main
 1{ lib, ... }:
 2{
 3  # Disko declarative partitioning for Scaleway (DEV1-* local SSD)
 4  # Verify the disk device with `lsblk` on the temporary Ubuntu before running
 5  # nixos-anywhere: local `l_ssd` volumes show up as /dev/vda, block storage
 6  # (`sbs_volume`, used by PLAY2/PRO2/POP2) as /dev/sda.
 7  disko.devices = {
 8    disk = {
 9      main = {
10        device = "/dev/vda";
11        type = "disk";
12        content = {
13          type = "gpt";
14          partitions = {
15            boot = {
16              size = "1M";
17              type = "EF02"; # BIOS boot partition for GRUB
18            };
19            root = {
20              size = "100%";
21              content = {
22                type = "filesystem";
23                format = "ext4";
24                mountpoint = "/";
25                mountOptions = [
26                  "defaults"
27                  "noatime"
28                ];
29              };
30            };
31          };
32        };
33      };
34    };
35  };
36
37  swapDevices = [
38    {
39      device = "/swapfile";
40      size = 4096; # 2x RAM — the VPS only has 2GB
41    }
42  ];
43
44  # Dedibox VPS networking is STATIC — there is no DHCP server on this segment.
45  # Values taken from the Debian rescue install (`ip -br a`, `ip r`, `ip -6 r`).
46  # Interface names are pinned to eth0 (unpredictable naming) so the static
47  # config below cannot break on a kernel/udev rename.
48  networking = {
49    useDHCP = false;
50    usePredictableInterfaceNames = lib.mkForce false;
51
52    interfaces.eth0 = {
53      ipv4.addresses = [
54        {
55          address = "64.31.63.130";
56          prefixLength = 24;
57        }
58      ];
59    };
60
61    defaultGateway = {
62      address = "64.31.63.1";
63      interface = "eth0";
64    };
65
66    # IPv6 is autoconfigured from router advertisements (SLAAC), yielding the
67    # stable EUI-64 address 2a11:840:72:1b:216:3eff:fea8:6cf3 in
68    # 2a11:840:72:1b::/64. Deliberately not pinned: the v6 gateway is the
69    # provider router's link-local address, which is theirs to change.
70
71    nameservers = [
72      "1.1.1.1"
73      "8.8.8.8"
74    ];
75  };
76
77  # Keep honouring RAs even if IP forwarding is enabled later (accept_ra=1 is
78  # ignored once a host forwards; 2 keeps SLAAC working).
79  boot.kernel.sysctl."net.ipv6.conf.eth0.accept_ra" = 2;
80}