portcullis is wired over 10G to fergal, which uplinks to jim's spare SFP+ port. That uplink is untagged VLAN 1, so hi is carried tagged on a lan-hi VLAN interface: a static assignment at 192.168.68.41 / ::6:1, resolving through the router VIPs like any other hi client. Its gateway route outranks the DHCP default, making 10G the preferred path while the 2.5G bootstrap stays as a fallback. Deploy now targets that address. The hi MTU goes on the .network rather than the .link, since a .link is only applied at udev device-add -- with it there, et10g-0 stays at 1500 across a switch and lan-hi cannot take 9000. jim's sfp-spare was tagged into hi and lo out of band to match. fergal turns out to belong with portcullis rather than to the home fabric -- it goes to Nikhef when the box does -- so its documentation moves to the colony site, leaving home/switches.md a short section on what it borrows from that fabric. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Deployment documentation
Note: these pages are a work in progress and were agent-generated from the repository. They may be incomplete or out of date — treat the Nix configuration as the source of truth.
This directory documents the boxes managed by this flake: their roles, network assignments,
hierarchy, and the services they run. For the mechanics of the repo itself (conventions, module
system internals for contributors, agent guidance), see AGENTS.md.
The two big sites follow the pattern:
physical host (VM host)
└── VM (for things impractical to containerise)
└── container host VM
└── NixOS containers (one per application group)
Not every box fits this pattern, but colony and home are organised this way.
General
architecture.md— the custom module system,my.*namespace, multiple nixpkgs channels, shared module inventory.networking.md— network assignments, domains, site topologies, router HA, the AS211024 L2 mesh, BGP, WireGuard, Tailscale.deployment.md— deploy-rs, devshell commands, secrets workflow, CI.nixpkgs-upgrade.md— guided procedure for the periodic upgrade of the four nixpkgs channels and home-manager (fork rebase, stable bumps, input review).install-box.md— guided procedure for installing a new box, from the booted installer through partitioning, the box config,do-installand documentation.openwrt-flash.md— guided procedure for flashing a flake-built image onto an OpenWrt box, from the build through pre-flight,sysupgradeand verification.reference/dns.md— generated forward and reverse DNS record reference.reference/nixos-options.md— generated per-option reference for the custommy.*NixOS modules.
Site: colony (Amsterdam)
Physical host and public-infrastructure hub — see sites/colony/README.md.
colony (physical VM host, ams1)
├── estuary ── edge router: WAN, firewall/NAT, DNS, BGP (AS211024), WireGuard
├── shill ──── NixOS container host ──┬── middleman (reverse proxy, ACME, nginx-sso, librespeed)
│ ├── vaultwarden (password manager)
│ ├── colony-psql (shared PostgreSQL)
│ ├── chatterbox (Matrix Synapse + bridges)
│ ├── jackflix (media stack)
│ ├── object (MinIO, Harmonia Nix cache, Sharry, HedgeDoc, wastebin)
│ ├── toot (Bluesky PDS; Mastodon disabled)
│ ├── waffletail (Tailscale subnet router / exit node)
│ ├── qclk (WireGuard management appliance)
│ ├── gam (Terraria server)
│ └── jam (raw nspawn customer container)
├── whale2 ─── podman/OCI host for game servers
├── git ────── Gitea + Gitea Actions runner
├── mail ───── Debian VM running mailcow (not NixOS)
└── darts ──── third-party/customer VM (opaque, not NixOS)
portcullis (bare-metal edge box for Nikhef — staged, not yet in service)
└── fergal OpenWrt SFP+ switch, staged and moving with it
Site: home
Redundant routers, VM host, storage, IoT containers and the workstation — see
sites/home/README.md. The hand-configured switch fabric (jim/dave/brian)
and the Digiweb WAN path are documented in sites/home/switches.md; the
5G modem being evaluated as a replacement for stream's WAN is in
sites/home/wwan.md.
h.nul.ie
├── palace (physical VM host — AMD, 100G, SR-IOV)
│ ├── river ── primary router VM (PPPoE / Digiweb WAN)
│ ├── cellar ─ NVMe-oF / SPDK storage target VM
│ └── sfh ──── container host VM ("shill from home")
│ ├── hass ── Home Assistant + Frigate + MQTT (container)
│ └── unifi ─ UniFi controller (container)
├── stream (physical secondary router — Virgin Media WAN)
└── castle (workstation / gaming desktop — netboot, NVMe-oF root)
Remote boxes
The edge VPSes and remote kelder site are indexed in remote/README.md.
Mobile boxes
The laptop is indexed in mobile/README.md.
Misc
misc/installer.md— the custom NixOS installer image.
A note on the assignment tables
The consolidated Box assignments tables in
networking.md (one per site, between <!-- assignments: <site> --> markers)
are generated from the flake (nixos.allAssignments) by nix run .#update-docs-assignments —
CI refreshes them on push. Individual box pages link to that section rather than carrying their
own table. Only the Notes column is hand-written; don't hand-edit the other cells.