This repository has been archived on 2026-07-30. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
nixos/docs/ip-addressing.md
T
beatzaplentyandClaude Sonnet 4.6 8d43b7039c
Check NixOS configurations / eval-hosts (push) Successful in 10m39s
feat(ha): add vmbr2 storage-client network and corosync ring1
Infrastructure changes already applied to pve1:
- vmbr2 internal bridge created (192.168.5.0/24, no physical uplink)
- VM 200 (ha-server-1): net2 added → vmbr2 (ens20)
- VM 201 (ha-server-2): net2 added → vmbr2 (ens20)
- CT 105 (docker): net1 added → vmbr2 (eth1)
- VM 101 (server): net1 added → vmbr2 (ens19) — needs reboot to activate

NixOS config (deploy to ha nodes to complete; docker/server at cutover):
- ha-server-{1,2}/host.nix: ens20 with 192.168.5.{228,227}/24
- docker/host.nix: eth1 with 192.168.5.225/24
- server/host.nix: ens19 with 192.168.5.226/24
- cluster-config.nix: corosync ring1 on LAN IPs as backup heartbeat path
- cluster-config.nix: allow haClientCidr (192.168.5.0/24) in iptables
- ha-server.nix: NFS exports now allow both lanCidr and haClientCidr
- VIP moves from 192.168.2.229 (vmbr0/LAN) to 192.168.5.229 (vmbr2)
- iSCSI portal to be rebound from [::0] to 192.168.5.229 at cutover

variables.nix: haStorageCidr corrected to 192.168.4.224/29; new vars:
vmStorageClientInterface, lxcStorageInterface, haServer{1,2}ClientIp,
dockerStorageIp, serverStorageIp, haClientCidr/PrefixLength; haServerVip
updated to 192.168.5.229.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-29 16:02:53 +10:00

7.0 KiB
Raw Blame History

IP Addressing Scheme

Subnets

Subnet CIDR Purpose Routed?
LAN 192.168.2.0/24 General LAN — clients and infrastructure Yes (gateway .254)
Cluster 192.168.4.224/29 HA file server DRBD replication + Corosync heartbeat No — internal vmbr1 only, no uplink
Storage client 192.168.5.0/24 HA file server iSCSI + NFS — docker and server access VIP here No — internal vmbr2 only, no uplink

The cluster and storage-client subnets never leave pve1. vmbr1 and vmbr2 are Proxmox Linux bridges with no physical port attached; traffic between guests on each bridge stays in-kernel.

The host octet is consistent across all subnets — e.g. ha-node1 is always .228: 192.168.2.228 (LAN), 192.168.4.228 (cluster), 192.168.5.228 (storage client).


LAN — 192.168.2.0/24

Address map

Range Purpose
.1.9 Reserved, never assign
.10.59 Client DHCP pool (router-assigned)
.60.219 Unallocated buffer
.220.229 Virtual nodes (VMs / LXC containers)
.230.239 Expansion buffer (reserved, unallocated)
.240.249 Physical nodes (bare-metal hosts)
.250.253 Network services
.254 Router / gateway

Network services (.250.253)

IP Hostname Role
192.168.2.254 router Gateway (TP-Link)
192.168.2.253 domain-controller FreeIPA — authoritative DNS for sweet.home, Kerberos, LDAP
192.168.2.250.252 Reserved for future network services

Physical nodes (.240.249)

IP Hostname Role
192.168.2.245 pve1 Proxmox VE hypervisor
192.168.2.244 pbs Proxmox Backup Server
192.168.2.243 nixos Bare-metal workstation (baremetal-gui)
192.168.2.246.249 Reserved — second Proxmox node and associated services
192.168.2.240.242 Reserved

pve1 sits mid-range deliberately so a second Proxmox node can slot in on either side.

Virtual nodes (.220.229)

All VMs and LXC containers run on pve1.

IP Hostname Role Status
192.168.2.229 Was planned as ha-vip; VIP moved to 192.168.5.229 (vmbr2) Unassigned
192.168.2.228 ha-node1 HA file server node 1 — management NIC Active
192.168.2.227 ha-node2 HA file server node 2 — management NIC Active
192.168.2.226 server Current NFS/ZFS file server — retires when HA is live Retiring
192.168.2.225 docker Docker / Traefik stack Active
192.168.2.224 nix-cache Nix binary cache + remote builder Active
192.168.2.223 pxe-boot PXE / TFTP / HTTP netboot server Active
192.168.2.222 tailscale-router Tailscale exit node / router Active
192.168.2.221 tor-relay Tor relay Active
192.168.2.220 pdm Proxmox Deploy Manager Active

Client DHCP pool (.10.59)

Assigned by the router. DNS option points to 192.168.2.253 (domain-controller).

