87cdfdbd97
portcullis is wired over 10G to fergal, which uplinks to jim's spare SFP+ port. That uplink is untagged VLAN 1, so hi is carried tagged on a lan-hi VLAN interface: a static assignment at 192.168.68.41 / ::6:1, resolving through the router VIPs like any other hi client. Its gateway route outranks the DHCP default, making 10G the preferred path while the 2.5G bootstrap stays as a fallback. Deploy now targets that address. The hi MTU goes on the .network rather than the .link, since a .link is only applied at udev device-add -- with it there, et10g-0 stays at 1500 across a switch and lan-hi cannot take 9000. jim's sfp-spare was tagged into hi and lo out of band to match. fergal turns out to belong with portcullis rather than to the home fabric -- it goes to Nikhef when the box does -- so its documentation moves to the colony site, leaving home/switches.md a short section on what it borrows from that fabric. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
40 lines
2.0 KiB
Markdown
40 lines
2.0 KiB
Markdown
# colony
|
|
|
|
The hosted dedicated server in Amsterdam (`ams1`) and the public-facing half of
|
|
the boxes: almost everything reachable from the internet lives here.
|
|
|
|
- **Internal domain:** `ams1.int.nul.ie` (`lib.my.c.colony.domain`)
|
|
- **Public domain:** `nul.ie` — public services are published as `*.nul.ie`
|
|
- **Source:** [`nixos/boxes/colony/`](../../../nixos/boxes/colony)
|
|
|
|
## Networking
|
|
|
|
`colony` separates the host, VMs, `shill` containers and `whale2` OCI workloads onto dedicated
|
|
networks behind [`estuary`](estuary.md), which terminates the public addressing. The canonical
|
|
prefixes and routing overview are in the [`colony` section of networking.md](../../networking.md#colony).
|
|
|
|
## Boxes
|
|
|
|
| Box | Role |
|
|
|---|---|
|
|
| [`colony`](colony.md) | Physical VM host (AMD, KVM, LVM-thin, `borgthin` backups → rsync.net) |
|
|
| [`estuary`](estuary.md) | Edge router: WAN, firewall/NAT, DNS, BGP (AS211024), WireGuard |
|
|
| [`shill`](shill/README.md) | NixOS container host (most applications; per-container pages under `shill/`) |
|
|
| [`whale2`](whale2.md) | podman/OCI game-server host |
|
|
| [`git`](git.md) | Gitea + Gitea Actions runner |
|
|
| [`mail`](mail.md) | Debian VM running mailcow (not NixOS) |
|
|
| [`darts`](darts.md) | Third-party/customer VM (not NixOS) |
|
|
| [`portcullis`](portcullis.md) | Bare-metal edge box for Nikhef; being staged, not yet in service |
|
|
|
|
The applications running on `shill` are listed on its own page — see
|
|
[shill/README.md](shill/README.md#containers).
|
|
|
|
`mail` and `darts` are host-defined VMs whose guest operating systems are managed out of band; their
|
|
pages document only what this repository controls.
|
|
|
|
`portcullis` is new hardware headed for Nikhef that will take over most of `estuary`'s edge routing.
|
|
It is not deployed yet and the resulting topology is still being worked out. It travels with
|
|
[`fergal`](fergal.md), an OpenWrt SFP+ switch whose firmware this flake builds; both are staged at
|
|
home for now, borrowing the home fabric through
|
|
[jim](../home/switches.md#fergal-portculliss-switch).
|