Files
nixfiles/docs/sites/home
dev 98162ea989 openwrt: Build fergal's firmware in the flake
fergal is an 8-port SFP+ switch on a Realtek RTL9303, running OpenWrt
rather than RouterOS or UniFi. It is not part of the fabric yet, but
its firmware is now built here via astro's nix-openwrt-imagebuilder.
Packages are baked into the image: OpenWrt's package server keeps only
the current build of each feed, so installing at runtime stops working
as soon as the feed moves past the running firmware.

Those feed indexes rotate constantly, and upstream pins only the
indexes -- a mismatch drops evaluation into import-from-derivation,
putting this flake's eval on the network. The openwrt-feeds input pins
expanded per-package hashes instead, in a repository of its own
because they run to hundreds of thousands of generated lines.

Flashing gets a procedure doc and a thin skill pointing at it, the
same split as the box installation and nixpkgs upgrade procedures.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-22 01:16:53 +01:00
..
2026-08-02 11:42:09 +01:00
2026-08-02 00:12:57 +01:00
2026-08-02 00:12:57 +01:00
2026-08-05 22:57:42 +01:00

Home site

The home network (domain h.nul.ie): a redundant pair of routers in front of a VM host, an NVMe-oF storage target, an IoT container host, and a workstation. The two routers — river (a VM) and stream (a physical box) — are built from one shared routing-common definition as an active/backup VRRP pair, and everything clients touch (gateway, DNS) is a floating VIP that follows the master.

Boxes

Box Role Host
palace VM host physical
river Primary router (VRRP pair with stream) VM on palace
stream Secondary router (VRRP pair with river) physical
cellar NVMe-oF / SPDK storage target VM on palace
sfh NixOS container host (containers on its page) VM on palace
castle Workstation / gaming desktop physical

Router VIPs

Clients use per-VLAN floating VIPs as their gateway and DNS server; keepalived moves them between river and stream. The addresses, DHCP/RA behavior and failover mechanics are documented once in Router VIPs and Router HA.

Networks

The site separates core management, high-MTU trusted traffic, general trusted traffic, untrusted clients and the two WAN paths. VLAN IDs, prefixes, MTUs and router addressing live in the canonical home section of networking.md.

Switch fabric

The boxes hang off three hand-configured switches — jim and dave (MikroTik, RouterOS) and brian (Ubiquiti, UniFi) — which are not managed by this flake. The physical topology, VLAN map, the Digiweb WAN path (trunked VLAN 10 + PVID 140 at the ONT edge), and the multi-ONT plan are documented in switches.md.

Wireless APs

The Wi-Fi APs — vibe (MikroTik cAP ax) and wave (Cudy AX3000 on OpenWrt) — are dumb APs, also not managed by this flake. The shared VLAN-trunk design, SSIDs, per-AP management addressing, and the OpenWrt flash/config for wave are in aps.md.

5G WWAN

A Quectel RM500U-EA USB modem with a GoMo SIM is being evaluated as a replacement for stream's Virgin Media WAN. It is bench-tested only and not yet referenced by the flake; the module settings it needs, the APN gotcha and the CGNAT consequences are in wwan.md.