!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

902 Members
Declaratively manage your switching, routing, wireless, tunneling and more.263 Servers

Load older messages


SenderMessageTime
27 Jul 2025
@sodiboo:gaysex.cloudsodiboo joined the room.13:17:46
28 Jul 2025
@emilazy:matrix.orgemilyhttps://github.com/systemd/systemd/commit/5c68c51045c27d77b7afc211df7304a958d8cf2413:32:24
@emilazy:matrix.orgemily🪦13:32:33
@emilazy:matrix.orgemily we should probably kill off some of our iptables detritus 13:34:21
@emilazy:matrix.orgemilythough probably much of it will die with scripted networking already13:34:50
@emilazy:matrix.orgemily wow apparently Docker still does not support nftables 13:35:10
@emilazy:matrix.orgemily

Our initial plan was to include nftables support in v29, but it's not going to make it as the first RC is scheduled for July 10 (although this date might slip). The implementation itself is in good shape, but it needs thorough review before it can be merged and released. We've an Epic open here to track the work left: moby/moby#49634.

13:35:22
@emilazy:matrix.orgemilythankfully they have an Epic13:35:26
@magic_rb:matrix.redalder.orgmagic_rbNo it doesnt, along with "youd be surprised how many things"13:35:35
@emilazy:matrix.orgemilyhopefully it will achieve For the Win status in a timely manner13:35:37
@magic_rb:matrix.redalder.orgmagic_rb
In reply to @emilazy:matrix.org
we should probably kill off some of our iptables detritus
Yes please, lets kill it with fire, its 2025
13:36:01
@emilazy:matrix.orgemilyfrankly the NixOS firewall probably just does not work well with half of them anyway13:36:04
@emilazy:matrix.orgemily but I expect we can kill any remaining iptables nonsense at the same time as scripted networking 13:36:21
@emilazy:matrix.orgemily also it would be real nice to use firewalld or something instead of homegrown stuff for that 13:36:35
@emilazy:matrix.orgemilybut that's another whole project13:36:37
@magic_rb:matrix.redalder.orgmagic_rbId say no firewall works well with them because interoperability at the iptables/nftables level is grossly at the wrong level, but thats another separate rant13:37:02
@molly:matrix.flyingcircus.ioMolly Millergetting docker to work with scripted networking and iptables is a bit painful but doable13:38:20
@molly:matrix.flyingcircus.ioMolly Miller(ask me how i know, etc etc)13:38:30
@magic_rb:matrix.redalder.orgmagic_rbI personally gave up, i put k3s (containerd) into a separate network namespace and do the firewalling on the outside13:39:17
@marcel:envs.netMarcelIfstate is not in the release phase for V2 so I am preparing to upstream the nix module to nixpkgs. The question is if the options should be under networking.ifstate or services.ifstate or somewhere different? That's hot it's currently done in my flake: https://search.nüschtos.de/?scope=IfState.nix16:01:33
@marcel:envs.netMarcel * 16:01:58
@marcel:envs.netMarcel * 16:02:08
@marcel:envs.netMarcel * 16:02:33
@marcel:envs.netMarcel *

Ifstate is now in the release candidate phase for V2 so I am preparing to upstream the nix module to nixpkgs. The question is if the options should be under networking.ifstate or services.ifstate or somewhere different? That's how it's currently done in my flake: https://search.nüschtos.de/?scope=IfState.nix

Services.ifstate might not be optimal because it's not a daemon and only runs on boot or rebuild

16:03:46
@adam:robins.wtfadamcstephens networking.ifstate seems reasonable to me 16:06:06
@zhaofeng:zhaofeng.liZhaofeng Liinteresting, what's your setup like? I might do something similar, but for the wrong reasons :p16:13:06
@zhaofeng:zhaofeng.liZhaofeng Li(launch k3s from k8s)16:13:19
@magic_rb:matrix.redalder.orgmagic_rb
In reply to @zhaofeng:zhaofeng.li
interesting, what's your setup like? I might do something similar, but for the wrong reasons :p
uh, i use systemd-nspawn with some convincing and i wrote a simple k3s module for NixNG
16:17:21
@magic_rb:matrix.redalder.orgmagic_rb https://git.sr.ht/~magic_rb/uk3s.nix/tree/master/item/nixos/modules these modules 16:17:52
@magic_rb:matrix.redalder.orgmagic_rb https://git.sr.ht/~magic_rb/uk3s.nix/tree/master/item/nixos/modules/uk3s.nix#L341 this specifically is what you need to run k3s in a nspawn container 16:18:40

Show newer messages


Back to Room ListRoom Version: 6