Merge pull request 'fix(server): open mountd port 20048 so NFS clients can scan and mount' (#74) from worktree-fix-nfs-mountd-firewall into main

Reviewed-on: #74
This commit is contained in:
2026-07-26 17:57:40 +00:00
2 changed files with 11 additions and 3 deletions
+5 -1
View File
@@ -88,5 +88,9 @@ in
''; '';
}; };
networking.firewall.allowedTCPPorts = [ vars.ports.nfsRpcbind vars.ports.nfsd ]; # mountd (20048) is needed for showmount/NFSv3 mount protocol — without it
# clients can reach portmapper (111) and get the mountd port back, then
# time out trying to connect to it. All three ports need TCP and UDP.
networking.firewall.allowedTCPPorts = [ vars.ports.nfsRpcbind vars.ports.nfsd vars.ports.nfsMountd ];
networking.firewall.allowedUDPPorts = [ vars.ports.nfsRpcbind vars.ports.nfsd vars.ports.nfsMountd ];
} }
+6 -2
View File
@@ -137,10 +137,14 @@
# (modules/build-types/pxe-boot.nix). # (modules/build-types/pxe-boot.nix).
pxeBootTftp = 69; pxeBootTftp = 69;
# `server`'s NFS exports need both the portmapper (rpcbind) and the # `server`'s NFS exports: portmapper (rpcbind), NFS data, and the
# NFS data port itself opened (modules/build-types/server.nix). # mountd RPC service (used by showmount/NFSv3 mount protocol).
# Mountd listens on a fixed port so the firewall can whitelist it
# explicitly rather than opening all of rpcbind's dynamic range.
# All three need both TCP and UDP (modules/build-types/server.nix).
nfsRpcbind = 111; nfsRpcbind = 111;
nfsd = 2049; nfsd = 2049;
nfsMountd = 20048;
# Opened on the docker host's firewall for the Traefik-fronted # Opened on the docker host's firewall for the Traefik-fronted
# container stack (docker-compose config lives in the separate # container stack (docker-compose config lives in the separate