Without this the installer only ever sees cache.nixos.org, which
doesn't carry sops-install-secrets — it's built straight from the
sops-nix flake's own Go source, not part of nixpkgs. Every install had
to compile it from scratch, which is what ran an 8GB LXC container's
disk out of space (Go toolchain fetch plus a large module tree of
small files, all on the same disk that needs to hold the rest of the
system).
Once sops-install-secrets has been built once anywhere and served via
the existing nix-cache/nix-serve setup (naturally happens the next
time nix-cache itself gets switched with the sops-nix changes), every
future install of any type fetches the pre-built binary instead of
rebuilding.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
sops-nix (in the nixos flake) derives each host's age decryption key
from its own /etc/ssh/ssh_host_ed25519_key at activation time, which
runs before systemd would otherwise generate that key on first boot
(sshd-keygen is a plain systemd service gated behind multi-user.target;
activation scripts run earlier). Without pre-seeding, secrets --
including the login password -- fail to decrypt on a fresh install's
very first boot.
- scripts/prepare-host-key.sh: run on the admin workstation before an
install, generates the host's ed25519 keypair and prints the exact
steps to register its derived age key in nixos/.sops.yaml and
re-encrypt the affected secrets/*.yaml files.
- common.nix's auto-install.sh: after disko mounts /mnt and before
nixos-install, installs a pre-seeded key from /root/host-keys/ into
/mnt/etc/ssh/ if present, otherwise warns and asks for confirmation
before continuing without one.
- installer.nix now imports common.nix (previously only proxmox-lxc.nix
did), so the ISO/netboot path used for EFI VM installs gets the same
auto-install.sh and pre-seed check, not just the LXC path.
- Also fixes a pre-existing stray backtick in the disko invocation that
broke auto-install.sh's bash syntax entirely, independent of this
change (found while rendering the script to verify the new logic).
README.md documents the new pre-flight workflow.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Replaces the single monolithic installer.nix (preserved as
installer_old.nix for reference) with a shared common.nix carrying the
install-script/user/SSH baseline, consumed by per-platform targets
(installer.nix for netboot/ISO, new proxmox-lxc.nix for the Proxmox
LXC-based flow). flake.nix drops the nixos-generators input in favor
of building images directly from each nixosConfiguration's
system.build.isoImage/tarball.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>