diff --git a/hosts/imxyy-nix-server/docker.nix b/hosts/imxyy-nix-server/docker.nix deleted file mode 100644 index 045d071..0000000 --- a/hosts/imxyy-nix-server/docker.nix +++ /dev/null @@ -1,14 +0,0 @@ -{ lib, ... }: -{ - virtualisation.oci-containers.backend = lib.mkForce "podman"; - virtualisation.podman = { - enable = true; - dockerCompat = true; - dockerSocket.enable = true; - defaultNetwork.settings.dns_enabled = true; - }; - # avoid collision with dnsmasq - virtualisation.containers = { - containersConf.settings.network.dns_bind_port = 5353; - }; -} diff --git a/hosts/imxyy-nix-server/podman.nix b/hosts/imxyy-nix-server/podman.nix new file mode 100644 index 0000000..f0b6199 --- /dev/null +++ b/hosts/imxyy-nix-server/podman.nix @@ -0,0 +1,20 @@ +{ lib, ... }: +{ + virtualisation.oci-containers.backend = lib.mkForce "podman"; + virtualisation.podman = { + enable = true; + dockerCompat = true; + dockerSocket.enable = true; + defaultNetwork.settings.dns_enabled = true; + }; + virtualisation.containers = { + containersConf.settings.network = { + # avoid collision with dnsmasq + dns_bind_port = 5353; + # keep netavark rules in an isolated `table inet netavark` instead of the + # `table ip nat` that networking.nat recreates on each nixos-rebuild switch, + # which would otherwise evict podman's published-port DNAT rules. + firewall_driver = "nftables"; + }; + }; +}