Devices in this range: phones, laptops, IoT, Canon printer, any non-infrastructure host. No static reservations for infrastructure hosts — all infra uses static IP configuration on the guest itself (not DHCP reservations), so IPs survive VM recreation regardless of MAC address churn.


Cluster network — 192.168.4.224/29

Internal to pve1 only. Proxmox bridge vmbr1, no physical NIC attached.

IP Hostname Interface role
192.168.4.228 ha-node1 DRBD replication + Corosync ring0 (primary heartbeat)
192.168.4.227 ha-node2 DRBD replication + Corosync ring0 (primary heartbeat)
no gateway Isolated — not routed to LAN or internet

Corosync ring1 (backup heartbeat only) uses the LAN IPs (192.168.2.228 / 192.168.2.227) over vmbr0 — no additional bridge needed, and DRBD traffic never crosses ring1.


Storage-client network — 192.168.5.0/24

Internal to pve1 only. Proxmox bridge vmbr2, no physical NIC attached.

IP Hostname Interface / role
192.168.5.229 ha-vip Pacemaker floating VIP — iSCSI portal + NFS endpoint
192.168.5.228 ha-node1 Storage-client NIC (ens20 / vmbr2)
192.168.5.227 ha-node2 Storage-client NIC (ens20 / vmbr2)
192.168.5.226 server Storage-client NIC (ens19 / vmbr2) — for final rsync before cutover
192.168.5.225 docker Storage-client NIC (eth1 / vmbr2) — iSCSI initiator + NFS client
no gateway Isolated — not routed to LAN or internet

iSCSI initiators and NFS clients connect exclusively to the VIP (192.168.5.229) so sessions survive failover transparently. The portal is bound to the VIP only (not [::0]).


Migration reference

Current → target IP for every host being renumbered.

Host Current IP New IP Config location
router 192.168.2.254 192.168.2.254 unchanged
domain-controller 192.168.2.138 192.168.2.253 /etc/sysconfig/network-scripts/ifcfg-eth0 on guest
pve1 192.168.2.250 192.168.2.245 /etc/network/interfaces on Proxmox host
pbs 192.168.2.108 192.168.2.244 static config on PBS host
nixos workstation 192.168.2.119 192.168.2.243 networking.interfaces / NetworkManager on guest
ha-node1 192.168.2.228 (LAN), 192.168.4.228 (cluster), 192.168.5.228 (storage) active
ha-node2 192.168.2.227 (LAN), 192.168.4.227 (cluster), 192.168.5.227 (storage) active
ha-vip 192.168.5.229 (vmbr2 / Pacemaker IPaddr2) active
server 192.168.2.252 192.168.2.226 static config on guest
docker 192.168.2.249 192.168.2.225 static config on guest
nix-cache 192.168.2.120 192.168.2.224 static config on guest
pxe-boot 192.168.2.247 192.168.2.223 static config on guest; update vars.pxeServerIp in variables.nix
tailscale-router 192.168.2.121 192.168.2.222 static config on guest
tor-relay 192.168.2.107 192.168.2.221 static config on guest
pdm 192.168.2.248 192.168.2.220 static config on guest

Cutover notes

  • Do domain-controller first — it becomes the DNS server; everything else depends on it having its new IP and FreeIPA DNS configured before Pi-hole is retired.
  • pve1 last among physical hosts — changing the Proxmox management IP drops the web UI briefly; all guests keep running.
  • Update Pi-hole custom.list / FreeIPA DNS A records to new IPs before flipping any host, so name resolution stays valid throughout the migration.
  • variables.nix already updated for pxeServerIp (.247→.223), pbsIp (.108→.244), and new domainControllerIp (.253). Rebuild affected hosts after renumbering.
  • Router DHCP: once domain-controller is at .253 and FreeIPA DNS is serving sweet.home, switch router DHCP on with pool .10.59 and DNS option pointing to .253; retire Pi-hole CT.
  • Pi-hole's iPXE dnsmasq config (99-ipxe-chainload.conf) moves to the pxe-boot CT as a dnsmasq proxy-mode config before Pi-hole is decommissioned.