fix(vds-nftables): remove allowPing — not a top-level networking option

networking.allowPing was a top-level networking option when
firewall.enable = true. With firewall.enable = false (T3 Option A),
the option no longer exists at the networking level. ICMP is now
handled by the nftables ruleset directly
().

Rebuild error: 'The option networking.allowPing does not exist.
Definition values: networking.domain, networking.vlans, networking.wicd.'

Fix: remove the line. No behavior change — ICMP is still accepted
via nftables.
This commit is contained in:
2026-10-10 16:47:02 +03:00
parent 57967861c1
commit 3deaa75f5c
+4 -1
View File
@@ -89,7 +89,10 @@
firewall.enable = false;
firewall.allowedTCPPorts = lib.mkForce [ ];
firewall.interfaces = lib.mkForce { };
allowPing = true;
# allowPing removed 2026-10-10 (T3 Option A): with firewall.enable = false,
# `networking.allowPing` no longer exists as a top-level option. ICMP
# accept is now handled by the nftables ruleset below
# (`ip protocol icmp accept`).
nftables = {
enable = true;
ruleset = ''