WIP: add meta to packages and create nix-support/private file for unfree packages
			#20
		
		
	@ -23,6 +23,16 @@
 | 
				
			|||||||
      address = "10.0.42.40";
 | 
					      address = "10.0.42.40";
 | 
				
			||||||
      prefixLength = 24;
 | 
					      prefixLength = 24;
 | 
				
			||||||
    } ];
 | 
					    } ];
 | 
				
			||||||
 | 
					    firewall = {
 | 
				
			||||||
 | 
					      extraCommands = ''
 | 
				
			||||||
 | 
					        # Accept all incoming TCP traffic from lake2
 | 
				
			||||||
 | 
					        iptables -A nixos-fw -p tcp -s lake2 -j nixos-fw-accept
 | 
				
			||||||
 | 
					        # Accept monitoring requests from hut
 | 
				
			||||||
 | 
					        iptables -A nixos-fw -p tcp -s hut -m multiport --dport 9283,9002 -j nixos-fw-accept
 | 
				
			||||||
 | 
					        # Accept all Ceph traffic from the local network
 | 
				
			||||||
 | 
					        iptables -A nixos-fw -p tcp -s 10.0.40.0/24 -m multiport --dport 3300,6789,6800:7568 -j nixos-fw-accept
 | 
				
			||||||
 | 
					      '';
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  services.ceph = {
 | 
					  services.ceph = {
 | 
				
			||||||
 | 
				
			|||||||
@ -45,6 +45,14 @@
 | 
				
			|||||||
      address = "10.0.42.42";
 | 
					      address = "10.0.42.42";
 | 
				
			||||||
      prefixLength = 24;
 | 
					      prefixLength = 24;
 | 
				
			||||||
    } ];
 | 
					    } ];
 | 
				
			||||||
 | 
					    firewall = {
 | 
				
			||||||
 | 
					      extraCommands = ''
 | 
				
			||||||
 | 
					        # Accept all incoming TCP traffic from bay
 | 
				
			||||||
 | 
					        iptables -A nixos-fw -p tcp -s bay -j nixos-fw-accept
 | 
				
			||||||
 | 
					        # Accept monitoring requests from hut
 | 
				
			||||||
 | 
					        iptables -A nixos-fw -p tcp -s hut --dport 9002 -j nixos-fw-accept
 | 
				
			||||||
 | 
					      '';
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  # Missing service for volumes, see:
 | 
					  # Missing service for volumes, see:
 | 
				
			||||||
 | 
				
			|||||||
		Reference in New Issue
	
	Block a user