summaryrefslogtreecommitdiff
path: root/microvms/lib/default.nix
blob: bdcc07f90a312ca95cb0e8475dbbeba9ce5ca8f6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
{ lib, config, ... }:
{
  options.oxalab.vm.number =
    with lib;
    mkOption {
      type = types.nullOr types.int;
      default = null;
    };

  config =
    let
      vmMac = n:
        assert n >= 0 && n <= 4294967295;
        let
          hex = lib.fixedWidthString 8 "0" (lib.toHexString n);
        in
          "02:00:"
          + "${builtins.substring 0 2 hex}:"
          + "${builtins.substring 2 2 hex}:"
          + "${builtins.substring 4 2 hex}:"
          + "${builtins.substring 6 2 hex}";
    in
      {
        sops.defaultSopsFile = ../${config.networking.hostName}/secrets.yaml;
        sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];

        microvm = {
          hypervisor = "cloud-hypervisor";
          vsock.cid = 3 + config.oxalab.vm.number;
          interfaces =
            [
              {
                type = "tap";
                id = "uvm-${config.networking.hostName}";
                mac = vmMac config.oxalab.vm.number;
              }
            ];
          shares = [
            {
              source = "/nix/store";
              mountPoint = "/nix/.ro-store";
              tag = "store";
              proto = "virtiofs";
              socket = "store.socket";
            }
          ]
          ++
          map
            (dir: {
              source = dir;
              mountPoint = "/${dir}";
              tag = dir;
              proto = "virtiofs";
              socket = "${dir}.socket";
            })
            [
              "etc"
              "var"
              "home"
            ];
        };

        networking.useNetworkd = true;
        networking.firewall.enable = lib.mkForce false; # firewalling done by the host

        systemd.network = {
          enable = true;
          networks."11-host" = {
            matchConfig.MACAddress = vmMac config.oxalab.vm.number;
            networkConfig = {
              Address = "10.99.99." + lib.toString (10 + config.oxalab.vm.number)  + "/24";
              DHCP = "no";
            };
            routes = [
              {
                Gateway = "10.99.99.1";
                Destination = "0.0.0.0/0";
                Metric = 1024;
              }
            ];
          };
        };
      };

}