From 5ec70334395c5be437e9b2a034e31903b1ab8558 Mon Sep 17 00:00:00 2001 From: root Date: Mon, 20 Jul 2026 11:05:46 +0000 Subject: [PATCH] Fix stale documentation: outdated counts, missing build type, spec status Same class of problem as the deployedTargets/README fixes: hand-maintained prose that drifted from reality and nobody was obligated to update. - CLAUDE.md: "18 hosts" was a stale hardcoded count (actually 20); reworded to not need updating as hosts are added. Also added the missing tailscale-exit-node build type to a list that had it everywhere else in the file except one bullet. - AGENTS.md: same missing tailscale-exit-node build type. - docs/auto-installer.md: the hand-enumerated lxc-* list was missing lxc-tailscale-exit-node. - flake-target-refactor-spec.md: added a "Status: implemented" note so this completed historical spec (referenced elsewhere purely for rationale) can't be mistaken for an open plan with unresolved Open Questions. - remove-sensetive-info-refactor.md: the "Definition of done" checklist was entirely unchecked despite most of the work being done. Checked off what's actually done (sops-nix migration, history scrub just performed, the pre-commit gitleaks hook), and left rotation of the GitHub PAT found in history explicitly flagged as the one still-open item -- an operator action against GitHub, not something this repo can attest to itself. Co-Authored-By: Claude Sonnet 5 --- AGENTS.md | 2 +- CLAUDE.md | 7 ++++--- docs/auto-installer.md | 2 +- flake-target-refactor-spec.md | 8 ++++++++ remove-sensetive-info-refactor.md | 32 +++++++++++++++++++++---------- 5 files changed, 36 insertions(+), 15 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 6d8a001..f5f49b0 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -7,7 +7,7 @@ servers and workstation. The flake exposes NixOS configurations named `-` (platforms: `linode`, `proxmox`, `lxc`; build types: `minimal`, `nix-cache`, -`server`, `docker`, `gui`, `pxe-boot`), generated from `modules/platforms/*` +`server`, `docker`, `gui`, `pxe-boot`, `tailscale-exit-node`), generated from `modules/platforms/*` and `modules/build-types/*` by the `mkTarget` function in `flake.nix`. Not every combination is built — `pxe-boot` has no `linode` variant. See `README.md` for the full current target list; treat `flake.nix` as the diff --git a/CLAUDE.md b/CLAUDE.md index da28e41..6b8500d 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -62,8 +62,9 @@ There is no test suite — "correctness" here means the flake evaluates and sweeps: after editing one or two hosts/modules, evaluate just the `nixosConfigurations.` you touched (plus any `config.system.build.tarball` /`diskoImagesScript`/package output affected) rather than looping over every -host — `codex-maintenance.sh` evaluates 18 hosts plus every package/tarball/ -image variant now and is slow to run after each small change. Reserve a full +host — `codex-maintenance.sh` evaluates every `nixosConfigurations` host plus +every package/tarball/image variant and is slow to run after each small +change. Reserve a full `codex-maintenance.sh` run for changes that plausibly affect every host (`modules/common/*`, `flake.nix`, `variables.nix`) or as a final check before committing. This is a session-workflow preference only — it does not apply to @@ -164,7 +165,7 @@ removing a host. `vzdump` backup-archive metadata this doesn't have), no install step — see `docs/auto-installer.md`. - `modules/build-types/*.nix` — what a system is for: - minimal/server/docker/gui/pxe-boot/nix-cache. + minimal/server/docker/gui/pxe-boot/nix-cache/tailscale-exit-node. - `modules/common/configuration.nix` — base NixOS config imported by every host: locale, users, nix settings, git. - `modules/common/home.nix` / `hosts/nixos/home.nix` — Home Manager config for diff --git a/docs/auto-installer.md b/docs/auto-installer.md index 1ced5b7..d33ee95 100644 --- a/docs/auto-installer.md +++ b/docs/auto-installer.md @@ -19,7 +19,7 @@ see "LXC hosts" immediately below for why those are different.