After `lpppsssy`, `networking.nat` now recreates table ip nat on each switch, evicting netavark's published-port DNAT rules and breaking Caddy reverse proxies to published container ports. Pin the nftables driver so rules live in an isolated table inet netavark that NixOS never touches.
21 lines
659 B
Nix
21 lines
659 B
Nix
{ lib, ... }:
|
|
{
|
|
virtualisation.oci-containers.backend = lib.mkForce "podman";
|
|
virtualisation.podman = {
|
|
enable = true;
|
|
dockerCompat = true;
|
|
dockerSocket.enable = true;
|
|
defaultNetwork.settings.dns_enabled = true;
|
|
};
|
|
virtualisation.containers = {
|
|
containersConf.settings.network = {
|
|
# avoid collision with dnsmasq
|
|
dns_bind_port = 5353;
|
|
# keep netavark rules in an isolated `table inet netavark` instead of the
|
|
# `table ip nat` that networking.nat recreates on each nixos-rebuild switch,
|
|
# which would otherwise evict podman's published-port DNAT rules.
|
|
firewall_driver = "nftables";
|
|
};
|
|
};
|
|
}
|