# What every hyperhive service nixos-container sets for itself, imported # inside the container's own `config`. # # The host module that declares `containers.` sets the options below. # They restate host-side facts the container cannot read on its own: its # evaluation is nested inside `containers.`, and reading the host side # back from in here recurses. { config, lib, ... }: let cfg = config.services.hyperhive.swarmContainer; in { options.services.hyperhive.swarmContainer = { privateNetwork = lib.mkOption { type = lib.types.bool; description = '' Must equal the host-side `containers..privateNetwork`. When `false` the container shares the host netns, so its own firewall.service would rewrite the HOST ruleset at every boot; the container's firewall is turned off and the host firewall owns all filtering. ''; }; writesOwnResolvConf = lib.mkOption { type = lib.types.bool; default = true; description = '' Something in this container writes `/etc/resolv.conf` itself (the `swarm-container-resolver.nix` unit, or a static file), so resolvconf is forced off. Left on, host-tracking would regenerate the file empty, since the host's copy doesn't cross the boundary after start. ''; }; }; config = lib.mkMerge [ { # A container that sets its own keeps it. Changing this value changes # it for every container that doesn't, and that is a state migration # for each of them. system.stateVersion = lib.mkDefault "26.05"; } (lib.mkIf (!cfg.privateNetwork) { networking.firewall.enable = false; }) (lib.mkIf cfg.writesOwnResolvConf { networking.resolvconf.enable = lib.mkForce false; }) ]; }