diff --git a/config/admin.pub b/config/admin.pub new file mode 100644 index 0000000000000000000000000000000000000000..df6a10fd3934d6c5f10950b6de30a3986e0e860b --- /dev/null +++ b/config/admin.pub @@ -0,0 +1 @@ +ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMpxNpkRLTUijhd3HSaOvKYn2MWXEY+YEFdsPNZhBROn clo@sandwich.local diff --git a/flake.nix b/flake.nix index b50542f56f4b1d5a7dae9e4e6926c089250719a8..0e6d8f35a89986aa5bdfa284e26f943afe482696 100644 --- a/flake.nix +++ b/flake.nix @@ -6,9 +6,32 @@ outputs = { self, nixpkgs, ... }: { packages.x86_64-linux.dashboard = nixpkgs.legacyPackages.x86_64-linux.callPackage ./nixos/dashboard.nix { }; packages.x86_64-linux.dashboard-image = self.packages.x86_64-linux.dashboard.image; + packages.x86_64-linux.installer = self.nixosConfigurations.installer.config.system.build.isoImage; packages.aarch64-darwin.qemu = nixpkgs.legacyPackages.aarch64-darwin.qemu; + nixosConfigurations.installer = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + "${nixpkgs}/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix" + ({ lib, pkgs, ... }: { + networking.hostName = "infra-2-installer"; + boot.zfs.forceImportRoot = false; + users.users.root.openssh.authorizedKeys.keys = [ (lib.fileContents ./config/admin.pub) ]; + services.openssh.settings = { + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + }; + nix.settings.experimental-features = [ "nix-command" "flakes" ]; + environment.etc."infra-2".source = self; + environment.systemPackages = [ + (pkgs.callPackage ./nixos/pkl.nix { }) pkgs.python3 pkgs.rsync + ]; + isoImage.storeContents = [ self.packages.x86_64-linux.dashboard-image ]; + }) + ]; + }; + nixosConfigurations.vm = nixpkgs.lib.nixosSystem { system = "x86_64-linux"; modules = [ ./nixos/configuration.nix ./nixos/vm.nix ]; diff --git a/nixos/zenith.nix b/nixos/zenith.nix index f4dddb6cf157bac3932f36811c8751af04e74e6f..bfc305b7af553891346cec4bf64e058873668e2f 100644 --- a/nixos/zenith.nix +++ b/nixos/zenith.nix @@ -1,6 +1,6 @@ -{ pkgs, ... }: +{ lib, pkgs, ... }: let - adminKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMpxNpkRLTUijhd3HSaOvKYn2MWXEY+YEFdsPNZhBROn clo@sandwich.local"; + adminKey = lib.fileContents ../config/admin.pub; in { networking.hostName = "zenith"; diff --git a/readme.md b/readme.md index f2afa7639a15254d652759c4edbefea0cbafc4af..c91927fe33714fcb548110994a168dd623a67aa2 100644 --- a/readme.md +++ b/readme.md @@ -37,6 +37,20 @@ at upload time. Their frozen contents are part of the release digest. `main` joins the infra-2 and home-infra histories. Its tree contains infra-2; the retired configuration remains available in the home-infra parent history. +## installer + +After publishing main, build the prepared USB image on an x86 Linux host: + +```sh +nix build --extra-experimental-features 'nix-command flakes' path:/opt/studio/main#installer +``` + +The ISO is in `result/iso/`. It boots a live installer with this Mac's SSH key, +ZFS and migration tools, the uploaded repository at `/etc/infra-2`, and a cached +dashboard image. It does not install automatically. The physical installation +uses `#zenith` after generating its hardware configuration; the existing data +pool and service state follow the [handoff](tools/legacy-handoff.md). + ## filesystem layout The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely