Archived
Check NixOS configurations / eval-hosts (push) Successful in 10m31s
Updates mount-pxe-images.nix to mount pxe-boot/images from ha-vip-lan.sweet.home (Pacemaker vip-lan, 192.168.2.229) instead of server.sweet.home. Storage root changes from /tank to haStorageRoot (/srv/ha-data). NFSv3+nolock options for LXC are unchanged. Removes nfsServerHost and storageRoot from variables.nix — all NFS clients now reference the HA cluster directly (docker via haStorageNfsFqdn on VLAN 20, pxe-boot via ha-vip-lan on VLAN 2). Updates the nfsShares comment to reflect the new single-source-of-truth role without the dead server.nix references. DNS records for server.sweet.home and server.storage.home were already cleaned up automatically by IPA dynamic DNS when the VM was deleted. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01J8djTWdXVzXZc99iujU6T2
43 lines
1.7 KiB
Nix
43 lines
1.7 KiB
Nix
{ config, lib, vars, ... }:
|
|
|
|
let
|
|
# FQDN of the LAN NFS VIP (Pacemaker vip-lan, 192.168.2.229). Using the
|
|
# FQDN rather than a raw IP or bare hostname avoids systemd-resolved LLMNR
|
|
# quirks and survives a future VIP renumber via a DNS-only update.
|
|
nfsServer = "ha-vip-lan.${vars.homeDomain}";
|
|
in
|
|
{
|
|
fileSystems.${vars.nfsShares.pxebootImages.mountpoint} = {
|
|
device = "${nfsServer}:${vars.haStorageRoot}/${vars.nfsShares.pxebootImages.subpath}";
|
|
fsType = "nfs";
|
|
options = [
|
|
"_netdev"
|
|
"noatime"
|
|
] ++ (if config.boot.isContainer
|
|
# NFSv4 requires rpc_pipefs (sunrpc filesystem), which Proxmox LXC
|
|
# containers block unless `features: mount=nfs` is set. Use NFSv3+nolock
|
|
# instead: no rpc_pipefs dependency at the protocol level, and rpcbind
|
|
# on the server handles port resolution without needing client-side
|
|
# sunrpc infrastructure. nofail keeps boot clean if server is unreachable.
|
|
then [ "nfsvers=3" "proto=tcp" "nolock" "nofail" ]
|
|
else [ "nfsvers=4.2" "x-systemd.automount" ]);
|
|
};
|
|
|
|
# NixOS pulls var-lib-nfs-rpc_pipefs.mount (the sunrpc filesystem) into
|
|
# nfs-client.target for any nfs fileSystems entry. In LXC containers the
|
|
# sunrpc mount is blocked by Proxmox's AppArmor profile, causing it to fail
|
|
# and the activation to report an error even though our mount uses nofail.
|
|
# Add ConditionVirtualization=!container via drop-in so systemd skips the
|
|
# unit entirely in containers (skip = inactive, not failed), which keeps
|
|
# nfs-client.target green and activation clean.
|
|
systemd.units = lib.mkIf config.boot.isContainer {
|
|
"var-lib-nfs-rpc_pipefs.mount" = {
|
|
overrideStrategy = "asDropin";
|
|
text = ''
|
|
[Unit]
|
|
ConditionVirtualization=!container
|
|
'';
|
|
};
|
|
};
|
|
}
|