Files
nixfiles/docs/sites/colony
jackos1998 87cdfdbd97 nixos/portcullis: Bring up 10G on the home hi VLAN
portcullis is wired over 10G to fergal, which uplinks to jim's spare
SFP+ port. That uplink is untagged VLAN 1, so hi is carried tagged on a
lan-hi VLAN interface: a static assignment at 192.168.68.41 / ::6:1,
resolving through the router VIPs like any other hi client. Its gateway
route outranks the DHCP default, making 10G the preferred path while the
2.5G bootstrap stays as a fallback. Deploy now targets that address.

The hi MTU goes on the .network rather than the .link, since a .link is
only applied at udev device-add -- with it there, et10g-0 stays at 1500
across a switch and lan-hi cannot take 9000.

jim's sfp-spare was tagged into hi and lo out of band to match.

fergal turns out to belong with portcullis rather than to the home
fabric -- it goes to Nikhef when the box does -- so its documentation
moves to the colony site, leaving home/switches.md a short section on
what it borrows from that fabric.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-22 01:30:50 +01:00
..
2026-08-02 00:12:57 +01:00
2026-08-02 00:12:57 +01:00
2026-08-02 01:07:27 +01:00
2026-08-02 00:12:57 +01:00
2026-08-02 00:12:57 +01:00
2026-08-02 00:12:57 +01:00

colony

The hosted dedicated server in Amsterdam (ams1) and the public-facing half of the boxes: almost everything reachable from the internet lives here.

  • Internal domain: ams1.int.nul.ie (lib.my.c.colony.domain)
  • Public domain: nul.ie — public services are published as *.nul.ie
  • Source: nixos/boxes/colony/

Networking

colony separates the host, VMs, shill containers and whale2 OCI workloads onto dedicated networks behind estuary, which terminates the public addressing. The canonical prefixes and routing overview are in the colony section of networking.md.

Boxes

Box Role
colony Physical VM host (AMD, KVM, LVM-thin, borgthin backups → rsync.net)
estuary Edge router: WAN, firewall/NAT, DNS, BGP (AS211024), WireGuard
shill NixOS container host (most applications; per-container pages under shill/)
whale2 podman/OCI game-server host
git Gitea + Gitea Actions runner
mail Debian VM running mailcow (not NixOS)
darts Third-party/customer VM (not NixOS)
portcullis Bare-metal edge box for Nikhef; being staged, not yet in service

The applications running on shill are listed on its own page — see shill/README.md.

mail and darts are host-defined VMs whose guest operating systems are managed out of band; their pages document only what this repository controls.

portcullis is new hardware headed for Nikhef that will take over most of estuary's edge routing. It is not deployed yet and the resulting topology is still being worked out. It travels with fergal, an OpenWrt SFP+ switch whose firmware this flake builds; both are staged at home for now, borrowing the home fabric through jim.