{ self, inputs, ... }: { flake.nixosModules.robinConfiguration = { pkgs, config, ... }: { imports = [ self.nixosModules.robinHardware self.nixosModules.nest self.nixosModules.git self.nixosModules.zsh ]; environment.systemPackages = with pkgs; [ kubectl htop zip unzip dig traceroute neovim wget openiscsi # Required for longhorn nfs-utils ]; networking.networkmanager.enable = true; networking.hostName = "robin"; services = { openssh.enable = true; openiscsi.enable = true; openiscsi.name = "iqn.2005-10.nixos:${config.networking.hostName}"; envfs.enable = true; }; users.users."nest".openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKitQh7D9pKVECI4+fxr5M1gRzdCbEsrISWeiK4LJ7wd nest@mynest.love" ]; # Enable K3s in Agent Mode services.k3s = { enable = true; role = "agent"; package = pkgs.k3s_1_36; serverAddr = "https://192.168.1.122:6443"; tokenFile = "/var/lib/rancher/k3s/join-token"; }; # Fix non-FHS paths for longhorn # This creates persistent symlinks where Longhorn expects to find them. systemd.tmpfiles.rules = [ # Core mount utilities (provide both /bin and /usr/bin paths) "L+ /bin/mount - - - - /run/current-system/sw/bin/mount" "L+ /usr/bin/mount - - - - /run/current-system/sw/bin/mount" "L+ /sbin/mount - - - - /run/current-system/sw/bin/mount" "L+ /bin/umount - - - - /run/current-system/sw/bin/umount" "L+ /usr/bin/umount - - - - /run/current-system/sw/bin/umount" "L+ /bin/nsenter - - - - /run/current-system/sw/bin/nsenter" "L+ /usr/bin/nsenter - - - - /run/current-system/sw/bin/nsenter" # NFS Mount Helpers (Crucial for Longhorn Share-Manager / RWX volumes) "L+ /sbin/mount.nfs - - - - /run/current-system/sw/bin/mount.nfs" "L+ /sbin/umount.nfs - - - - /run/current-system/sw/bin/umount.nfs" "L+ /usr/sbin/mount.nfs - - - - /run/current-system/sw/bin/mount.nfs" "L+ /usr/sbin/umount.nfs - - - - /run/current-system/sw/bin/umount.nfs" # NFSv4 specific helpers required by Longhorn RWX "L+ /sbin/mount.nfs4 - - - - /run/current-system/sw/bin/mount.nfs4" "L+ /sbin/umount.nfs4 - - - - /run/current-system/sw/bin/umount.nfs4" "L+ /usr/sbin/mount.nfs4 - - - - /run/current-system/sw/bin/mount.nfs4" "L+ /usr/sbin/umount.nfs4 - - - - /run/current-system/sw/bin/umount.nfs4" ]; # RAID boot.swraid = { enable = true; mdadmConf = '' MAILADDR root ARRAY /dev/md0 level=raid10 num-devices=4 metadata=1.2 UUID=f94b90a5:574f242f:00596ed9:a2b369c7 ''; }; fileSystems."/mnt/raid" = { device = "/dev/disk/by-uuid/208bee23-4723-42c2-ac4e-c902eb530f80"; fsType = "ext4"; options = [ "defaults" "nofail" ]; }; # NFS services.nfs = { server.enable = true; server.exports = '' /export/yarr 192.168.1.0/16(rw,secure,anonuid=1000,anongid=1000,all_squash) /export/nextcloud 192.168.1.0/16(rw,secure,no_root_squash) /export 192.168.1.0/16(ro,fsid=0,root_squash,subtree_check,secure) ''; # Pin the ports server.statdPort = 4000; server.lockdPort = 4001; server.mountdPort = 4002; }; fileSystems."/export/yarr" = { device = "/mnt/raid/yarr"; fsType = "ext4"; options = [ "bind" ]; }; fileSystems."/export/nextcloud" = { device = "/mnt/raid/nextcloud"; fsType = "ext4"; options = [ "bind" ]; }; networking.firewall = { enable = true; trustedInterfaces = [ "cni0" "flannel.1" ]; allowedTCPPorts = [ 22 # SSH (CRITICAL: Do not remove) # --- NFS Ports --- 111 2049 4000 4001 4002 # --- K3s Agent Ports --- 10250 # Kubelet API (Required for master node logs/metrics/exec) 9100 # Prometheus Node Exporter ]; allowedUDPPorts = [ # --- NFS Ports --- 111 2049 4000 4001 4002 # --- K3s Agent Ports --- 8472 # Flannel VXLAN overlay networking (Required for pod-to-pod communication) ]; }; security.sudo.wheelNeedsPassword = false; boot = { loader = { systemd-boot.enable = true; efi.canTouchEfiVariables = true; timeout = 1; }; kernelPackages = pkgs.linuxPackages_latest; supportedFilesystems = [ "nfs" ]; }; time.timeZone = "America/New_York"; time.hardwareClockInLocalTime = false; nix.settings.experimental-features = [ "nix-command" "flakes" ]; nix.settings.auto-optimise-store = true; nix.gc = { automatic = true; dates = "weekly"; options = "--delete-older-than 30d"; }; nixpkgs.config.allowUnfree = true; system.stateVersion = "26.05"; }; }