-
1
-
2
-
3
-
4
-
5
-
6
-
7
-
8
-
9
-
10
-
11
-
12
-
13
-
14
-
15
-
16
-
17
-
18
-
19
-
20
-
21
-
22
-
23
-
24
-
25
-
26
-
27
-
28
-
29
-
30
-
31
-
32
-
33
-
34
-
35
-
36
-
37
-
38
-
39
-
40
-
41
-
42
-
43
-
44
-
45
-
46
-
47
-
48
-
49
-
50
-
51
-
52
-
53
-
54
-
55
-
56
-
57
-
58
-
59
-
60
-
61
-
62
-
63
-
64
-
65
-
66
-
67
-
68
-
69
-
70
-
71
-
72
-
73
-
74
-
75
-
76
-
77
-
78
-
79
-
80
-
81
-
82
-
83
-
84
-
85
-
86
-
87
-
88
-
89
-
90
-
91
-
92
-
93
-
94
-
95
-
96
-
97
-
98
-
99
-
100
-
101
-
102
-
103
-
104
-
105
-
106
-
107
-
108
-
109
-
110
-
111
-
112
-
113
-
114
# Copyright 2025 Shota FUJI <pockawoooh@gmail.com>
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted.
#
# THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
# AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
# OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
#
# SPDX-License-Identifier: 0BSD
#
# Container and VM management.
{ pkgs, ... }: {
config = {
# virtualisation.incus option does not install Incus CLI tools such as
# incus-agent and incus-migrate
environment.systemPackages = [ pkgs.incus ];
virtualisation.incus = {
enable = true;
preseed = {
config = {
"images.auto_update_interval" = "0";
};
networks = [
{
config = {
"ipv4.address" = "10.236.32.1/24";
"ipv4.nat" = "true";
"ipv6.address" = "fd42:d2ea:8018:467a::1/64";
"ipv6.nat" = "true";
};
name = "incusbr0";
type = "bridge";
project = "default";
}
];
storage_pools = [
{
config = {
source = "/var/lib/incus/storage-pools/default";
};
name = "default";
driver = "dir";
}
];
profiles = [
{
description = "Default Incus profile";
devices = {
eth0 = {
name = "eth0";
network = "incusbr0";
type = "nic";
};
root = {
path = "/";
pool = "default";
type = "disk";
};
};
name = "default";
}
];
projects = [
{
config = {
"features.images" = "true";
"features.networks" = "true";
"features.networks.zones" = "true";
"features.profiles" = "true";
"features.storage.buckets" = "true";
"features.storage.volumes" = "true";
};
description = "Default Incus project";
name = "default";
}
];
};
};
networking.nftables.enable = true;
networking.firewall.interfaces.incusbr0 = {
allowedTCPPorts = [
53
67
];
allowedUDPPorts = [
53
67
];
};
services.resolved = {
enable = true;
settings.Resolve = {
DNS = [ "10.236.32.1" ];
Domains = [ "incus" ];
};
};
};
}