33 lines
1.4 KiB
Nix
33 lines
1.4 KiB
Nix
{lib, ...}: {
|
|
imports = [
|
|
#./baserow.nix
|
|
./atrocore.nix
|
|
./excalidraw.nix
|
|
./kestra.nix
|
|
./n8n-sandbox.nix
|
|
./online3dviewer.nix
|
|
./semaphore.nix
|
|
./stirling-pdf.nix
|
|
];
|
|
system.activationScripts.createPodmanNetworkWeb = lib.mkAfter ''
|
|
if ! /run/current-system/sw/bin/podman network exists web; then
|
|
/run/current-system/sw/bin/podman network create web --subnet=10.89.0.0/24 --internal
|
|
fi
|
|
if ! /run/current-system/sw/bin/podman network exists web-dev; then
|
|
/run/current-system/sw/bin/podman network create web-dev --subnet=10.89.1.0/24 --internal
|
|
fi
|
|
# Routed egress network: unlike web/web-dev (isolated), netavark sets up
|
|
# a default gateway plus NAT/masquerade for attached containers —
|
|
# outbound via host, incl. the NetBird overlay (wt0, 100.91.0.0/16).
|
|
if ! /run/current-system/sw/bin/podman network exists vpn-egress; then
|
|
/run/current-system/sw/bin/podman network create vpn-egress --subnet=10.89.9.0/24
|
|
fi
|
|
# n8n AI-Assistant sandbox stack (n8n-sandbox.nix): routed, NOT --internal
|
|
# — the privileged DinD runner must pull its sandbox images from ghcr.io.
|
|
# DNS between sandbox-api/sandbox-runner-1 via netavark/aardvark.
|
|
if ! /run/current-system/sw/bin/podman network exists n8n-sandbox; then
|
|
/run/current-system/sw/bin/podman network create n8n-sandbox --subnet=10.89.10.0/24
|
|
fi
|
|
'';
|
|
}
|