default.nix

 1# hosts/infra-rtw-run/default.nix
 2# Entry point for infra.rtw.run host
 3{ config, lib, pkgs, ... }:
 4{
 5  imports = [
 6    ../common
 7    ./hardware.nix
 8    ./services.nix
 9    ./secrets.nix
10  ];
11
12  # Host-specific settings
13  networking.hostName = "infra";
14  networking.domain = "rtw.run";
15  
16  # Static network configuration from nixos-infect
17  # Disabling DHCP since we have static IPs
18  networking.useDHCP = lib.mkForce false;
19  networking.dhcpcd.enable = lib.mkForce false;
20  
21  # IPv4 configuration
22  # The interface must be named: since 26.05 the scripted backend only sets a
23  # default gateway on an interface it's named for or whose subnet contains
24  # it, and 172.31.1.1 is outside our /32. Without this the box boots with no
25  # IPv4 default route (plan 2.5).
26  networking.defaultGateway = {
27    address = "172.31.1.1";
28    interface = "enp1s0";
29  };
30  networking.nameservers = [ "8.8.8.8" ];
31
32  # IPv6: Hetzner's gateway is the link-local fe80::1 (routed below). There
33  # was no default route before 2.5a, so IPv6 never worked off-link.
34  networking.defaultGateway6 = {
35    address = "fe80::1";
36    interface = "enp1s0";
37  };
38  
39  # Interface configuration
40  networking.interfaces.enp1s0 = {
41    ipv4.addresses = [ 
42      { address = "178.104.201.207"; prefixLength = 32; } 
43    ];
44    ipv4.routes = [ 
45      { address = "172.31.1.1"; prefixLength = 32; } 
46    ];
47    ipv6.addresses = [ 
48      { address = "2a01:4f8:1c18:235d::1"; prefixLength = 64; }
49      { address = "fe80::9000:7ff:fe91:5ae8"; prefixLength = 64; }
50    ];
51    ipv6.routes = [ 
52      { address = "fe80::1"; prefixLength = 128; } 
53    ];
54  };
55  
56  system.stateVersion = "25.11";
57}