Files
jackos1998 d51f2d62b6 docs: Document the deployment
Add a top-level README mapping the boxes and a full docs/ tree: topic
pages (architecture, networking, deployment), per-site box pages for
colony and home with containers nested under their hosts, remote and
mobile boxes, the installer, and the home switch fabric reference
(folded in from home-switches.md, with AGENTS.md and code comments
retargeted to its new home). Box pages carry marked assignment tables
that CI regenerates from nixos.allAssignments.

AGENTS.md points at the new docs and keeps its terse agent version of
the mechanics, referring to the topic pages for depth.
2026-07-26 19:16:43 +01:00

3.1 KiB

sfh

"Services for home" — the NixOS container host for the home site. A VM on palace that netboots from river and runs its root off NVMe-oF from cellar.

Role

  • Runs the home NixOS containers via my.containers.instances (systemd-nspawn); each container is its own nixos.systems.* entry rendered through my.asContainer.
  • Netboot client (my.netboot.client.enable): the VM has no boot disk — its netboot NIC (MAC 52:54:00:a5:7e:93, on palace's lan-lo bridge, bootindex=1) is matched by a kea client-class on river and iPXE-boots from boot.h.nul.ie.
  • Root on NVMe-oF: my.nvme.boot connects to nqn.2016-06.io.spdk:sfh at 192.168.68.80 (cellar, RDMA) from the initrd (lan-hi up + roceBootModules); /nix and /persist are LVs on that volume. KeepConfiguration=static on lan-hi protects the NVMe-oF address from networkd reconfigures.
  • Frigate footage disk: palace passes the hdds/frigate LVM LV through as a virtio disk; sfh mounts it at /mnt/frigate (by label) and bind-mounts it into the hass container at /var/lib/frigate.
  • USB: two host ports are passed to the VM (qemu flags) for the Zigbee coordinator and webcam used by hass; the nspawn unit gets DeviceAllow for char-ttyUSB and char-video4linux.

Network assignments

Name Assignment IPv4 IPv6 Domain Notes
sfh hi 192.168.68.81/22 gw 192.168.71.254 2a0e:97c0:4d0:1::4:2/64 h.nul.ie

Networking

Four NICs, all MTU 9000 where jumbo-capable:

  • lan-hi — SR-IOV VF 2, the box's own hi assignment (192.168.68.81).
  • lan-hi-ctrs — SR-IOV VF 3, no L3: the MACVLAN parent for the containers' hi legs (host0 inside each container).
  • lan-core-ctrs / lan-lo-ctrs — virtio NICs (bridged to palace's lan-core / lan-lo), no L3: MACVLAN parents for containers that need a core or lo leg.

The per-container MACVLAN wiring lives in systemd.nspawn.*.networkConfig in sfh/default.nix.

Containers

Container Role Page
hass Home Assistant + Frigate + MQTT sfh/containers/hass.md
unifi UniFi controller sfh/containers/unifi.md

Notable config files