Previous history: -c359054daku working! -8de5cfffix integer overflow in vmix network lib -9c25a66daku on 25.05. with ollama -385a3bfvmix enables relaxed sandbox -c363da1restructure vmixLib into linux/windows subattrs with OS-specific customizeImage -edd4dc2vmix: port namespace model and module improvements from conf.nix -6666ecfvmix: add SPICE support, install virtio guest tools with SPICE agent -46f5671vmix: add QEMU guest agent channel for Windows VMs -e1fea34vmix: add Win11 LTSC 2024 image, refactor VirtIO driver selection -c27ae68vmix: make customizeImage chroot-sandboxed by default, opt-in impure -305fbacvirt customize needs chroot for now due to usr bin env things. could be fixed later -264d30fvmix: add win10 VM on desk, disable SMB signing for guest Samba access -9b64f51vmix: split Windows templates into per-category files, add comprehensive debloat -ef91bf8vmix: fix missing parent registry keys in Windows templates -f87f340win10 VM on panda with AMD GPU + USB passthrough -38e474fvmix: split Windows build into Audit Mode install + composable templates -a6a8db3vmix: win11 support, remove build VNC, switch VMs to SPICE -6cf5a21generalize stage sets bg color, accent color and sets visual effects to performance -a84849fremove rdp template since it doesn't even work -5245263vmix: best performance template + generalize cleanup -ab12dd3vmix: use CopyProfile for best performance visual effects -bce3326vmix: CopyProfile for best performance visual effects -2496107vmix: add app templates (7zip, VLC, ImageGlass, Edge WebView, VC++ runtimes) -29a6123wip: debug default associations xml -2a2e5f5vmix: fix DefaultAssociations.xml cmd.exe escaping -cc6ff9dvmix: move DefaultAssociations.xml to template only -a4a78ecvmix: add removeWMP template to remove Windows Media Player -3fe56devmix: improved Edge removal (files, shortcuts, scheduled tasks) -a491767vmix: fully remove Edge via post-oobe AppxPackage removal -6ca1619vmix: remove Edge DevToolsClient SystemApps + AppxPackage -0c1ec35vmix: sandboxie windows app template -628bbd2vmix: add Sandboxie-Plus template -f055a41vmix: reorganize templates, add file associations, remove Paint -34326f4vmix: set Thorium as default browser via PS-SFTA in post-oobe -86af258vmix: Active Setup for default browser (all users, no post-oobe needed) -35b8cb0remove vnc display from thorium template -c7e0af6vmix: fix Win11 generalize timeout + UCPD disable for URL associations -43a1345vmix: add Office 2024 template + Ohook activation in generalize -03bbce0vmix: updated office installation xml. more privacy options enabled -790a0eevmix: thorium installation - hide SFTA window -a0e5c18vmix: fix office install.bat call + add privacy registry policies -3df38cavmix: fix Ohook activation + suppress Office theme dialog -df39ba3vmix: remove sandboxie shortcut from desktop -50d5972vmix: skip Sandboxie desktop shortcut via installer flag -ee2fa0fvmix: fix win10 default browser -938315bvmix: windows: set accent color to automatic. remove accent color from unnecessary elements -beceda8vmix: allow ISO-only VMs without OS disk, add WinPE VM to panda Flake outputs: overlays.default, nixosModules.default, lib, apps.toDisk Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
137 lines
4.3 KiB
Nix
137 lines
4.3 KiB
Nix
{ lib, vmixLib, ... }:
|
|
with lib;
|
|
with vmixLib.network;
|
|
{
|
|
macvtaps = mkOption {
|
|
description = "Macvtap network definitions available to VMs in this namespace.";
|
|
type = types.attrsOf (types.submodule {
|
|
options = {
|
|
uplink.iface = mkOption {
|
|
type = types.str;
|
|
description = "Host interface name to attach the macvtap device to.";
|
|
};
|
|
|
|
uplink.namespace = mkOption {
|
|
type = types.nullOr types.str;
|
|
default = null;
