chore: update persist immich containers, add nix-ld on kroma, disable

STT until jaxlib is fixed
This commit is contained in:
oddlama 2024-07-02 14:49:46 +02:00
parent 09c4531854
commit fe75b5b78c
No known key found for this signature in database
GPG key ID: 14EFE510775FE39A
7 changed files with 45 additions and 41 deletions

View file

@ -105,5 +105,6 @@
}
];
programs.nix-ld.enable = true;
topology.self.icon = "devices.desktop";
}

View file

@ -149,6 +149,13 @@ in {
# Forwarding required to masquerade podman network
boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
environment.persistence."/state".directories = [
{
directory = "/var/lib/containers";
mode = "0755";
}
];
# Mirror the original oauth2 secret
age.secrets.immich-oauth2-client-secret = {
inherit (nodes.ward-kanidm.config.age.secrets.kanidm-oauth2-immich) rekeyFile;

View file

@ -112,7 +112,6 @@
};
dhcpPrefixDelegationConfig.UplinkInterface = "wan";
dhcpPrefixDelegationConfig.Token = "::ff";
ipv6SendRAConfig.Managed = true;
# Announce a static prefix
ipv6Prefixes = [
{Prefix = globals.net.home-lan.cidrv6;}
@ -122,10 +121,12 @@
SubnetId = "22";
};
# Provide a DNS resolver
ipv6SendRAConfig = {
EmitDNS = true;
DNS = globals.net.home-lan.hosts.ward-adguardhome.ipv6;
};
# ipv6SendRAConfig = {
# Managed = true;
# EmitDNS = true;
# FIXME: this is not the true ipv6 of adguardhome DNS = globals.net.home-lan.hosts.ward-adguardhome.ipv6;
# FIXME: todo assign static additional to reservation in kea
# };
linkConfig.RequiredForOnline = "routable";
};
# Remaining macvtap interfaces should not be touched.