Files
imxyy1soope1 ad9771d339 server: podman: use nftables firewall driver
After `lpppsssy`, `networking.nat` now recreates table ip nat on each switch, evicting
netavark's published-port DNAT rules and breaking Caddy reverse proxies
to published container ports. Pin the nftables driver so rules live in
an isolated table inet netavark that NixOS never touches.
2026-07-27 22:24:04 +08:00

21 lines
659 B
Nix

{ lib, ... }:
{
virtualisation.oci-containers.backend = lib.mkForce "podman";
virtualisation.podman = {
enable = true;
dockerCompat = true;
dockerSocket.enable = true;
defaultNetwork.settings.dns_enabled = true;
};
virtualisation.containers = {
containersConf.settings.network = {
# avoid collision with dnsmasq
dns_bind_port = 5353;
# keep netavark rules in an isolated `table inet netavark` instead of the
# `table ip nat` that networking.nat recreates on each nixos-rebuild switch,
# which would otherwise evict podman's published-port DNAT rules.
firewall_driver = "nftables";
};
};
}