Install longhorn on k3s

Introduce new storage standard with LVM
This commit is contained in:
Pim Kunis 2024-05-18 23:32:58 +02:00
parent 7e14a2cc13
commit a21a09ad6b
9 changed files with 257 additions and 69 deletions

View file

@ -15,7 +15,7 @@ let
# ./minecraft.nix
@ -25,6 +25,7 @@ in
imports = [

View file

@ -93,6 +93,7 @@
lab = {
ingresses.atticd = {
host = "";
entrypoint = "localsecure";
service = {
name = "atticd";

View file

@ -17,7 +17,14 @@
web.containerPort = 9000;
smtp.containerPort = 2500;
volumeMounts = [{
name = "storage";
mountPath = "/storage";
}; = "inbucket";
@ -44,6 +51,12 @@
persistentVolumeClaims.inbucket.spec = {
accessModes = [ "ReadWriteOnce" ];
storageClassName = "longhorn"; = "30Mi";
lab.ingresses.inbucket = {

View file

@ -0,0 +1,52 @@
{ nixhelm, system, ... }: {
config = {
kubernetes = {
helm.releases.longhorn = {
chart = nixhelm.chartsDerivations.${system}.longhorn.longhorn;
includeCRDs = true;
values = {
defaultSettings = {
defaultDataPath = "/mnt/longhorn";
storageMinimalAvailablePercentage = 0;
persistence = {
defaultClassReplicaCount = 2;
resources = {
ingresses.longhorn = {
metadata.annotations = {
"" = "letsencrypt";
"" = "localsecure";
spec = {
ingressClassName = "traefik";
rules = [{
host = "";
http.paths = [{
path = "/";
pathType = "Prefix";
backend.service = {
name = "longhorn-frontend";
port.number = 80;
tls = [{
secretName = "longhorn-tls";
hosts = [ "" ];

View file

@ -4,13 +4,12 @@
nixosModule.lab = {
storage = {
osDisk = "/dev/sda";
dataPartition = "/dev/nvme0n1p1";
kubernetesNode = true;
k3s = {
enable = true;
role = "agent";
# role = "server";
serverAddr = "https://jefke.dmz:6443";

View file

@ -4,8 +4,7 @@
nixosModule.lab = {
storage = {
osDisk = "/dev/sda";
dataPartition = "/dev/nvme0n1p1";
kubernetesNode = true;
k3s = {

View file

@ -11,46 +11,46 @@
config = builtins.readFile ./bird.conf;
}; = {
netdevs = {
hamgre = {
netdevConfig = {
Name = "hamgre";
Kind = "gre";
MTUBytes = "1468";
tunnelConfig = {
Remote = "";
#Local = "";
# hambr = { = {
# netdevs = {
# hamgre = {
# netdevConfig = {
# Name = "hambr";
# Kind = "bridge";
# Name = "hamgre";
# Kind = "gre";
# MTUBytes = "1468";
# };
# tunnelConfig = {
# Remote = "";
# #Local = "";
# };
# };
networks = {
"30-main-nic".networkConfig.Tunnel = "hamgre";
"40-hamgre" = {
matchConfig.Name = "hamgre";
networkConfig = {
Address = "";
# "40-hambr" = {
# matchConfig.Name = "hambr";
# # hambr = {
# # netdevConfig = {
# # Name = "hambr";
# # Kind = "bridge";
# # };
# # };
# };
# networks = {
# "30-main-nic".networkConfig.Tunnel = "hamgre";
# "40-hamgre" = {
# matchConfig.Name = "hamgre";
# networkConfig = {
# Address = "";
# };
# };
# # "40-hambr" = {
# # matchConfig.Name = "hambr";
# # };
# };

