From a4c50351f5d55438a102d48c63dcbb62f9ef5e8d Mon Sep 17 00:00:00 2001 From: "Henry J. Webster" Date: Tue, 4 Aug 2026 17:10:10 -0500 Subject: networking: expose Ollama and mDNS on Wi-Fi LAN Serve Ollama on kusanagi's Wi-Fi LAN while removing the blanket tailscale0 firewall trust so tailnet traffic follows explicit host firewall rules instead of inheriting every listening service. Add shared LAN networking for both hosts: allow ping, publish and resolve .local names with Avahi, and scope mDNS to each machine's declared Wi-Fi interface. Assisted-by: OpenAI:gpt-5 --- common/net.nix | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 common/net.nix (limited to 'common/net.nix') diff --git a/common/net.nix b/common/net.nix new file mode 100644 index 0000000..9341245 --- /dev/null +++ b/common/net.nix @@ -0,0 +1,36 @@ +# LAN reachability and mDNS discovery shared by all machines. +{ + config, + lib, + ... +}: + +let + cfg = config.lanDiscovery; +in +{ + options.lanDiscovery.interface = lib.mkOption { + type = lib.types.str; + description = "Wi-Fi LAN interface used for mDNS discovery."; + }; + + config = { + # Allow IPv4 ICMP echo requests so hosts can be found with ping. + networking.firewall.allowPing = true; + + # Avahi/mDNS: publish .local and resolve other *.local LAN names. + # Keep the multicast DNS firewall opening scoped to the host's Wi-Fi LAN interface. + networking.firewall.interfaces.${cfg.interface}.allowedUDPPorts = [ 5353 ]; + services.avahi = { + enable = true; + nssmdns4 = true; + openFirewall = false; + allowInterfaces = [ cfg.interface ]; + publish = { + enable = true; + addresses = true; + workstation = true; + }; + }; + }; +} -- cgit v1.3