| author | |
| committer | |
| log | 3c2e26a1d96a4046f45ebc1a19ee87dda5651e64 |
| tree | bc6b4e4b462f37312f2864cac022130a302f3f6d |
| parent | 81fe4b4ac91d4d63a8aac700e5b9e89c52b0f29b |
| signature | Signed by SSH key SHA256:52mNGHRsVFBDED9IAX5pe+LRWUefqTbxEReunq21QvU |
Share static networking between the installer and installed system. Start key-only SSH automatically so installation can proceed from the Mac after USB boot.
Assisted-by: gpt-64 files changed, 20 insertions(+), 8 deletions(-)
flake.nix+3| ... | @@ -14,10 +14,13 @@ | ... | @@ -14,10 +14,13 @@ |
| 14 | system = "x86_64-linux"; | 14 | system = "x86_64-linux"; |
| 15 | modules = [ | 15 | modules = [ |
| 16 | "${nixpkgs}/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix" | 16 | "${nixpkgs}/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix" |
| 17 | ./nixos/zenith-network.nix | ||
| 17 | ({ lib, pkgs, ... }: { | 18 | ({ lib, pkgs, ... }: { |
| 18 | networking.hostName = "infra-2-installer"; | 19 | networking.hostName = "infra-2-installer"; |
| 20 | networking.networkmanager.enable = lib.mkForce false; | ||
| 19 | boot.zfs.forceImportRoot = false; | 21 | boot.zfs.forceImportRoot = false; |
| 20 | users.users.root.openssh.authorizedKeys.keys = [ (lib.fileContents ./config/admin.pub) ]; | 22 | users.users.root.openssh.authorizedKeys.keys = [ (lib.fileContents ./config/admin.pub) ]; |
| 23 | services.openssh.enable = true; | ||
| 21 | services.openssh.settings = { | 24 | services.openssh.settings = { |
| 22 | PasswordAuthentication = false; | 25 | PasswordAuthentication = false; |
| 23 | KbdInteractiveAuthentication = false; | 26 | KbdInteractiveAuthentication = false; |
nixos/zenith-network.nix created+10| ... | @@ -0,0 +1,10 @@ | ||
| 1 | { | ||
| 2 | networking.useDHCP = false; | ||
| 3 | networking.interfaces.enp4s0.useDHCP = false; | ||
| 4 | networking.interfaces.enp4s0.ipv4.addresses = [ | ||
| 5 | { address = "10.0.0.1"; prefixLength = 24; } | ||
| 6 | { address = "192.168.0.1"; prefixLength = 24; } | ||
| 7 | ]; | ||
| 8 | networking.defaultGateway = { address = "10.0.0.2"; interface = "enp4s0"; }; | ||
| 9 | networking.nameservers = [ "1.1.1.1" "1.0.0.1" ]; | ||
| 10 | } | ||
nixos/zenith.nix+2-8| ... | @@ -3,16 +3,10 @@ let | ... | @@ -3,16 +3,10 @@ let |
| 3 | adminKey = lib.fileContents ../config/admin.pub; | 3 | adminKey = lib.fileContents ../config/admin.pub; |
| 4 | in | 4 | in |
| 5 | { | 5 | { |
| 6 | imports = [ ./zenith-network.nix ]; | ||
| 7 | |||
| 6 | networking.hostName = "zenith"; | 8 | networking.hostName = "zenith"; |
| 7 | networking.hostId = "4fa19ccb"; | 9 | networking.hostId = "4fa19ccb"; |
| 8 | networking.useDHCP = false; | ||
| 9 | networking.interfaces.enp4s0.useDHCP = false; | ||
| 10 | networking.interfaces.enp4s0.ipv4.addresses = [ | ||
| 11 | { address = "10.0.0.1"; prefixLength = 24; } | ||
| 12 | { address = "192.168.0.1"; prefixLength = 24; } | ||
| 13 | ]; | ||
| 14 | networking.defaultGateway = { address = "10.0.0.2"; interface = "enp4s0"; }; | ||
| 15 | networking.nameservers = [ "1.1.1.1" "1.0.0.1" ]; | ||
| 16 | networking.firewall.allowedTCPPorts = [ 80 443 ]; | 10 | networking.firewall.allowedTCPPorts = [ 80 443 ]; |
| 17 | networking.firewall.interfaces.enp4s0.allowedTCPPorts = [ 445 ]; | 11 | networking.firewall.interfaces.enp4s0.allowedTCPPorts = [ 445 ]; |
| 18 | 12 |
readme.md+5| ... | @@ -51,6 +51,11 @@ dashboard image. It does not install automatically. The physical installation | ... | @@ -51,6 +51,11 @@ dashboard image. It does not install automatically. The physical installation |
| 51 | uses `#zenith` after generating its hardware configuration; the existing data | 51 | uses `#zenith` after generating its hardware configuration; the existing data |
| 52 | pool and service state follow the [handoff](tools/legacy-handoff.md). | 52 | pool and service state follow the [handoff](tools/legacy-handoff.md). |
| 53 | 53 | ||
| 54 | On Zenith, the live installer uses the same wired addresses and gateway as the | ||
| 55 | installed system. Once firmware boots the USB, connect from this Mac with | ||
| 56 | `ssh root@10.0.0.1`. SSH starts automatically and accepts the admin key only; | ||
| 57 | no monitor, local login, or DHCP address lookup is needed after USB boot. | ||
| 58 | |||
| 54 | ## filesystem layout | 59 | ## filesystem layout |
| 55 | 60 | ||
| 56 | The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely | 61 | The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely |