diff --git a/docs/networking.md b/docs/networking.md index 9239df6..03867b0 100644 --- a/docs/networking.md +++ b/docs/networking.md @@ -321,6 +321,12 @@ family move together. serving disjoint pool halves. `radvd` advertises the v6 VIP as RDNSS (`untrusted` gets Cloudflare) and keepalived's `notify_master`/`notify_backup` hooks ensure that only the master sends RAs. +Statically-addressed boxes (the servers on `hi`) don't run DHCP, so they'd otherwise learn a +resolver only from the v6 RA RDNSS — which vanishes when v6 is disabled, taking DNS with it. They +instead anchor DNS on the VIPs via the shared `lib.my.c.home.vlanDns ""` fragment, which sets +`DNS` to `vips..{v4,v6}` and `Domains` to the advertised search list; the always-present +static v4 VIP keeps resolution working even with v6 down. + #### DNS binding `pdns-recursor` binds the VIPs directly; see diff --git a/lib/constants.nix b/lib/constants.nix index 7f530c6..984ca8e 100644 --- a/lib/constants.nix +++ b/lib/constants.nix @@ -385,6 +385,16 @@ rec { }; }; + # networkConfig fragment anchoring a VLAN client's DNS on the router pair's + # VRRP VIPs rather than the RA RDNSS. v6 addresses here are RA/token-derived, + # so when RA is absent (e.g. v6 disabled) there is no v6 and no RDNSS at all; + # the always-present static v4 VIP keeps name resolution working, with the v6 + # VIP as a bonus when v6 is up. Merge into the VLAN network's networkConfig. + vlanDns = vlan: { + DNS = [ vips.${vlan}.v4 vips.${vlan}.v6 ]; + Domains = searchDomains; + }; + roceBootModules = [ "ib_core" "ib_uverbs" "mlx5_core" "mlx5_ib" ]; }; diff --git a/nixos/boxes/home/castle/default.nix b/nixos/boxes/home/castle/default.nix index 05b80d4..9cdee57 100644 --- a/nixos/boxes/home/castle/default.nix +++ b/nixos/boxes/home/castle/default.nix @@ -2,7 +2,7 @@ let inherit (lib.my) net; inherit (lib.my.c) networkd; - inherit (lib.my.c.home) domain searchDomains vlans prefixes vips roceBootModules; + inherit (lib.my.c.home) domain vlans prefixes vips vlanDns roceBootModules; in { nixos.systems.castle = { @@ -190,11 +190,7 @@ in "40-lan-hi" = mkMerge [ (networkdAssignment "lan-hi" assignments.hi) { - networkConfig = { - # v6 is RA/SLAAC-derived, so when RA is absent we have no v6 at all; - # anchor DNS on the always-present static v4 (the VRRP VIP follows the master) - DNS = [ vips.hi.v4 vips.hi.v6 ]; - Domains = searchDomains; + networkConfig = vlanDns "hi" // { # So we don't drop the IP we use to connect to NVMe-oF! KeepConfiguration = "static"; }; diff --git a/nixos/boxes/home/palace/default.nix b/nixos/boxes/home/palace/default.nix index b474280..92a17a2 100644 --- a/nixos/boxes/home/palace/default.nix +++ b/nixos/boxes/home/palace/default.nix @@ -2,7 +2,7 @@ let inherit (lib.my) net mkVLAN; inherit (lib.my.c) pubDomain; - inherit (lib.my.c.home) domain vlans prefixes vips hiMTU; + inherit (lib.my.c.home) domain vlans prefixes vips vlanDns hiMTU; in { imports = [ ./vms ]; @@ -203,7 +203,10 @@ in MACAddress=52:54:00:90:34:95 ''; }; - "60-lan-hi" = networkdAssignment "lan-hi" assignments.hi; + "60-lan-hi" = mkMerge [ + (networkdAssignment "lan-hi" assignments.hi) + { networkConfig = vlanDns "hi"; } + ]; "50-lan-core-phy" = { matchConfig.Name = "lan-core-phy"; diff --git a/nixos/boxes/home/palace/vms/cellar/default.nix b/nixos/boxes/home/palace/vms/cellar/default.nix index e57034d..1b2594c 100644 --- a/nixos/boxes/home/palace/vms/cellar/default.nix +++ b/nixos/boxes/home/palace/vms/cellar/default.nix @@ -2,7 +2,7 @@ let inherit (lib.my) net; inherit (lib.my.c) pubDomain; - inherit (lib.my.c.home) domain prefixes vips hiMTU; + inherit (lib.my.c.home) domain prefixes vips vlanDns hiMTU; in { nixos.systems.cellar = { @@ -79,7 +79,10 @@ in }; networks = { - "80-lan-hi" = networkdAssignment "lan-hi" assignments.hi; + "80-lan-hi" = mkMerge [ + (networkdAssignment "lan-hi" assignments.hi) + { networkConfig = vlanDns "hi"; } + ]; }; }; diff --git a/nixos/boxes/home/palace/vms/sfh/containers/hass.nix b/nixos/boxes/home/palace/vms/sfh/containers/hass.nix index c65d793..8317345 100644 --- a/nixos/boxes/home/palace/vms/sfh/containers/hass.nix +++ b/nixos/boxes/home/palace/vms/sfh/containers/hass.nix @@ -2,7 +2,7 @@ let inherit (lib.my) net; inherit (lib.my.c) pubDomain; - inherit (lib.my.c.home) domain prefixes vips hiMTU; + inherit (lib.my.c.home) domain prefixes vips vlanDns hiMTU; in { nixos.systems.hass = { config, ... }: { @@ -82,7 +82,10 @@ in systemd = { network.networks = { - "80-container-host0" = networkdAssignment "host0" assignments.hi; + "80-container-host0" = mkMerge [ + (networkdAssignment "host0" assignments.hi) + { networkConfig = vlanDns "hi"; } + ]; "80-container-lan-lo" = networkdAssignment "lan-lo" assignments.lo; }; }; diff --git a/nixos/boxes/home/palace/vms/sfh/containers/unifi.nix b/nixos/boxes/home/palace/vms/sfh/containers/unifi.nix index 0e5429e..363691f 100644 --- a/nixos/boxes/home/palace/vms/sfh/containers/unifi.nix +++ b/nixos/boxes/home/palace/vms/sfh/containers/unifi.nix @@ -1,7 +1,7 @@ { lib, ... }: let inherit (lib.my) net; - inherit (lib.my.c.home) domain prefixes vips hiMTU; + inherit (lib.my.c.home) domain prefixes vips vlanDns hiMTU; in { nixos.systems.unifi = { config, ... }: { @@ -58,7 +58,10 @@ in systemd = { network.networks = { - "80-container-host0" = networkdAssignment "host0" assignments.hi; + "80-container-host0" = mkMerge [ + (networkdAssignment "host0" assignments.hi) + { networkConfig = vlanDns "hi"; } + ]; "80-lan-core" = networkdAssignment "lan-core" assignments.core; }; }; diff --git a/nixos/boxes/home/palace/vms/sfh/default.nix b/nixos/boxes/home/palace/vms/sfh/default.nix index 0a57f67..b06bbef 100644 --- a/nixos/boxes/home/palace/vms/sfh/default.nix +++ b/nixos/boxes/home/palace/vms/sfh/default.nix @@ -1,7 +1,7 @@ { lib, ... }: let inherit (lib.my) net; - inherit (lib.my.c.home) domain prefixes vips hiMTU roceBootModules; + inherit (lib.my.c.home) domain prefixes vips vlanDns hiMTU roceBootModules; in { imports = [ ./containers ]; @@ -134,8 +134,10 @@ in networks = { "30-lan-hi" = mkMerge [ (networkdAssignment "lan-hi" assignments.hi) - # So we don't drop the IP we use to connect to NVMe-oF! - { networkConfig.KeepConfiguration = "static"; } + { + # So we don't drop the IP we use to connect to NVMe-oF! + networkConfig = vlanDns "hi" // { KeepConfiguration = "static"; }; + } ]; "30-lan-hi-ctrs" = { matchConfig.Name = "lan-hi-ctrs";