From c541cb1474da3b95aca12246fb7d9df7c13957a4 Mon Sep 17 00:00:00 2001 From: autonomic-bot Date: Mon, 3 Aug 2026 20:13:24 +0000 Subject: [PATCH] networking: pin defaultGateway to eth0 (fixes no-default-route on 25.05+) Since NixOS 25.05, scripted networking installs the default route from the gateway interface's network-addresses-.service, matching the interface via defaultGateway.interface or by subnet inclusion. Hetzner's off-subnet point-to-point gateway (91.98.47.73/32 on eth0, gw 172.31.1.1) matched neither with the bare-string form, so the 26.05 switch on 2026-08-03 left the host with no default route and off the network (recovered via Hetzner rescue: grubenv default back to the 24.11 generation). With an explicit interface, the module installs both the gateway host route and the default route from eth0's own unit: ip -4 route replace 172.31.1.1 proto static dev eth0 ip -4 route replace default proto static dev eth0 via 172.31.1.1 Verified by nix eval of systemd.services.network-addresses-eth0.script. --- nix/hosts/cc-ci-hetzner/networking.nix | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/nix/hosts/cc-ci-hetzner/networking.nix b/nix/hosts/cc-ci-hetzner/networking.nix index e2c58a1..dde909e 100644 --- a/nix/hosts/cc-ci-hetzner/networking.nix +++ b/nix/hosts/cc-ci-hetzner/networking.nix @@ -14,7 +14,18 @@ "185.12.64.1" "185.12.64.2" ]; - defaultGateway = "172.31.1.1"; + # The interface MUST be explicit here. Since NixOS 25.05 the scripted-networking + # module installs the default route from the gateway interface's + # network-addresses-.service, and it finds that interface either by + # `defaultGateway.interface` or by the gateway address being inside one of the + # interface's subnets. With Hetzner's off-subnet point-to-point gateway + # (91.98.47.73/32 on eth0, gateway 172.31.1.1) neither matched when this was a + # bare string, so NO default route was installed and the 26.05 rebuild on + # 2026-08-03 took the host off the network (recovered via rescue mode). + defaultGateway = { + address = "172.31.1.1"; + interface = "eth0"; + }; # No IPv6 on this Hetzner instance (link-local only) — nixos-infect emitted an empty # defaultGateway6/ipv6.route which made network-addresses-eth0.service fail # ("ip route add /128" with no prefix). v4-only box, so no IPv6 gateway/route declared.