39 lines
932 B
Nix
39 lines
932 B
Nix
{ pkgs, ... }: {
|
|
boot.kernel.sysctl = {
|
|
"fs.inotify.max_user_watches" = 52428800;
|
|
"fs.inotify.max_user_instances" = 4096;
|
|
|
|
# Testing...
|
|
# "net.core.netdev_max_backlog" = 4000;
|
|
# "net.ipv4.tcp_max_syn_backlog" = 4096;
|
|
};
|
|
|
|
# Allow Docker containers to access Tailscale network
|
|
networking.firewall = {
|
|
trustedInterfaces = [ "tailscale0" ];
|
|
allowedUDPPorts = [ 41641 ]; # Tailscale port
|
|
};
|
|
|
|
virtualisation.docker = {
|
|
enable = true;
|
|
enableOnBoot = true;
|
|
liveRestore = true;
|
|
autoPrune = {
|
|
enable = true;
|
|
dates = "weekly";
|
|
flags = ["--all"];
|
|
};
|
|
daemon.settings = {
|
|
registry-mirrors = [ "https://registry.sysctl.io" ];
|
|
};
|
|
};
|
|
|
|
environment.systemPackages = with pkgs; [
|
|
docker-compose
|
|
ctop
|
|
];
|
|
|
|
# Add the docker telegraf listener
|
|
services.telegraf.extraConfig.inputs.docker = {};
|
|
users.users.telegraf.extraGroups = [ "docker" ];
|
|
}
|