README.md
hosts/infra-rtw-run
Host-specific configuration for infra.rtw.run (Hetzner Cloud, 2 vCPU, x86_64), a legacy-layout host: installed with nixos-infect before the fleet existed, so its hardware and networking are hand-written here instead of coming from modules/vm.nix and modules/hetzner.nix. What it runs is the forge role (roles/forge).
| File | What |
|---|---|
default.nix |
Hostname, static networking, stateVersion = "25.11" (never change it). |
hardware.nix |
From the nixos-infect install: GRUB on /dev/sda, root /dev/sda1 by device name. |
services.nix |
OpenSSH (root and btburke). |
secrets.nix |
btburke’s password hash. |
zone.db |
An exported BIND zone for rtw.run, for reference only. |
Shared with other legacy hosts: hosts/common/ (Nix GC, users, secrets wiring). Monitoring is the forge’s /healthz, watched by the monitor (~/projects/monitor), which alerts by email and Pushover.
Networking
Static, scripted backend, interface enp1s0:
- IPv4
178.104.201.207/32, gateway172.31.1.1. The gateway names its interface on purpose: since 26.05 the scripted backend only installs a default gateway on an interface it’s named for or whose subnet contains it, and 172.31.1.1 is outside the /32. - IPv6
2a01:4f8:1c18:235d::1/64, gatewayfe80::1onenp1s0.
Changing anything here restarts network-addresses-enp1s0, whose stop step removes every address and route before re-adding them. Deploy networking changes with --reboot.
The disk also has an EFI system partition (sda15) from Hetzner’s image; systemd automounts it at /efi. Unused.
Later
Rebuilding the host on the standard layout (nixos-anywhere, disko, vm.nix + hetzner.nix) and restoring from R2 is plan step 2.8; a good moment is when the CI runner is added.