diff --git a/modules/common/configuration.nix b/modules/common/configuration.nix index cb2a757..eba6347 100644 --- a/modules/common/configuration.nix +++ b/modules/common/configuration.nix @@ -61,24 +61,32 @@ !include ${config.sops.templates."nix-github-token.conf".path} ''; - #Set root password - users.users.root = { - hashedPasswordFile = config.sops.secrets."root-hashedPassword".path; - }; + users = { + # With mutableUsers = false, update-users-groups.pl enforces hashedPasswordFile + # on every activation regardless of whether the account already exists in + # /etc/shadow. The default (true) only applies hashedPasswordFile to newly- + # created accounts — which means a freshly-built proxmox disk image (where + # activation runs without a usable sops key, so both accounts land in shadow + # with ‘!’) will never have its passwords fixed by subsequent boots. + mutableUsers = false; - # Define a user account. Don't forget to set a password with ‘passwd’. - users.users.${vars.primaryUser} = { - isNormalUser = true; - extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. - packages = with pkgs; [ - tree - ]; - hashedPasswordFile = config.sops.secrets."nixos-hashedPassword".path; - openssh.authorizedKeys.keys = [ - vars.adminSshKey - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICMJhrfFayLBG+gWtO6oAvgambw5nWWgztiTFEaaaVRH debian@surface" - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGygkCljN6uKpdJbHTOQtn8ZnH+wKXDLAwrDFbLrE/65 nixos@nixos" - ]; + users.root = { + hashedPasswordFile = config.sops.secrets."root-hashedPassword".path; + }; + + users.${vars.primaryUser} = { + isNormalUser = true; + extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. + packages = with pkgs; [ + tree + ]; + hashedPasswordFile = config.sops.secrets."nixos-hashedPassword".path; + openssh.authorizedKeys.keys = [ + vars.adminSshKey + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICMJhrfFayLBG+gWtO6oAvgambw5nWWgztiTFEaaaVRH debian@surface" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGygkCljN6uKpdJbHTOQtn8ZnH+wKXDLAwrDFbLrE/65 nixos@nixos" + ]; + }; }; diff --git a/scripts/proxmox/create-proxmox-resource.sh b/scripts/proxmox/create-proxmox-resource.sh index 6c9ce4e..34d99e6 100755 --- a/scripts/proxmox/create-proxmox-resource.sh +++ b/scripts/proxmox/create-proxmox-resource.sh @@ -302,6 +302,12 @@ platform_prefix="lxc" [[ -z "$cores" ]] && cores="$PROXMOX_DEFAULT_CORES" [[ -z "$memory" ]] && memory="$PROXMOX_DEFAULT_MEMORY_MB" +if [[ "$type" == "vm" && -n "$disk_size" ]]; then + echo "WARNING: --disk-size is LXC-only for create mode and is ignored for VMs." >&2 + echo " VM disk size comes from proxmoxImageSize in variables.nix (currently ${disk_size}G was requested)." >&2 + echo " To expand after creation, use: --modify --vmid --grow-disk " >&2 +fi + # --- discover / resolve the flake target from --host -------------------- # Emits "\t" pairs for every ${platform_prefix}-* flake # target -- the one source both --list and the --host lookup below read @@ -896,7 +902,7 @@ else else importdisk_output="$(ssh "$ssh_target" "${sudo_prefix} qm importdisk ${vmid} ${remote_path} ${storage}")" echo "$importdisk_output" - disk_id="$(echo "$importdisk_output" | grep -oP "(?<=Successfully imported disk as ')[^']+" | sed 's/^unused[0-9]*://')" + disk_id="$(echo "$importdisk_output" | grep -ioP "(?<=successfully imported disk as ')[^']+" | sed 's/^unused[0-9]*://')" if [[ -z "$disk_id" ]]; then echo "ERROR: couldn't parse the imported disk identifier from qm importdisk's output above." >&2 echo "The VM shell (${vmid}) and imported disk both exist -- finish attaching it by hand:" >&2