{ pkgs, config, hostName, ... }:
with builtins;
let
  inherit (config) networking;
  netIface = "enp5s0";
  lanNet = "192.168.1.0/24";
in
{
  imports = [
    networking/nftables.nix
    #networking/tor.nix
    networking/nsupdate.nix
    networking/wireless.nix
    networking/openvpn.nix
  ];

  boot.initrd.network = {
    enable = true;
    flushBeforeStage2 = true;
  };
  boot.initrd.systemd = {
    network.networks = {
      "10-${netIface}" = {
        name = netIface;
        # Start a DHCP Client for IPv4 Addressing/Routing
        DHCP = "ipv4";
        networkConfig = {
          # Accept Router Advertisements for Stateless IPv6 Autoconfiguraton (SLAAC)
          IPv6AcceptRA = true;
          IPv6PrivacyExtensions = true;
          KeepConfiguration = "dhcp-on-stop";
        };
      };
    };
  };

  systemd.services.systemd-networkd.environment.SYSTEMD_LOG_LEVEL = "debug";
  systemd.network = {
    enable = true;
    wait-online = {
      enable = false;
    };
    networks = {
      "10-${netIface}" = {
        name = netIface;
        # Start a DHCP Client for IPv4 Addressing/Routing
        DHCP = "ipv4";
        networkConfig = {
          # Accept Router Advertisements for Stateless IPv6 Autoconfiguraton (SLAAC)
          IPv6AcceptRA = true;
          IPv6PrivacyExtensions = true;
          KeepConfiguration = "dhcp-on-stop";
        };
        linkConfig = {
          RequiredForOnline = "no";
        };
      };
    };
  };

  /* WARNING: using ipconfig (the ip= kernel parameter) IS NOT RELIABLE:
     a 91.216.110.35/32 becomes a 91.216.110.35/8
    boot.kernelParams = map
    (ip: "ip=${ip.clientIP}:${ip.serverIP}:${ip.gatewayIP}:${ip.netmask}:${ip.hostname}:${ip.device}:${ip.autoconf}")
    [ { clientIP = netIPv4; serverIP = "";
      gatewayIP = networking.defaultGateway.address;
      netmask = "255.255.255.255";
      hostname = ""; device = networking.defaultGateway.interface;
      autoconf = "off";
    }
    { clientIP = lanIPv4; serverIP = "";
      gatewayIP = "";
      netmask = "255.255.255.0";
      hostname = ""; device = "enp2s0";
      autoconf = "off";
    }
    ];
  */
  /* DIY network config, but a right one */
  /*
    boot.initrd.preLVMCommands = ''
    set -x

    # IPv4 lan
    ip link set ${netIface} up
    ip address add ${lanIPv4}/32 dev ${netIface}
    ip route add ${lanIPv4Gateway} dev ${netIface}
    ip route add ${lanNet} dev ${netIface} src ${lanIPv4} proto kernel
    # NOTE: ${lanIPv4}/24 would not work with initrd's ip, hence ${lanNet}
    ip route add default via ${lanIPv4Gateway} dev ${netIface}

    # IPv6 net
    #ip -6 address add ''${lanIPv6} dev ${netIface}
    #ip -6 route add ''${lanIPv6Gateway} dev ${netIface}
    #ip -6 route add default via ''${lanIPv6Gateway} dev ${netIface}

    ip -4 address
    ip -4 route
    #ip -6 address
    #ip -6 route

    set +x
    '';
  */
  # Workaround https://github.com/NixOS/nixpkgs/issues/56822
  #boot.initrd.kernelModules = [ "ipv6" ];

  # Useless without an out-of-band access, and unsecure
  # (though / may still be encrypted at this point).
  # boot.kernelParams = [ "boot.shell_on_fail" ];

  /*
    # Disable IPv6 entirely until it's available
    boot.kernel.sysctl = {
    "net.ipv6.conf.${netIface}.disable_ipv6" = 1;
    };
  */

  networking = {
    hostName = hostName;
    domain = "sourcephile.fr";

    useDHCP = false;
    enableIPv6 = true;
  };

  networking.nftables.ruleset = ''
    table inet filter {
      chain input {
        iifname ${netIface} goto input-net
      }
      chain output {
        oifname ${netIface} jump output-net
        oifname ${netIface} log level warn prefix "output-net: " counter drop
      }
      chain output-net {
        ip daddr ${lanNet} log level info prefix "output-net: lan: " counter accept comment "LAN"
      }
    }
    table inet nat {
      chain postrouting {
        oifname ${netIface} masquerade
      }
    }
  '';
  /*
    security.gnupg.secrets."ipv6/${netIface}/stable_secret" = {};
    # This is only active in stage2, the initrd will still use the MAC-based SLAAC IPv6.
    system.activationScripts.ipv6 = ''
    ${pkgs.procps}/bin/sysctl --quiet net.ipv6.conf.${netIface}.stable_secret="$(cat ${gnupg.secrets."ipv6/${netIface}/stable_secret".path})"
    '';
  */
  environment.systemPackages = [
    pkgs.iodine
  ];
  services.vnstat.enable = true;
}