Network bootstrap script

Info

Setup script based on the CyanLabs guide for configuring networking on the Proxmox host. Proxmox itself is installed via Hetzner’s server setup + the PVE post-install script.

Canonical doc: topology

# WAN NIC: on this host it's pinned to `nic0` via
# /usr/local/lib/systemd/network/50-pve-nic0.link (pve-network-interface-
# pinning, PVE 8→9 upgrade — it was `enp0s31f6` before). On a fresh
# install without the pin, substitute whatever owns the default route.
INTERFACE_NAME=nic0
IP_CIDR=$(ip addr show "$INTERFACE_NAME" | grep "inet\b" | awk '{print $2}')
GATEWAY=$(ip route | grep default | awk '{print $3}')
IP_ADDRESS=$(echo "$IP_CIDR" | cut -d'/' -f1)
CIDR=$(echo "$IP_CIDR" | cut -d'/' -f2)
echo $INTERFACE_NAME
echo $IP_CIDR
echo $GATEWAY
echo $IP_ADDRESS
echo $CIDR
cat > /tmp/proxmox_network_config << EOF
auto lo
iface lo inet loopback

iface $INTERFACE_NAME inet manual

auto vmbr0
iface vmbr0 inet static
  address $IP_ADDRESS/$CIDR
  gateway $GATEWAY
  bridge_ports $INTERFACE_NAME
  bridge_stp off
  bridge_fd 0
EOF


#interfaces.d/sdn — generated by SDN Apply, not hand-written:
auto vnet0
iface vnet0
  address 10.0.1.1/24
  post-up iptables -t nat -A POSTROUTING -s '10.0.1.0/24' -o vmbr0 -j SNAT --to-source «PUBLIC_IP»
  post-down iptables -t nat -D POSTROUTING -s '10.0.1.0/24' -o vmbr0 -j SNAT --to-source «PUBLIC_IP»
  post-up iptables -t raw -I PREROUTING -i fwbr+ -j CT --zone 1
  post-down iptables -t raw -D PREROUTING -i fwbr+ -j CT --zone 1
  bridge_ports none
  bridge_stp off
  bridge_fd 0
  ip-forward on

SDN-owned file

The post-up SNAT and CT-zone lines are emitted by SDN itself (subnet SNAT enabled) — they only look manual because the guide documented the generated file. Apply regenerates the file and wipes anything hand-added; custom rules (vnet1’s isolation) live in /etc/network/if-up.d/vnet-rules (see topology).