!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

881 Members
on your Router! Declaratively manage your switching, routing, wireless, tunneling and more.259 Servers

Load older messages


SenderMessageTime
30 Jul 2025
@emilazy:matrix.orgemily(and that host key can be only accessible if you are booting a trusted kernel/initrd and nothing funny went on with the bootloader)19:38:10
@hexa:lossy.networkhexayes, and an unencrypted ssh hostkey19:38:14
@hexa:lossy.networkhexathe threat modelling on this is pretty clear19:38:24
@emilazy:matrix.orgemilywell, that's the less effective option :D19:38:28
@emilazy:matrix.orgemilybut yes19:38:30
@emilazy:matrix.orgemilywe have had support for this in NixOS for years19:38:39
@hexa:lossy.networkhexaright19:38:41
@denkn:denkn.atDenKnthan you could also install a second system with a full nixos, which will be booted first. than you use containers for the encrypted services.19:39:35
@hexa:lossy.networkhexathe discussion is about bringing parity for network configuration options between the running system and the initrd, no need to question everything from first principles19:41:08
@denkn:denkn.atDenKnyes, than you have only one network config19:48:42
@emilazy:matrix.orgemilythis is initrd except worse19:50:09
@emilazy:matrix.orgemilysince you can easily verify initrd with secure boot/attestation19:50:18
@hexa:lossy.networkhexaor at least the one you are already familiar with19:51:38
@hexa:lossy.networkhexa* or at least the configuration stack one you are already familiar with19:51:47
@denkn:denkn.atDenKnThere are a filesystem/dm-module with no encryption, but with signing?20:12:57
@k900:0upti.meK900There are options, yes20:14:35
@emilazy:matrix.orgemily(with complicated trade-offs)20:16:13
@emilazy:matrix.orgemily(and not ones that are easy to deploy mutable NixOS systems to)20:16:19
@denkn:denkn.atDenKnI do not need encryption, but signing would be interesting in such cases. I only want to mount encrypted data, but mostly the system could be only signed20:18:30
@emilazy:matrix.orgemilydm-verity is used for this in production20:20:33
@emilazy:matrix.orgemilybut is only really suitable for image deploys20:20:37
@emilazy:matrix.orgemilyfs-verity has potential for mutable systems but is complicated to close the gap with20:20:47
@elvishjerricco:matrix.orgElvishJerriccohuh, I can't seem to get networking to work with libvirt anymore...23:58:18
31 Jul 2025
@elvishjerricco:matrix.orgElvishJerriccoIf I set up a VM with virt-manager and just let it do its default network, which should be some NAT thing, it seems like it's just not doing DHCP00:15:10
@elvishjerricco:matrix.orgElvishJerricco great... If I downgrade virtualisation.libvirtd.package to the libvirt from 25.05 it works... 00:34:16
@hexa:lossy.networkhexahttps://media.freifunk.net/v/openwrt-on-realtek-switches20:44:11
@adam:robins.wtfadamcstephensI run a couple gigabit realtek switches on openwrt. They've been stable and without problems 20:52:04
@hexa:lossy.networkhexahow fun is management?20:55:59
@adam:robins.wtfadamcstephensI'm not changing it much. Mostly just updates, which have been problem free. The interfaces for the basic switch setup are mildly awkward, either GUI or config, but they're passable20:57:04
@adam:robins.wtfadamcstephensIt would be nice to get one with 8x10GB SFP ports and maybe 24x2.5G, to replace my core switch, but I haven't seen one that meets that. And I really don't have any 2.5G yet, so no rush.20:58:55

Show newer messages


Back to Room ListRoom Version: 6