Archived
Check NixOS configurations / eval-hosts (pull_request) Successful in 17m29s
The previous commit's networking.search fix was wrong. Confirmed live
on lxc-docker (vmid 105) after redeploying with it: `resolvectl query
server.sweet.home` started failing again, even though
`resolvectl query --interface=eth0 server.sweet.home` still resolved
correctly to the right IP via the LAN's real DNS server. The debug log
showed why -- adding a *global* search domain via networking.search
gave systemd-resolved a domain-matched but server-less "global" scope,
which it now prioritizes over eth0's correctly-configured scope for
every "*.sweet.home" query, silently sending them to public fallback
DNS (1.1.1.1 et al) instead, which of course returns NXDOMAIN for an
internal-only name. Bare single-label names (e.g. "server") were never
going to work either way -- systemd-resolved only ever tries LLMNR for
those, never DNS search-suffixing, regardless of configuration.
Reverts the networking.search addition and instead has
modules/docker/mount-data.nix build each NFS device string from
"${vars.nfsServerHost}.${vars.homeDomain}" (a plain FQDN, no dependency
on search-domain behavior at all) -- the same pattern
modules/raspi/mount-data.nix already uses for the Raspberry Pi's share
and for the identical reason.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T48qgH3VTvs8wvwj44FEbE
85 lines
2.9 KiB
Nix
85 lines
2.9 KiB
Nix
{ config, lib, pkgs, vars, ... }:
|
|
|
|
let
|
|
# `x-systemd.automount` never works inside a Linux container (LXC
|
|
# included, regardless of privilege) -- confirmed live on lxc-docker:
|
|
# systemd logs "Starting of <unit>.automount unsupported" for every
|
|
# share and never mounts them. Mount eagerly there instead, with
|
|
# `nofail` so a boot with the NFS server unreachable doesn't hang
|
|
# (the VM platforms rely on automount itself to get that same
|
|
# non-blocking behavior, so they don't need `nofail` too).
|
|
automountOpts = if config.boot.isContainer then [ "nofail" ] else [ "x-systemd.automount" ];
|
|
|
|
# A bare hostname here never resolves reliably: systemd-resolved only
|
|
# ever tries LLMNR for single-label names (never DNS, regardless of any
|
|
# configured search domain), and a *global* search domain (the first fix
|
|
# attempted here) backfires worse -- confirmed live on lxc-docker, adding
|
|
# `networking.search` made systemd-resolved prioritize its domain-matched
|
|
# but server-less global scope over eth0's correctly-configured one for
|
|
# every "*.sweet.home" query, silently sending them to public fallback
|
|
# DNS instead. `resolvectl query --interface=eth0 server.sweet.home`
|
|
# resolved fine throughout, proving the LAN DNS server was never the
|
|
# problem -- only the ambient, unqualified device string was. Using the
|
|
# FQDN directly sidesteps all of that, matching the pattern
|
|
# ../raspi/mount-data.nix already uses for the same reason.
|
|
nfsServer = "${vars.nfsServerHost}.${vars.homeDomain}";
|
|
in
|
|
{
|
|
fileSystems = {
|
|
${vars.nfsShares.dockerConfig.mountpoint} = {
|
|
device = "${nfsServer}:${vars.storageRoot}/${vars.nfsShares.dockerConfig.subpath}";
|
|
fsType = "nfs";
|
|
|
|
options = [
|
|
"nfsvers=4.2"
|
|
"_netdev"
|
|
"noatime"
|
|
] ++ automountOpts;
|
|
};
|
|
|
|
${vars.nfsShares.dockerDatabases.mountpoint} = {
|
|
device = "${nfsServer}:${vars.storageRoot}/${vars.nfsShares.dockerDatabases.subpath}";
|
|
fsType = "nfs";
|
|
|
|
options = [
|
|
"nfsvers=4.2"
|
|
"_netdev"
|
|
"noatime"
|
|
] ++ automountOpts;
|
|
};
|
|
|
|
${vars.nfsShares.dockerVolumes.mountpoint} = {
|
|
device = "${nfsServer}:${vars.storageRoot}/${vars.nfsShares.dockerVolumes.subpath}";
|
|
fsType = "nfs";
|
|
|
|
options = [
|
|
"nfsvers=4.2"
|
|
"_netdev"
|
|
"noatime"
|
|
] ++ automountOpts;
|
|
};
|
|
|
|
${vars.nfsShares.nextcloudData.mountpoint} = {
|
|
device = "${nfsServer}:${vars.storageRoot}/${vars.nfsShares.nextcloudData.subpath}";
|
|
fsType = "nfs";
|
|
|
|
options = [
|
|
"nfsvers=4.2"
|
|
"_netdev"
|
|
"noatime"
|
|
] ++ automountOpts;
|
|
};
|
|
|
|
${vars.nfsShares.raspiVolumes.mountpoint} = {
|
|
device = "${nfsServer}:${vars.storageRoot}/${vars.nfsShares.raspiVolumes.subpath}";
|
|
fsType = "nfs";
|
|
|
|
options = [
|
|
"nfsvers=4.2"
|
|
"_netdev"
|
|
"noatime"
|
|
] ++ automountOpts;
|
|
};
|
|
};
|
|
}
|