{ lib, config, ... }: { options.oxalab.vm.number = with lib; mkOption { type = types.nullOr types.int; default = null; }; config = let vmMac = n: assert n >= 0 && n <= 4294967295; let hex = lib.fixedWidthString 8 "0" (lib.toHexString n); in "02:00:" + "${builtins.substring 0 2 hex}:" + "${builtins.substring 2 2 hex}:" + "${builtins.substring 4 2 hex}:" + "${builtins.substring 6 2 hex}"; in { sops.defaultSopsFile = ../${config.networking.hostName}/secrets.yaml; sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; microvm = { hypervisor = "cloud-hypervisor"; vsock.cid = 3 + config.oxalab.vm.number; interfaces = [ { type = "tap"; id = "uvm-${config.networking.hostName}"; mac = vmMac config.oxalab.vm.number; } ]; shares = [ { source = "/nix/store"; mountPoint = "/nix/.ro-store"; tag = "store"; proto = "virtiofs"; socket = "store.socket"; } ] ++ map (dir: { source = dir; mountPoint = "/${dir}"; tag = dir; proto = "virtiofs"; socket = "${dir}.socket"; }) [ "etc" "var" "home" ]; }; networking.useNetworkd = true; networking.firewall.enable = lib.mkForce false; # firewalling done by the host systemd.network = { enable = true; networks."11-host" = { matchConfig.MACAddress = vmMac config.oxalab.vm.number; networkConfig = { Address = "10.99.99." + lib.toString (10 + config.oxalab.vm.number) + "/24"; DHCP = "no"; }; routes = [ { Gateway = "10.99.99.1"; Destination = "0.0.0.0/0"; Metric = 1024; } ]; }; }; }; }