| author | |
| committer | |
| log | 81fe4b4ac91d4d63a8aac700e5b9e89c52b0f29b |
| tree | cda67614c112a170faa0503e30fbcc81acb6a2e9 |
| parent | c64219e7951c831e93c786d0f5a74ad685f066d5 |
| signature | Signed by SSH key SHA256:52mNGHRsVFBDED9IAX5pe+LRWUefqTbxEReunq21QvU |
Add a BIOS and USB capable NixOS installer with migration tools and key-only SSH. Share Zenith’s existing public admin key between the live installer and installed system.
Assisted-by: gpt-64 files changed, 40 insertions(+), 2 deletions(-)
config/admin.pub created+1| ... | @@ -0,0 +1 @@ | ||
| 1 | ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMpxNpkRLTUijhd3HSaOvKYn2MWXEY+YEFdsPNZhBROn clo@sandwich.local | ||
flake.nix+23| ... | @@ -6,9 +6,32 @@ | ... | @@ -6,9 +6,32 @@ |
| 6 | outputs = { self, nixpkgs, ... }: { | 6 | outputs = { self, nixpkgs, ... }: { |
| 7 | packages.x86_64-linux.dashboard = nixpkgs.legacyPackages.x86_64-linux.callPackage ./nixos/dashboard.nix { }; | 7 | packages.x86_64-linux.dashboard = nixpkgs.legacyPackages.x86_64-linux.callPackage ./nixos/dashboard.nix { }; |
| 8 | packages.x86_64-linux.dashboard-image = self.packages.x86_64-linux.dashboard.image; | 8 | packages.x86_64-linux.dashboard-image = self.packages.x86_64-linux.dashboard.image; |
| 9 | packages.x86_64-linux.installer = self.nixosConfigurations.installer.config.system.build.isoImage; | ||
| 9 | 10 | ||
| 10 | packages.aarch64-darwin.qemu = nixpkgs.legacyPackages.aarch64-darwin.qemu; | 11 | packages.aarch64-darwin.qemu = nixpkgs.legacyPackages.aarch64-darwin.qemu; |
| 11 | 12 | ||
| 13 | nixosConfigurations.installer = nixpkgs.lib.nixosSystem { | ||
| 14 | system = "x86_64-linux"; | ||
| 15 | modules = [ | ||
| 16 | "${nixpkgs}/nixos/modules/installer/cd-dvd/installation-cd-minimal.nix" | ||
| 17 | ({ lib, pkgs, ... }: { | ||
| 18 | networking.hostName = "infra-2-installer"; | ||
| 19 | boot.zfs.forceImportRoot = false; | ||
| 20 | users.users.root.openssh.authorizedKeys.keys = [ (lib.fileContents ./config/admin.pub) ]; | ||
| 21 | services.openssh.settings = { | ||
| 22 | PasswordAuthentication = false; | ||
| 23 | KbdInteractiveAuthentication = false; | ||
| 24 | }; | ||
| 25 | nix.settings.experimental-features = [ "nix-command" "flakes" ]; | ||
| 26 | environment.etc."infra-2".source = self; | ||
| 27 | environment.systemPackages = [ | ||
| 28 | (pkgs.callPackage ./nixos/pkl.nix { }) pkgs.python3 pkgs.rsync | ||
| 29 | ]; | ||
| 30 | isoImage.storeContents = [ self.packages.x86_64-linux.dashboard-image ]; | ||
| 31 | }) | ||
| 32 | ]; | ||
| 33 | }; | ||
| 34 | |||
| 12 | nixosConfigurations.vm = nixpkgs.lib.nixosSystem { | 35 | nixosConfigurations.vm = nixpkgs.lib.nixosSystem { |
| 13 | system = "x86_64-linux"; | 36 | system = "x86_64-linux"; |
| 14 | modules = [ ./nixos/configuration.nix ./nixos/vm.nix ]; | 37 | modules = [ ./nixos/configuration.nix ./nixos/vm.nix ]; |
nixos/zenith.nix+2-2| ... | @@ -1,6 +1,6 @@ | ... | @@ -1,6 +1,6 @@ |
| 1 | { pkgs, ... }: | 1 | { lib, pkgs, ... }: |
| 2 | let | 2 | let |
| 3 | adminKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMpxNpkRLTUijhd3HSaOvKYn2MWXEY+YEFdsPNZhBROn clo@sandwich.local"; | 3 | adminKey = lib.fileContents ../config/admin.pub; |
| 4 | in | 4 | in |
| 5 | { | 5 | { |
| 6 | networking.hostName = "zenith"; | 6 | networking.hostName = "zenith"; |
readme.md+14| ... | @@ -37,6 +37,20 @@ at upload time. Their frozen contents are part of the release digest. | ... | @@ -37,6 +37,20 @@ at upload time. Their frozen contents are part of the release digest. |
| 37 | `main` joins the infra-2 and home-infra histories. Its tree contains infra-2; | 37 | `main` joins the infra-2 and home-infra histories. Its tree contains infra-2; |
| 38 | the retired configuration remains available in the home-infra parent history. | 38 | the retired configuration remains available in the home-infra parent history. |
| 39 | 39 | ||
| 40 | ## installer | ||
| 41 | |||
| 42 | After publishing main, build the prepared USB image on an x86 Linux host: | ||
| 43 | |||
| 44 | ```sh | ||
| 45 | nix build --extra-experimental-features 'nix-command flakes' path:/opt/studio/main#installer | ||
| 46 | ``` | ||
| 47 | |||
| 48 | The ISO is in `result/iso/`. It boots a live installer with this Mac's SSH key, | ||
| 49 | ZFS and migration tools, the uploaded repository at `/etc/infra-2`, and a cached | ||
| 50 | dashboard image. It does not install automatically. The physical installation | ||
| 51 | uses `#zenith` after generating its hardware configuration; the existing data | ||
| 52 | pool and service state follow the [handoff](tools/legacy-handoff.md). | ||
| 53 | |||
| 40 | ## filesystem layout | 54 | ## filesystem layout |
| 41 | 55 | ||
| 42 | The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely | 56 | The computer mounts the ZFS root dataset under `/srv`, meaning "server," loosely |