Server Network — Centralized Subnets and Firewall
Purpose
The network module coordinates network subnet definitions and firewall rules, allowing for centralized configuration of subnets and automatic propagation of these settings to other servers in the cluster.
Entry Point
- Main file:
modules/nixos/server/network.nix
Options
server.network.openPortsForSubnet.tcp
| Type | list of 16 bit unsigned integer; between 0 and 65535 (both inclusive) |
| Default | [ ] |
List of TCP ports to open on the firewall for each subnet.
server.network.openPortsForSubnet.udp
| Type | list of 16 bit unsigned integer; between 0 and 65535 (both inclusive) |
| Default | [ ] |
List of UDP ports to open on the firewall for each subnet.
server.network.subnets
| Type | list of (submodule) |
| Default | { } |
This option has no description.
server.network.subnets.*.dns
| Type | string |
DNS server for the subnet.
server.network.subnets.*.domain
| Type | string |
Domain name for the subnet.
server.network.subnets.*.ipv4
| Type | submodule |
| Default | { } |
IPv4 configuration for the subnet.
server.network.subnets.*.ipv4.arpa
| Type | null or string |
| Default | null |
ARPA notation for reverse DNS lookups.
server.network.subnets.*.ipv4.cidr
| Type | null or string |
| Default | null |
CIDR notation for the IP range.
server.network.subnets.*.ipv6
| Type | submodule |
| Default | { } |
IPv6 configuration for the subnet.
server.network.subnets.*.ipv6.arpa
| Type | null or string |
| Default | null |
ARPA notation for reverse DNS lookups.
server.network.subnets.*.ipv6.cidr
| Type | null or string |
| Default | null |
CIDR notation for the IP range.
Architecture / Services / Scope
- This module uses
getIOPrimaryHostAttrto fetch theserver.network.subnetsconfiguration from the IO Coordinator (server.ioPrimaryHost), ensuring all servers in the cluster are aware of the network structure defined there. - The module automatically generates
iptablesandip6tablesrules for the specified ports, allowing traffic only from the defined subnets. - These rules are added to the
nixos-fwchain and are managed through thenetworking.firewall.extraCommandsandnetworking.firewall.extraStopCommandsoptions.
Operational Notes / Assumptions
- Subnets and per-subnet open ports are declared on the IO Coordinator via
server.network.subnetsandserver.network.openPortsForSubnet.