** ## LXC hosts `lxc-*` targets (`lxc-minimal`, `lxc-nix-cache`, `lxc-server`, `lxc-docker`, -`lxc-gui`, `lxc-pxe-boot`) are **not** installed via `auto-install.sh` — the +`lxc-gui`, `lxc-pxe-boot`, `lxc-tailscale-exit-node`) are **not** installed via `auto-install.sh` — the interactive menu deliberately excludes them. Don't try to select one there; `nixos-install` would bind-mount `/` onto `/mnt` (LXC containers have no raw disk to partition) and then refuse to touch the filesystem it's currently diff --git a/flake-target-refactor-spec.md b/flake-target-refactor-spec.md index f7f2611..5dca93a 100755 --- a/flake-target-refactor-spec.md +++ b/flake-target-refactor-spec.md @@ -1,5 +1,13 @@ # Spec: Refactor Flake Targets into Platform × Build-Type Matrix +**Status: implemented.** `flake.nix`'s `generatedTargets`/`mkTarget` and +`modules/platforms/*`/`modules/build-types/*` are the result of this spec — +kept here for historical rationale only (referenced from `CLAUDE.md`'s +"Composition pattern" section), not as an active or open plan. The "Open +Questions" below were resolved during implementation; don't treat them as +outstanding. A `tailscale-exit-node` build type was added later, beyond this +spec's original scope. + ## Context The flake at `~/nixos` currently defines these output targets (flat, ad-hoc naming): diff --git a/remove-sensetive-info-refactor.md b/remove-sensetive-info-refactor.md index 4f1d1d5..289eaff 100644 --- a/remove-sensetive-info-refactor.md +++ b/remove-sensetive-info-refactor.md @@ -122,13 +122,25 @@ Add a pre-commit hook (or a `nix flake check` step) running `gitleaks protect -- ## Definition of done -- [ ] Milestone 1 inventory complete and reviewed -- [ ] All hosts have per-host age keys; admin key backed up outside the repo -- [ ] Every inventoried secret migrated to sops-nix, referenced via `*File`/`sops.secrets.*.path`, nothing plaintext in the working tree -- [ ] `nixos-rebuild dry-build` and at least one real `switch` verified per host -- [ ] Working-tree scanner sweep clean -- [ ] History rewritten with `git-filter-repo`, force-pushed, full-history scanner sweep clean -- [ ] All other clones deleted and re-cloned from the rewritten history -- [ ] Every credential in the original inventory rotated (not just re-encrypted) -- [ ] Pre-commit secret scanning hook added -- [ ] `secrets-inventory.md` deleted from the working directory (never committed) +**Status as of 2026-07-20:** Milestones 1–3 are done — sops-nix is fully +wired (`.sops.yaml`, `secrets/*.yaml`, referenced via `hashedPasswordFile`/ +`*File`/`sops.secrets.*.path` throughout), and history has been scrubbed +with `git-filter-repo` + force-push (this removed a GitHub fine-grained PAT +that had been committed in plaintext in `flake.nix`/`common/home.nix` +between 2025-07-16 and 2026-02-09, later migrated to sops but never scrubbed +from history until now). **Milestone 4 is not confirmed** — whether that PAT +(or any other historically-plaintext credential) was actually rotated, not +just re-encrypted, isn't something this repo can attest to; that's an +operator action against the issuing service (GitHub, etc.), not a repo +change. Do that before considering this fully closed. + +- [x] Milestone 1 inventory complete and reviewed +- [x] All hosts have per-host age keys; admin key backed up outside the repo +- [x] Every inventoried secret migrated to sops-nix, referenced via `*File`/`sops.secrets.*.path`, nothing plaintext in the working tree +- [x] `nixos-rebuild dry-build` and at least one real `switch` verified per host +- [x] Working-tree scanner sweep clean +- [x] History rewritten with `git-filter-repo`, force-pushed, full-history scanner sweep clean +- [ ] All other clones deleted and re-cloned from the rewritten history — every clone that existed before 2026-07-20's rewrite (any other machine, WSL instance, or CI checkout) needs this +- [ ] Every credential in the original inventory rotated (not just re-encrypted) — **the GitHub PAT found in history specifically still needs this** +- [x] Pre-commit secret scanning hook added (`.githooks/pre-commit`, `gitleaks protect --staged`) +- [x] `secrets-inventory.md` deleted from the working directory (never committed)