d51f2d62b6
Add a top-level README mapping the boxes and a full docs/ tree: topic pages (architecture, networking, deployment), per-site box pages for colony and home with containers nested under their hosts, remote and mobile boxes, the installer, and the home switch fabric reference (folded in from home-switches.md, with AGENTS.md and code comments retargeted to its new home). Box pages carry marked assignment tables that CI regenerates from nixos.allAssignments. AGENTS.md points at the new docs and keeps its terse agent version of the mechanics, referring to the topic pages for depth.
3.1 KiB
3.1 KiB
sfh
"Services for home" — the NixOS container host for the home site. A VM on palace that netboots
from river and runs its root off NVMe-oF from cellar.
- Source:
nixos/boxes/home/palace/vms/sfh/(default.nix,containers/) - Host: VM on
palace
Role
- Runs the home NixOS containers via
my.containers.instances(systemd-nspawn); each container is its ownnixos.systems.*entry rendered throughmy.asContainer. - Netboot client (
my.netboot.client.enable): the VM has no boot disk — itsnetbootNIC (MAC52:54:00:a5:7e:93, on palace'slan-lobridge,bootindex=1) is matched by a kea client-class onriverand iPXE-boots fromboot.h.nul.ie. - Root on NVMe-oF:
my.nvme.bootconnects tonqn.2016-06.io.spdk:sfhat192.168.68.80(cellar, RDMA) from the initrd (lan-hiup +roceBootModules);/nixand/persistare LVs on that volume.KeepConfiguration=staticonlan-hiprotects the NVMe-oF address from networkd reconfigures. - Frigate footage disk: palace passes the
hdds/frigateLVM LV through as a virtio disk; sfh mounts it at/mnt/frigate(by label) and bind-mounts it into thehasscontainer at/var/lib/frigate. - USB: two host ports are passed to the VM (qemu flags) for the Zigbee coordinator and webcam used
by
hass; the nspawn unit getsDeviceAllowforchar-ttyUSBandchar-video4linux.
Network assignments
| Name | Assignment | IPv4 | IPv6 | Domain | Notes |
|---|---|---|---|---|---|
| sfh | hi | 192.168.68.81/22 gw 192.168.71.254 |
2a0e:97c0:4d0:1::4:2/64 |
h.nul.ie |
Networking
Four NICs, all MTU 9000 where jumbo-capable:
lan-hi— SR-IOV VF 2, the box's ownhiassignment (192.168.68.81).lan-hi-ctrs— SR-IOV VF 3, no L3: the MACVLAN parent for the containers'hilegs (host0inside each container).lan-core-ctrs/lan-lo-ctrs— virtio NICs (bridged to palace'slan-core/lan-lo), no L3: MACVLAN parents for containers that need acoreorloleg.
The per-container MACVLAN wiring lives in systemd.nspawn.*.networkConfig in
sfh/default.nix.
Containers
| Container | Role | Page |
|---|---|---|
hass |
Home Assistant + Frigate + MQTT | sfh/containers/hass.md |
unifi |
UniFi controller | sfh/containers/unifi.md |
Notable config files
nixos/boxes/home/palace/vms/sfh/default.nix— box config: netboot/NVMe-oF boot, container instances, MACVLAN plumbing, Frigate disk.nixos/boxes/home/palace/vms/sfh/containers/— the container system definitions.nixos/boxes/home/palace/vms/default.nix— the VM definition onpalace(VFs, USB passthrough, netboot NIC,hdds/frigatedisk).