authorgravatar for git@paperclover.netclover caruso <git@paperclover.net> 2026-10-03 21:50:24-07:00
committergravatar for git@paperclover.netclover caruso <git@paperclover.net> 2026-10-03 21:52:20-07:00
log3c2e26a1d96a4046f45ebc1a19ee87dda5651e64
treebc6b4e4b462f37312f2864cac022130a302f3f6d
parent81fe4b4ac91d4d63a8aac700e5b9e89c52b0f29b
signature Signed by SSH key SHA256:52mNGHRsVFBDED9IAX5pe+LRWUefqTbxEReunq21QvU

Boot the Zenith installer with its usual wired SSH address

Share static networking between the installer and installed system. Start key-only SSH automatically so installation can proceed from the Mac after USB boot. Assisted-by: gpt-6

4 files changed, 20 insertions(+), 8 deletions(-)

flake.nix+3
...@@ -14,10 +14,13 @@...@@ -14,10 +14,13 @@
14 system = "x86_64-linux";14 system = "x86_64-linux";
15 modules = [15 modules = [
16 "${nixpkgs}/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix"16 "${nixpkgs}/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix"
17 ./nixos/zenith-network.nix
17 ({ lib, pkgs, ... }: {18 ({ lib, pkgs, ... }: {
18 networking.hostName = "infra-2-installer";19 networking.hostName = "infra-2-installer";
20 networking.networkmanager.enable = lib.mkForce false;
19 boot.zfs.forceImportRoot = false;21 boot.zfs.forceImportRoot = false;
20 users.users.root.openssh.authorizedKeys.keys = [ (lib.fileContents ./config/admin.pub) ];22 users.users.root.openssh.authorizedKeys.keys = [ (lib.fileContents ./config/admin.pub) ];
23 services.openssh.enable = true;
21 services.openssh.settings = {24 services.openssh.settings = {
22 PasswordAuthentication = false;25 PasswordAuthentication = false;
23 KbdInteractiveAuthentication = false;26 KbdInteractiveAuthentication = false;
nixos/zenith-network.nix created+10
...@@ -0,0 +1,10 @@
1{
2 networking.useDHCP = false;
3 networking.interfaces.enp4s0.useDHCP = false;
4 networking.interfaces.enp4s0.ipv4.addresses = [
5 { address = "10.0.0.1"; prefixLength = 24; }
6 { address = "192.168.0.1"; prefixLength = 24; }
7 ];
8 networking.defaultGateway = { address = "10.0.0.2"; interface = "enp4s0"; };
9 networking.nameservers = [ "1.1.1.1" "1.0.0.1" ];
10}
nixos/zenith.nix+2-8
...@@ -3,16 +3,10 @@ let...@@ -3,16 +3,10 @@ let
3 adminKey = lib.fileContents ../config/admin.pub;3 adminKey = lib.fileContents ../config/admin.pub;
4in4in
5{5{
6 imports = [ ./zenith-network.nix ];
7
6 networking.hostName = "zenith";8 networking.hostName = "zenith";
7 networking.hostId = "4fa19ccb";9 networking.hostId = "4fa19ccb";
8 networking.useDHCP = false;
9 networking.interfaces.enp4s0.useDHCP = false;
10 networking.interfaces.enp4s0.ipv4.addresses = [
11 { address = "10.0.0.1"; prefixLength = 24; }
12 { address = "192.168.0.1"; prefixLength = 24; }
13 ];
14 networking.defaultGateway = { address = "10.0.0.2"; interface = "enp4s0"; };
15 networking.nameservers = [ "1.1.1.1" "1.0.0.1" ];
16 networking.firewall.allowedTCPPorts = [ 80 443 ];10 networking.firewall.allowedTCPPorts = [ 80 443 ];
17 networking.firewall.interfaces.enp4s0.allowedTCPPorts = [ 445 ];11 networking.firewall.interfaces.enp4s0.allowedTCPPorts = [ 445 ];
1812
readme.md+5
...@@ -51,6 +51,11 @@ dashboard image. It does not install automatically. The physical installation...@@ -51,6 +51,11 @@ dashboard image. It does not install automatically. The physical installation
51uses `#zenith` after generating its hardware configuration; the existing data51uses `#zenith` after generating its hardware configuration; the existing data
52pool and service state follow the [handoff](tools/legacy-handoff.md).52pool and service state follow the [handoff](tools/legacy-handoff.md).
5353
54On Zenith, the live installer uses the same wired addresses and gateway as the
55installed system. Once firmware boots the USB, connect from this Mac with
56`ssh root@10.0.0.1`. SSH starts automatically and accepts the admin key only;
57no monitor, local login, or DHCP address lookup is needed after USB boot.
58
54## filesystem layout59## filesystem layout
5560
56The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely61The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely