From f8719437ba260742e54bcc515672534ae5e098a0 Mon Sep 17 00:00:00 2001 From: beatzaplenty Date: Sat, 25 Jul 2026 15:59:07 +1000 Subject: [PATCH] fix(nix-cache): use FQDN to fix hostname resolution on clients MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit systemd-resolved only uses LLMNR for single-label hostnames, never DNS — same issue mount-data.nix already documented and fixed for NFS by switching to server.sweet.home. Change the substituter URL, SSH knownHosts, and remote-builder hostName from bare "nix-cache" to "nix-cache.sweet.home", and update nginx's virtualHost to match. Co-Authored-By: Claude Sonnet 4.6 --- modules/nix-cache/client.nix | 2 +- modules/nix-cache/remote-builder-client.nix | 8 ++++---- modules/nix-cache/server.nix | 2 +- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/modules/nix-cache/client.nix b/modules/nix-cache/client.nix index a1b2009..54cd08b 100644 --- a/modules/nix-cache/client.nix +++ b/modules/nix-cache/client.nix @@ -3,7 +3,7 @@ { nix.settings = { substituters = [ - "http://${vars.nixCacheHost}" + "http://${vars.nixCacheHost}.${vars.homeDomain}" "https://cache.nixos.org/" ]; trusted-public-keys = [ diff --git a/modules/nix-cache/remote-builder-client.nix b/modules/nix-cache/remote-builder-client.nix index e705c74..c4b6f9c 100644 --- a/modules/nix-cache/remote-builder-client.nix +++ b/modules/nix-cache/remote-builder-client.nix @@ -8,12 +8,12 @@ # dedicated keypair). If this host doesn't have one yet: # sudo -u root ssh-keygen -t ed25519 -N '' -f /root/.ssh/id_ed25519 # # then add its .pub to vars.remoteBuilderAuthorizedKeys and rebuild nix-cache - # sudo ssh -i /root/.ssh/id_ed25519 nixremote@nix-cache nix-store --version + # sudo ssh -i /root/.ssh/id_ed25519 nixremote@nix-cache.sweet.home nix-store --version # Trust nix-cache's SSH host key declaratively so the nix-daemon (root) # can connect the first time without a manual ssh-keyscan/known_hosts # step on every new client. - programs.ssh.knownHosts.${vars.nixCacheHost} = { - hostNames = [ vars.nixCacheHost ]; + programs.ssh.knownHosts."${vars.nixCacheHost}.${vars.homeDomain}" = { + hostNames = [ "${vars.nixCacheHost}.${vars.homeDomain}" ]; publicKey = vars.nixCacheHostKey; }; @@ -22,7 +22,7 @@ buildMachines = [ { - hostName = vars.nixCacheHost; + hostName = "${vars.nixCacheHost}.${vars.homeDomain}"; sshUser = vars.remoteBuilderUser; sshKey = "/root/.ssh/id_ed25519"; inherit (pkgs.stdenv.hostPlatform) system; diff --git a/modules/nix-cache/server.nix b/modules/nix-cache/server.nix index cd9c716..6c72b40 100644 --- a/modules/nix-cache/server.nix +++ b/modules/nix-cache/server.nix @@ -20,7 +20,7 @@ nginx = { enable = true; recommendedProxySettings = true; - virtualHosts.${vars.nixCacheHost} = { + virtualHosts."${vars.nixCacheHost}.${vars.homeDomain}" = { locations."/" = { proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}"; };