netcup.nix
1# netcup root servers and VPSes: networking and resolvers.
2#
3# netcup's DHCP support varies by product and isn't documented, and IPv6 is
4# never handed out by DHCP or RA. So both addresses are static, as
5# `just new-host` read them from the stock Debian image: IPv4 with its
6# prefix length and gateway, and the IPv6 address with netcup's fixed
7# link-local gateway.
8#
9# `host` is this machine's entry from hosts.json (a specialArg).
10{ host, lib, ... }:
11
12let
13 hasIpv6 = host.ipv6 or null != null;
14in
15{
16 assertions = [
17 {
18 assertion = host ? ipv4Prefix && host ? ipv4Gateway;
19 message = "${host.name}: netcup hosts need ipv4Prefix and ipv4Gateway in hosts.json (just new-host records them)";
20 }
21 ];
22
23 systemd.network.networks."10-uplink" = {
24 matchConfig.Type = "ether";
25 networkConfig = {
26 DHCP = "no";
27 IPv6AcceptRA = false;
28 };
29 address = [
30 "${host.ipv4}/${toString (host.ipv4Prefix or 32)}"
31 ]
32 ++ lib.optional hasIpv6 host.ipv6;
33 routes = [
34 { Gateway = host.ipv4Gateway or "0.0.0.0"; }
35 ]
36 ++ lib.optional hasIpv6 { Gateway = "fe80::1"; };
37 };
38
39 # netcup's recursive resolvers (community.netcup.com, "How to set up a DNS
40 # server on netcup servers").
41 services.resolved.settings.Resolve.DNS = [
42 "46.38.225.230"
43 "46.38.252.230"
44 "2a03:4000:0:1::e1e6"
45 "2a03:4000:8000::fce6"
46 ];
47}