summaryrefslogtreecommitdiffstats
path: root/lass/2configs/container-networking.nix
diff options
context:
space:
mode:
authorlassulus <lassulus@lassul.us>2018-05-16 17:32:00 +0200
committerlassulus <lassulus@lassul.us>2018-05-16 17:54:12 +0200
commit2e7bcebfd07080db071f07c3ad8e42e136857c31 (patch)
tree2bdf3f9a2d8dfaf58f1d138d08472669c1b4ffef /lass/2configs/container-networking.nix
parentdbcdae5e38bddcb7683ae115c222c098d8e3c6a5 (diff)
l container-networking: set ipv4.ip_forward
Diffstat (limited to 'lass/2configs/container-networking.nix')
-rw-r--r--lass/2configs/container-networking.nix3
1 files changed, 2 insertions, 1 deletions
diff --git a/lass/2configs/container-networking.nix b/lass/2configs/container-networking.nix
index 3dae3420d..98b56bd41 100644
--- a/lass/2configs/container-networking.nix
+++ b/lass/2configs/container-networking.nix
@@ -1,4 +1,4 @@
-{ ... }:
+{ lib, ... }:
{
#krebs.iptables.tables.filter.INPUT.rules = [
@@ -24,4 +24,5 @@
{ v6 = false; predicate = "-s 10.233.2.0/24 ! -d 10.233.2.0/24 -p tcp"; target = "MASQUERADE --to-ports 1024-65535"; }
{ v6 = false; predicate = "-s 10.233.2.0/24 ! -d 10.233.2.0/24 -p udp"; target = "MASQUERADE --to-ports 1024-65535"; }
];
+ boot.kernel.sysctl."net.ipv4.ip_forward" = lib.mkDefault 1;
}