|
|
description = "Optional network namespace where the uplink interface exists. Null means the host namespace.";
|
|
};
|
|
};
|
|
});
|
|
};
|
|
|
|
wan = {
|
|
enable = mkOption {
|
|
type = types.bool;
|
|
default = true;
|
|
description = "Enable forwarding traffic to and from the namespace to the rest of the networks on the host including the internet. (iptables FORWARD chain on the host)";
|
|
};
|
|
|
|
masquerade = mkOption {
|
|
type = types.bool;
|
|
default = true;
|
|
description = "Masquerade outgoing traffic using host's IP";
|
|
};
|
|
|
|
host.reachable = mkOption {
|
|
type = types.bool;
|
|
default = true;
|
|
description = "Allow talking to the host itself from the namespace and VMs on the lan (iptables INPUT chain on the host)";
|
|
};
|
|
|
|
host.addNSLansRoutes = mkOption {
|
|
type = types.bool;
|
|
default = true;
|
|
description = "add routes to the LAN on host so the vms are reachable from the host";
|
|
};
|
|
|
|
# host.dns.addNSLansResolver = mkOption {
|
|
# type = types.bool;
|
|
# default = true;
|
|
# };
|
|
|
|
dns.resolver.enable = mkOption {
|
|
type = types.bool;
|
|
default = true;
|
|
description = "Add dnsmasq's built in resolver to lan clients DHCP responses";
|
|
};
|
|
dns.resolver.useHostResolvConf = mkOption {
|
|
type = types.bool;
|
|
default = false;
|
|
description = "Use host's resolvconf for upstreaming dns queries";
|
|
};
|
|
|
|
dns.resolver.upstream = mkOption {
|
|
type = types.listOf (types.strMatching regex.ipv4);
|
|
default = [];
|
|
description = "Upstream DNS servers for dnsmasq's built in resolver";
|
|
};
|
|
|
|
forwardPorts = mkOption {
|
|
type = types.attrsOf types.int;
|
|
default = {};
|
|
description = "Map host TCP port to namespace destination TCP port.";
|
|
};
|
|
};
|
|
|
|
lans = mkOption {
|
|
description = "Layer-2 LAN bridge networks and DHCP settings for the namespace.";
|
|
type = types.attrsOf (types.submodule {
|
|
options.domain = mkOption {
|
|
type = types.nullOr types.str;
|
|
default = null;
|
|
description = "Domain name for the hosts of this lan.";
|
|
};
|
|
|
|
options.ipv4 = {
|
|
range = mkOption {
|
|
type = types.strMatching regex.cidr4;
|
|
description = "IPv4 Range in x.x.x.x/y format to be assigned to the network.";
|
|
};
|
|
|
|
address = mkOption {
|
|
type = types.nullOr (types.strMatching regex.ipv4);
|
|
default = null;
|
|
description = "IPv4 address to attach to the bridge interface of this Lan.";
|
|
};
|
|
|
|
dhcp.enable = mkOption {
|
|
type = types.bool;
|
|
default = true;
|
|
description = "Whether to start a DHCP server within this network.";
|
|
};
|
|
|
|
dhcp.startAddress = mkOption {
|
|
type = types.nullOr (types.strMatching regex.ipv4);
|
|
description = "Starting IP Address for DHCP clients.";
|
|
default = null;
|
|
};
|
|
|
|
dhcp.endAddress = mkOption {
|
|
type = types.nullOr (types.strMatching regex.ipv4);
|
|
description = "Ending IP Address for DHCP clients.";
|
|
default = null;
|
|
};
|
|
|
|
dhcp.dns.addresses = mkOption {
|
|
type = types.nullOr (types.listOf (types.strMatching regex.ipv4));
|
|
description = "List of IP Addresses to pass as DNS servers in the DHCP response. These servers are only passed if dnsmasq's built in resolver is not enabled via wan.dns.resolver.enable";
|
|
};
|
|
|
|
dhcp.statics = mkOption {
|
|
description = "Static IP leases for mac addresses";
|
|
type = types.attrsOf (types.strMatching regex.ipv4);
|
|
default = {};
|
|
};
|
|
};
|
|
});
|
|
};
|
|
|
|
# routes.internal.add = mkOption {
|
|
# description = "Additional routes to add on the internal network";
|
|
# };
|
|
|
|
# routes.host.add = mkOption {
|
|
# description = "Addtional routes to add on the host's network namespace";
|
|
# };
|
|
}
|