`networking.wireguard.interfaces.wg0.ips` was set in hardware/douro.nix and hardware/batm3.nix, but hardware/upboard.nix is shared by tejo and sintra — an address there would be claimed by both machines on the same /24, so neither got one. tejo therefore evaluated to `wg0.ips = [ ]`: the interface comes up with no IP and the tunnel is silently dead. On a machine with no other route in, that is how you lose a box. Replace the two per-hardware definitions with one `wireguardIpForModel` table in flake.nix, keyed on model like fiatCodeForModel / upgradeWindowForModel / nfcReaderForModel, and give tejo 10.0.0.3/24 — the address it answers on today under its factory Debian. douro (10.0.0.4/24) and batm3 (10.0.0.5/24) evaluate unchanged; sintra stays deliberately unlisted, since it is reachable on the LAN and has never had a tunnel address. The address is only half of it: the VPS maps peer pubkey to tunnel IP, so the machine still needs /var/lib/wireguard/wg0.key carried over from its previous install (or a fresh key added to the VPS peer list). Both wireguard units are ConditionPathExists-guarded on that key, so a keyless first boot is clean and the tunnel starts once it is dropped in. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
104 lines
2.8 KiB
Nix
104 lines
2.8 KiB
Nix
# Douro (Bay Trail) Hardware Configuration
|
|
# Bay Trail Atom SoC with eDP panel, mSATA internal storage.
|
|
#
|
|
# Kernel 5.15 LTS required: i915 eDP display regression in 6.x kernels
|
|
# causes blank screen on Bay Trail with embedded DisplayPort panels.
|
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
{
|
|
boot = {
|
|
loader = {
|
|
systemd-boot.enable = true;
|
|
efi.canTouchEfiVariables = true;
|
|
timeout = 3;
|
|
};
|
|
|
|
# Bay Trail needs 5.15 LTS (i915 eDP regression in 6.x)
|
|
kernelPackages = pkgs.linuxPackages_5_15;
|
|
|
|
initrd.availableKernelModules = [
|
|
"xhci_pci"
|
|
"ahci"
|
|
# USB mass-storage: required to boot the dd'd image from a USB stick
|
|
# (stage-1 must bind the flash drive as a SCSI disk so
|
|
# /dev/disk/by-label/* appears). Harmless on the internal install.
|
|
#
|
|
# NOTE: deliberately NO "uas" here. Many USB sticks/bridges advertise
|
|
# UAS but drop off the bus ("device offline error, dev sdb") under
|
|
# sustained write load. Blacklisting uas below forces the slower-but-
|
|
# reliable usb-storage (Bulk-Only Transport) path. SATA/mSATA installs
|
|
# don't use uas anyway. (Same hardening as batm3.nix.)
|
|
"usb_storage"
|
|
"sd_mod"
|
|
"sdhci_pci"
|
|
"i915"
|
|
];
|
|
|
|
# Keep the USB flash drive off the flaky UAS driver (see note above).
|
|
blacklistedKernelModules = [ "uas" ];
|
|
|
|
kernelModules = [
|
|
"kvm-intel"
|
|
"i2c-dev"
|
|
"spi-dev"
|
|
];
|
|
|
|
kernelParams = [
|
|
"i915.enable_psr=0"
|
|
"vt.handoff=7" # Bay Trail: preserve BIOS display init
|
|
"quiet"
|
|
"splash"
|
|
# Disable USB autosuspend so the boot medium (and kiosk peripherals)
|
|
# aren't power-suspended mid-I/O — another cause of "device offline".
|
|
"usbcore.autosuspend=-1"
|
|
];
|
|
};
|
|
|
|
# Disk layout: GPT with ESP (sda1) + ext4 root (sda2)
|
|
fileSystems."/" = {
|
|
device = "/dev/disk/by-label/nixos";
|
|
fsType = "ext4";
|
|
};
|
|
|
|
# make-disk-image.nix labels the ESP as "ESP" (not "boot")
|
|
fileSystems."/boot" = {
|
|
device = "/dev/disk/by-label/ESP";
|
|
fsType = "vfat";
|
|
};
|
|
|
|
hardware = {
|
|
graphics = {
|
|
enable = true;
|
|
extraPackages = with pkgs; [
|
|
intel-media-driver
|
|
libva-vdpau-driver
|
|
libvdpau-va-gl
|
|
];
|
|
};
|
|
enableRedistributableFirmware = true;
|
|
cpu.intel.updateMicrocode = true;
|
|
};
|
|
|
|
powerManagement = {
|
|
enable = true;
|
|
cpuFreqGovernor = "performance";
|
|
};
|
|
|
|
# Disable suspend/hibernate for kiosk
|
|
systemd.targets = {
|
|
sleep.enable = false;
|
|
suspend.enable = false;
|
|
hibernate.enable = false;
|
|
hybrid-sleep.enable = false;
|
|
};
|
|
|
|
# WireGuard VPN address → wireguardIpForModel in flake.nix.
|
|
|
|
# Serial port access for bill validator/dispenser
|
|
services.udev.extraRules = lib.mkAfter ''
|
|
KERNEL=="ttyS[0-9]*", MODE="0666"
|
|
KERNEL=="ttyUSB[0-9]*", MODE="0666"
|
|
KERNEL=="ttyACM[0-9]*", MODE="0666"
|
|
'';
|
|
}
|