authorgravatar for git@paperclover.netclover caruso <git@paperclover.net> 2026-10-03 21:10:14-07:00
committergravatar for git@paperclover.netclover caruso <git@paperclover.net> 2026-10-03 21:15:45-07:00
log81fe4b4ac91d4d63a8aac700e5b9e89c52b0f29b
treecda67614c112a170faa0503e30fbcc81acb6a2e9
parentc64219e7951c831e93c786d0f5a74ad685f066d5
signature Signed by SSH key SHA256:52mNGHRsVFBDED9IAX5pe+LRWUefqTbxEReunq21QvU

Bundle an infra-2 installer with main and a cached dashboard

Add a BIOS and USB capable NixOS installer with migration tools and key-only SSH. Share Zenith’s existing public admin key between the live installer and installed system. Assisted-by: gpt-6

4 files changed, 40 insertions(+), 2 deletions(-)

config/admin.pub created+1
...@@ -0,0 +1 @@
1ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMpxNpkRLTUijhd3HSaOvKYn2MWXEY+YEFdsPNZhBROn clo@sandwich.local
flake.nix+23
...@@ -6,9 +6,32 @@...@@ -6,9 +6,32 @@
6 outputs = { self, nixpkgs, ... }: {6 outputs = { self, nixpkgs, ... }: {
7 packages.x86_64-linux.dashboard = nixpkgs.legacyPackages.x86_64-linux.callPackage ./nixos/dashboard.nix { };7 packages.x86_64-linux.dashboard = nixpkgs.legacyPackages.x86_64-linux.callPackage ./nixos/dashboard.nix { };
8 packages.x86_64-linux.dashboard-image = self.packages.x86_64-linux.dashboard.image;8 packages.x86_64-linux.dashboard-image = self.packages.x86_64-linux.dashboard.image;
9 packages.x86_64-linux.installer = self.nixosConfigurations.installer.config.system.build.isoImage;
910
10 packages.aarch64-darwin.qemu = nixpkgs.legacyPackages.aarch64-darwin.qemu;11 packages.aarch64-darwin.qemu = nixpkgs.legacyPackages.aarch64-darwin.qemu;
1112
13 nixosConfigurations.installer = nixpkgs.lib.nixosSystem {
14 system = "x86_64-linux";
15 modules = [
16 "${nixpkgs}/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix"
17 ({ lib, pkgs, ... }: {
18 networking.hostName = "infra-2-installer";
19 boot.zfs.forceImportRoot = false;
20 users.users.root.openssh.authorizedKeys.keys = [ (lib.fileContents ./config/admin.pub) ];
21 services.openssh.settings = {
22 PasswordAuthentication = false;
23 KbdInteractiveAuthentication = false;
24 };
25 nix.settings.experimental-features = [ "nix-command" "flakes" ];
26 environment.etc."infra-2".source = self;
27 environment.systemPackages = [
28 (pkgs.callPackage ./nixos/pkl.nix { }) pkgs.python3 pkgs.rsync
29 ];
30 isoImage.storeContents = [ self.packages.x86_64-linux.dashboard-image ];
31 })
32 ];
33 };
34
12 nixosConfigurations.vm = nixpkgs.lib.nixosSystem {35 nixosConfigurations.vm = nixpkgs.lib.nixosSystem {
13 system = "x86_64-linux";36 system = "x86_64-linux";
14 modules = [ ./nixos/configuration.nix ./nixos/vm.nix ];37 modules = [ ./nixos/configuration.nix ./nixos/vm.nix ];
nixos/zenith.nix+2-2
...@@ -1,6 +1,6 @@...@@ -1,6 +1,6 @@
1{ pkgs, ... }:1{ lib, pkgs, ... }:
2let2let
3 adminKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMpxNpkRLTUijhd3HSaOvKYn2MWXEY+YEFdsPNZhBROn clo@sandwich.local";3 adminKey = lib.fileContents ../config/admin.pub;
4in4in
5{5{
6 networking.hostName = "zenith";6 networking.hostName = "zenith";
readme.md+14
...@@ -37,6 +37,20 @@ at upload time. Their frozen contents are part of the release digest....@@ -37,6 +37,20 @@ at upload time. Their frozen contents are part of the release digest.
37`main` joins the infra-2 and home-infra histories. Its tree contains infra-2;37`main` joins the infra-2 and home-infra histories. Its tree contains infra-2;
38the retired configuration remains available in the home-infra parent history.38the retired configuration remains available in the home-infra parent history.
3939
40## installer
41
42After publishing main, build the prepared USB image on an x86 Linux host:
43
44```sh
45nix build --extra-experimental-features 'nix-command flakes' path:/opt/studio/main#installer
46```
47
48The ISO is in `result/iso/`. It boots a live installer with this Mac's SSH key,
49ZFS and migration tools, the uploaded repository at `/etc/infra-2`, and a cached
50dashboard image. It does not install automatically. The physical installation
51uses `#zenith` after generating its hardware configuration; the existing data
52pool and service state follow the [handoff](tools/legacy-handoff.md).
53
40## filesystem layout54## filesystem layout
4155
42The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely56The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely