!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

893 Members
Declaratively manage your switching, routing, wireless, tunneling and more.261 Servers

Load older messages


SenderMessageTime
30 Jul 2025
@emilazy:matrix.orgemilyyou can use TPM etc. to get a not-easily-extractable host key prior to decryption19:37:54
@emilazy:matrix.orgemily(and that host key can be only accessible if you are booting a trusted kernel/initrd and nothing funny went on with the bootloader)19:38:10
@hexa:lossy.networkhexayes, and an unencrypted ssh hostkey19:38:14
@hexa:lossy.networkhexathe threat modelling on this is pretty clear19:38:24
@emilazy:matrix.orgemilywell, that's the less effective option :D19:38:28
@emilazy:matrix.orgemilybut yes19:38:30
@emilazy:matrix.orgemilywe have had support for this in NixOS for years19:38:39
@hexa:lossy.networkhexaright19:38:41
@denkn:denkn.atDenKnthan you could also install a second system with a full nixos, which will be booted first. than you use containers for the encrypted services.19:39:35
@hexa:lossy.networkhexathe discussion is about bringing parity for network configuration options between the running system and the initrd, no need to question everything from first principles19:41:08
@denkn:denkn.atDenKnyes, than you have only one network config19:48:42
@emilazy:matrix.orgemilythis is initrd except worse19:50:09
@emilazy:matrix.orgemilysince you can easily verify initrd with secure boot/attestation19:50:18
@hexa:lossy.networkhexaor at least the one you are already familiar with19:51:38
@hexa:lossy.networkhexa* or at least the configuration stack one you are already familiar with19:51:47
@denkn:denkn.atDenKnThere are a filesystem/dm-module with no encryption, but with signing?20:12:57
@k900:0upti.meK900There are options, yes20:14:35
@emilazy:matrix.orgemily(with complicated trade-offs)20:16:13
@emilazy:matrix.orgemily(and not ones that are easy to deploy mutable NixOS systems to)20:16:19
@denkn:denkn.atDenKnI do not need encryption, but signing would be interesting in such cases. I only want to mount encrypted data, but mostly the system could be only signed20:18:30
@emilazy:matrix.orgemilydm-verity is used for this in production20:20:33
@emilazy:matrix.orgemilybut is only really suitable for image deploys20:20:37
@emilazy:matrix.orgemilyfs-verity has potential for mutable systems but is complicated to close the gap with20:20:47
@elvishjerricco:matrix.orgElvishJerriccohuh, I can't seem to get networking to work with libvirt anymore...23:58:18
31 Jul 2025
@elvishjerricco:matrix.orgElvishJerriccoIf I set up a VM with virt-manager and just let it do its default network, which should be some NAT thing, it seems like it's just not doing DHCP00:15:10
@elvishjerricco:matrix.orgElvishJerricco great... If I downgrade virtualisation.libvirtd.package to the libvirt from 25.05 it works... 00:34:16
@hexa:lossy.networkhexahttps://media.freifunk.net/v/openwrt-on-realtek-switches20:44:11
@adam:robins.wtfadamcstephensI run a couple gigabit realtek switches on openwrt. They've been stable and without problems 20:52:04
@hexa:lossy.networkhexahow fun is management?20:55:59
@adam:robins.wtfadamcstephensI'm not changing it much. Mostly just updates, which have been problem free. The interfaces for the basic switch setup are mildly awkward, either GUI or config, but they're passable20:57:04

Show newer messages


Back to Room ListRoom Version: 6