View file

@ -37,14 +37,20 @@ in {
config = lib.mkIf cfg.enable {
environment.systemPackages = with pkgs; [ k3s ];
environment.systemPackages = with pkgs; [
openiscsi # Required for Longhorn
nfs-utils # Required for Longhorn
jq # Required for Longhorn
networking = {
nftables.enable = lib.mkForce false;
firewall.enable = lib.mkForce false;
services.k3s =
services = {
k3s =
serverFlags = "--tls-san ${config.networking.fqdn} --disable servicelb --cluster-cidr=,2001:cafe:42::/56 --service-cidr=,2001:cafe:43::/112";
@ -57,6 +63,20 @@ in {
serverAddr = lib.mkIf (! (cfg.serverAddr == null)) cfg.serverAddr;
# Required for Longhorn
openiscsi = {
enable = true;
name = "${config.networking.fqdn}";
# HACK: Symlink binaries to /usr/local/bin such that Longhorn can find them
# when they use nsenter.
systemd.tmpfiles.rules = [
"L+ /usr/local/bin - - - - /run/current-system/sw/bin/"
system = lib.mkIf (cfg.role == "server") {
activationScripts = {
k3s-bootstrap.text = (
@ -73,11 +93,11 @@ in {
k3s-certs.text = ''
mkdir -p /var/lib/rancher/k3s/server/tls/etcd
ln -sf ${./k3s-ca/server-ca.crt} /var/lib/rancher/k3s/server/tls/server-ca.crt
ln -sf ${./k3s-ca/client-ca.crt} /var/lib/rancher/k3s/server/tls/client-ca.crt
ln -sf ${./k3s-ca/request-header-ca.crt} /var/lib/rancher/k3s/server/tls/request-header-ca.crt
ln -sf ${./k3s-ca/etcd/peer-ca.crt} /var/lib/rancher/k3s/server/tls/etcd/peer-ca.crt
ln -sf ${./k3s-ca/etcd/server-ca.crt} /var/lib/rancher/k3s/server/tls/etcd/server-ca.crt
cp -f ${./k3s-ca/server-ca.crt} /var/lib/rancher/k3s/server/tls/server-ca.crt
cp -f ${./k3s-ca/client-ca.crt} /var/lib/rancher/k3s/server/tls/client-ca.crt
cp -f ${./k3s-ca/request-header-ca.crt} /var/lib/rancher/k3s/server/tls/request-header-ca.crt
cp -f ${./k3s-ca/etcd/peer-ca.crt} /var/lib/rancher/k3s/server/tls/etcd/peer-ca.crt
cp -f ${./k3s-ca/etcd/server-ca.crt} /var/lib/rancher/k3s/server/tls/etcd/server-ca.crt

View file

@ -24,23 +24,126 @@ in {
Mount point of the machine's data partition.
kubernetesNode = lib.mkOption {
default = false;
type = lib.types.bool;
description = ''
Whether to apply the Kubernetes disk setup.
config = {
fileSystems = lib.attrsets.mergeAttrsList [
(lib.optionalAttrs (! machine.isRaspberryPi) {
"${cfg.dataMountPoint}".device = cfg.dataPartition;
(lib.optionalAttrs machine.isRaspberryPi {
"/" = {
fileSystems = {
"/" = lib.mkIf machine.isRaspberryPi {
device = "/dev/disk/by-label/NIXOS_SD";
fsType = "ext4";
options = [ "noatime" ];
disko = lib.mkIf (! machine.isRaspberryPi) {
disko = lib.mkIf (! machine.isRaspberryPi) (if cfg.kubernetesNode then {
devices = {
disk = {
nvme = {
device = "/dev/nvme0n1";
type = "disk";
content = {
type = "gpt";
partitions = {
boot = {
type = "EF00";
size = "500M";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
pv_os = {
size = "79G";
content = {
type = "lvm_pv";
vg = "vg_os";
pv_nvme_extra = {
size = "100%";
content = {
type = "lvm_pv";
vg = "vg_data";
sata = {
device = "/dev/sda";
type = "disk";
content = {
type = "gpt";
partitions.pv_sata = {
size = "100%";
content = {
type = "lvm_pv";
vg = "vg_data";
lvm_vg = {
vg_os = {
type = "lvm_vg";
lvs = {
root = {
size = "75G";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
mountOptions = [ "defaults" ];
swap = {
size = "100%FREE";
content.type = "swap";
vg_data = {
type = "lvm_vg";
lvs.longhorn = {
size = "100%FREE";
content = {
type = "filesystem";
format = "xfs";
mountpoint = "/mnt/longhorn";
} else {
# TODO: Rename this to 'osDisk'. Unfortunately, we would need to run nixos-anywhere again then.
devices.disk.vdb = {
device = cfg.osDisk;
@ -75,6 +178,6 @@ in {