default.nix
1# hosts/infra-rtw-run/default.nix
2# Entry point for infra.rtw.run host
3{ config, lib, pkgs, ... }:
4{
5 imports = [
6 ../common
7 ./hardware.nix
8 ./services.nix
9 ./secrets.nix
10 ];
11
12 # Host-specific settings
13 networking.hostName = "infra";
14 networking.domain = "rtw.run";
15
16 # Static network configuration from nixos-infect
17 # Disabling DHCP since we have static IPs
18 networking.useDHCP = lib.mkForce false;
19 networking.dhcpcd.enable = lib.mkForce false;
20
21 # IPv4 configuration
22 # The interface must be named: since 26.05 the scripted backend only sets a
23 # default gateway on an interface it's named for or whose subnet contains
24 # it, and 172.31.1.1 is outside our /32. Without this the box boots with no
25 # IPv4 default route (plan 2.5).
26 networking.defaultGateway = {
27 address = "172.31.1.1";
28 interface = "enp1s0";
29 };
30 networking.nameservers = [ "8.8.8.8" ];
31
32 # IPv6: Hetzner's gateway is the link-local fe80::1 (routed below). There
33 # was no default route before 2.5a, so IPv6 never worked off-link.
34 networking.defaultGateway6 = {
35 address = "fe80::1";
36 interface = "enp1s0";
37 };
38
39 # Interface configuration
40 networking.interfaces.enp1s0 = {
41 ipv4.addresses = [
42 { address = "178.104.201.207"; prefixLength = 32; }
43 ];
44 ipv4.routes = [
45 { address = "172.31.1.1"; prefixLength = 32; }
46 ];
47 ipv6.addresses = [
48 { address = "2a01:4f8:1c18:235d::1"; prefixLength = 64; }
49 { address = "fe80::9000:7ff:fe91:5ae8"; prefixLength = 64; }
50 ];
51 ipv6.routes = [
52 { address = "fe80::1"; prefixLength = 128; }
53 ];
54 };
55
56 system.stateVersion = "25.11";
57}