateNetwork) {
|
||||
networking.firewall.enable = false;
|
||||
})
|
||||
(lib.mkIf cfg.writesOwnResolvConf {
|
||||
networking.resolvconf.enable = lib.mkForce false;
|
||||
})
|
||||
];
|
||||
}
|
||||
Loading…
Reference in a new issue