docs/gotchas: describe hive-priv's network-isolation nspawn-conf branch, fix a spliced doc comment

This commit is contained in:
damocles 2026-08-29 11:51:14 +02:00 committed by mara
commit fcdba9e681
2 changed files with 18 additions and 8 deletions

View file

@ -30,9 +30,19 @@ Not `boot.isContainer = true`. Renamed in nixos-25.11+.
…in the `.conf`. The start script's `if HOST_ADDRESS set →
--network-veth` branch then forces a private netns — silently fatal
for our web UIs (the bind is invisible from the host). We
for our web UIs (the bind is invisible from the host). By default we
force-clear `HOST_ADDRESS` / `LOCAL_ADDRESS` / `HOST_ADDRESS6` /
`LOCAL_ADDRESS6` / `HOST_BRIDGE` and set `PRIVATE_NETWORK=0`.
`LOCAL_ADDRESS6` / `HOST_BRIDGE` and set `PRIVATE_NETWORK=0`
(`hive-priv`'s `write_nspawn_flags`).
When `HIVE_NETWORK_ISOLATION=1` is set (the `hive-network.nix` module's
`isolateContainers` option), the same function takes the opposite
branch instead: `PRIVATE_NETWORK=1` plus a veth pair onto the host
bridge, `HOST_ADDRESS` set to the bridge gateway IP (so
`nixos-container`'s in-container init installs a default route before
the DHCP lease arrives), and the rest left for DHCP. Isolation is a
per-host opt-in, not the default — most hosts still take the
force-clear branch above.
### systemd service PATH ≠ host PATH