summaryrefslogtreecommitdiff
path: root/microvms/immich/default.nix
diff options
context:
space:
mode:
Diffstat (limited to 'microvms/immich/default.nix')
-rw-r--r--microvms/immich/default.nix78
1 files changed, 78 insertions, 0 deletions
diff --git a/microvms/immich/default.nix b/microvms/immich/default.nix
new file mode 100644
index 0000000..9e635d9
--- /dev/null
+++ b/microvms/immich/default.nix
@@ -0,0 +1,78 @@
+{ config, lib, ... }:
+let
+ mac = "02:00:00:00:00:03";
+in
+{
+ imports = [
+ ./immich.nix
+ ];
+ sops.defaultSopsFile = ./secrets.yaml;
+ sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
+
+ sops.secrets = {
+ "wg/0xa-proxy" = {
+ owner = config.users.users.systemd-network.name;
+ };
+ };
+
+ microvm = {
+ hypervisor = "cloud-hypervisor";
+ vsock.cid = 3 + 3;
+ mem = 3 * 1024;
+ vcpu = 2;
+ interfaces = [
+ {
+ type = "tap";
+ id = "uvm-immich";
+ mac = mac;
+ }
+ ];
+ shares = [
+ {
+ source = "/nix/store";
+ mountPoint = "/nix/.ro-store";
+ tag = "store";
+ proto = "virtiofs";
+ socket = "store.socket";
+ }
+ ]
+ ++
+ map
+ (dir: {
+ source = dir;
+ mountPoint = "/${dir}";
+ tag = dir;
+ proto = "virtiofs";
+ socket = "${dir}.socket";
+ })
+ [
+ "etc"
+ "var"
+ "home"
+ ];
+ };
+
+ networking.useNetworkd = true;
+ networking.firewall.enable = lib.mkForce false; # firewalling done by the host
+
+ systemd.network = {
+ enable = true;
+ networks."11-host" = {
+ matchConfig.MACAddress = mac;
+ networkConfig = {
+ Address = "10.99.99.13/24";
+ DHCP = "no";
+ };
+ routes = [
+ {
+ Gateway = "10.99.99.1";
+ Destination = "0.0.0.0/0";
+ Metric = 1024;
+ }
+ ];
+ };
+ };
+
+ networking.hostName = "immich";
+ system.stateVersion = "24.11";
+}