From 3d3653efeb33fc96d58df5e733fdff52202c14a5 Mon Sep 17 00:00:00 2001 From: Erwin Boskma Date: Wed, 21 Sep 2022 22:52:10 +0200 Subject: [PATCH] Configure network for libvirtd with systemd --- modules/libvirtd/default.nix | 55 ++++++++++++++++++++++++++++++------ 1 file changed, 46 insertions(+), 9 deletions(-) diff --git a/modules/libvirtd/default.nix b/modules/libvirtd/default.nix index ba0b7b6..f09ff9c 100644 --- a/modules/libvirtd/default.nix +++ b/modules/libvirtd/default.nix @@ -9,23 +9,60 @@ in config = mkIf (cfg.enable) { virtualisation.libvirtd = { enable = true; + allowedBridges = [ "br0" ]; }; - networking = { - interfaces = { - br0 = { - useDHCP = true; - macAddress = "04:d9:f5:f9:c2:c6"; + + systemd.network = { + netdevs = { + "40-br0" = { + enable = true; + netdevConfig = { + Kind = "bridge"; + Name = "br0"; + }; + extraConfig = '' + [Bridge] + STP=yes + ''; }; }; - bridges = { - "br0" = { - interfaces = [ "enp4s0" ]; - # rstp = true; + networks = { + "40-br0" = { + enable = true; + matchConfig = { + Name = "br0"; + }; + linkConfig = { + MACAddress = "04:d9:f5:f9:c2:c6"; + }; + networkConfig = { + DHCP = "yes"; + IPv6PrivacyExtensions = "kernel"; + }; + }; + + "40-enp4s0" = { + enable = true; + bridge = [ "br0" ]; + matchConfig = { + Name = "enp4s0"; + }; + networkConfig = { + DHCP = mkForce "no"; + IPv6PrivacyExtensions = "kernel"; + }; }; }; }; + systemd.services.docker = { + serviceConfig = { + ExecStartPre = "${pkgs.iptables}/bin/iptables -I DOCKER-USER -i br0 -o br0 -j ACCEPT"; + }; + }; users.users.${config.eboskma.var.mainUser}.extraGroups = [ "libvirtd" ]; + + environment.systemPackages = with pkgs; [ virt-manager ]; }; }