|
2 | 2 | { config, lib, pkgs, ... }: |
3 | 3 | let |
4 | 4 | qemuPkg = config.services.vmrunner.qemuPackage or pkgs.qemu; |
| 5 | + vmrunnerPkg = config.services.vmrunner.package or (pkgs.callPackage ./default.nix { }); |
| 6 | + |
5 | 7 | qemuBridgeHelperPath = "/run/wrappers/bin/qemu-bridge-helper"; |
| 8 | + bridge = "bridge43"; |
6 | 9 | in |
7 | | -{ |
| 10 | + { |
8 | 11 | options.services.vmrunner.qemuPackage = lib.mkOption { |
9 | 12 | type = lib.types.package; |
10 | 13 | default = pkgs.qemu; |
11 | 14 | description = "QEMU with capabilities enabled for IncludeOS unikernels"; |
12 | 15 | }; |
13 | 16 |
|
14 | | - config.security.wrappers = { |
15 | | - # https://wiki.qemu.org/Features/HelperNetworking |
16 | | - qemu-bridge-helper = { |
17 | | - source = "${qemuPkg}/libexec/qemu-bridge-helper"; |
18 | | - owner = "root"; |
19 | | - group = "root"; |
20 | | - capabilities = "cap_net_admin+ep"; # required for attaching TAP devices to bridges |
21 | | - }; |
| 17 | + config = { |
| 18 | + security.wrappers = { |
| 19 | + # https://wiki.qemu.org/Features/HelperNetworking |
| 20 | + qemu-bridge-helper = { |
| 21 | + source = "${qemuPkg}/libexec/qemu-bridge-helper"; |
| 22 | + owner = "root"; |
| 23 | + group = "root"; |
| 24 | + capabilities = "cap_net_admin+ep"; # required for attaching TAP devices to bridges |
| 25 | + }; |
22 | 26 |
|
23 | | - ping = { |
24 | | - source = "${pkgs.iputils}/bin/ping"; |
25 | | - owner = "root"; |
26 | | - group = "root"; |
27 | | - capabilities = "cap_net_raw+ep"; # required to send ICMP packets |
| 27 | + ping = { |
| 28 | + source = "${pkgs.iputils}/bin/ping"; |
| 29 | + owner = "root"; |
| 30 | + group = "root"; |
| 31 | + capabilities = "cap_net_raw+ep"; # required to send ICMP packets |
| 32 | + }; |
28 | 33 | }; |
29 | | - }; |
30 | 34 |
|
31 | | - config.environment.etc."qemu/bridge.conf".text = '' |
32 | | - allow bridge43 |
33 | | - ''; |
| 35 | + environment = { |
| 36 | + etc."qemu/bridge.conf".text = '' |
| 37 | + allow ${bridge} |
| 38 | + ''; |
34 | 39 |
|
35 | | - config.networking.firewall = { |
36 | | - trustedInterfaces = [ "bridge43" ]; |
37 | | - }; |
| 40 | + systemPackages = [ vmrunnerPkg ]; |
38 | 41 |
|
39 | | - config.environment.variables.QEMU_BRIDGE_HELPER = qemuBridgeHelperPath; |
| 42 | + variables.QEMU_BRIDGE_HELPER = qemuBridgeHelperPath; |
| 43 | + }; |
| 44 | + |
| 45 | + networking.firewall = { |
| 46 | + trustedInterfaces = [ bridge ]; |
| 47 | + }; |
| 48 | + }; |
40 | 49 | } |
41 | 50 |
|
0 commit comments