Files
nixfiles/docs
jackos1998 b9bcb1eaeb
Update docs / update (push) Successful in 1m10s
CI / Check, build and cache nixfiles (push) Has been cancelled
nixos/home: Anchor static hi clients' DNS on VIPs
Statically-addressed home servers on hi run no DHCP, so they learned a
resolver only from the v6 RA RDNSS and lost DNS whenever v6 (and thus
the RA) was absent. Factor the fix castle/palace applied inline into a
shared lib.my.c.home.vlanDns helper that points resolved at the VLAN's
VRRP VIPs (always-present static v4, plus v6 when up) and sets the
advertised search domains, then apply it to every statically-addressed
hi client: castle, palace, cellar, sfh and the sfh hass/unifi
containers. Document it under the router client DNS section.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-03 22:27:47 +01:00
..
2026-08-02 00:12:57 +01:00
2026-08-02 11:42:09 +01:00

Deployment documentation

Note: these pages are a work in progress and were agent-generated from the repository. They may be incomplete or out of date — treat the Nix configuration as the source of truth.

This directory documents the boxes managed by this flake: their roles, network assignments, hierarchy, and the services they run. For the mechanics of the repo itself (conventions, module system internals for contributors, agent guidance), see AGENTS.md.

The two big sites follow the pattern:

physical host (VM host)
└── VM (for things impractical to containerise)
    └── container host VM
        └── NixOS containers (one per application group)

Not every box fits this pattern, but colony and home are organised this way.

General

  • architecture.md — the custom module system, my.* namespace, multiple nixpkgs channels, shared module inventory.
  • networking.md — network assignments, domains, site topologies, router HA, the AS211024 L2 mesh, BGP, WireGuard, Tailscale.
  • deployment.md — deploy-rs, devshell commands, secrets workflow, CI.
  • reference/dns.md — generated forward and reverse DNS record reference.
  • reference/nixos-options.md — generated per-option reference for the custom my.* NixOS modules.

Site: colony (Amsterdam)

Physical host and public-infrastructure hub — see sites/colony/README.md.

colony (physical VM host, ams1)
├── estuary ── edge router: WAN, firewall/NAT, DNS, BGP (AS211024), WireGuard
├── shill ──── NixOS container host ──┬── middleman    (reverse proxy, ACME, nginx-sso, librespeed)
│                                     ├── vaultwarden  (password manager)
│                                     ├── colony-psql  (shared PostgreSQL)
│                                     ├── chatterbox   (Matrix Synapse + bridges)
│                                     ├── jackflix     (media stack)
│                                     ├── object       (MinIO, Harmonia Nix cache, Sharry, HedgeDoc, wastebin)
│                                     ├── toot         (Bluesky PDS; Mastodon disabled)
│                                     ├── waffletail   (Tailscale subnet router / exit node)
│                                     ├── qclk         (WireGuard management appliance)
│                                     ├── gam          (Terraria server)
│                                     └── jam          (raw nspawn customer container)
├── whale2 ─── podman/OCI host for game servers
├── git ────── Gitea + Gitea Actions runner
├── mail ───── Debian VM running mailcow (not NixOS)
└── darts ──── third-party/customer VM (opaque, not NixOS)

Site: home

Redundant routers, VM host, storage, IoT containers and the workstation — see sites/home/README.md. The hand-configured switch fabric (jim/dave/brian) and the Digiweb WAN path are documented in sites/home/switches.md.

h.nul.ie
├── palace (physical VM host — AMD, 100G, SR-IOV)
│   ├── river ── primary router VM (PPPoE / Digiweb WAN)
│   ├── cellar ─ NVMe-oF / SPDK storage target VM
│   └── sfh ──── container host VM ("shill from home")
│       ├── hass ── Home Assistant + Frigate + MQTT (container)
│       └── unifi ─ UniFi controller (container)
├── stream (physical secondary router — Virgin Media WAN)
└── castle (workstation / gaming desktop — netboot, NVMe-oF root)

Remote boxes

The edge VPSes and remote kelder site are indexed in remote/README.md.

Mobile boxes

The laptop is indexed in mobile/README.md.

Misc

A note on the assignment tables

The consolidated Box assignments tables in networking.md (one per site, between <!-- assignments: <site> --> markers) are generated from the flake (nixos.allAssignments) by nix run .#update-docs-assignments — CI refreshes them on push. Individual box pages link to that section rather than carrying their own table. Only the Notes column is hand-written; don't hand-edit the other cells.