From 3589fc31d7e20d0193a40bc352fd7d7459c7165e Mon Sep 17 00:00:00 2001 From: beatzaplenty Date: Tue, 28 Jul 2026 12:53:10 +1000 Subject: [PATCH] feat(ipa): add Home Manager config for IPA primary user Any enrolled host now automatically gets a Home Manager profile for the IPA primary user (vars.ipaUser = "wayne"), covering what IPA doesn't: dotfiles, user-scoped packages (tmux, sshfs), and EDITOR variable. The home directory is pre-created by systemd-tmpfiles so HM activation succeeds on steady-state systems before first login; pam_mkhomedir remains as a fallback for fresh deploys where SSSD hasn't cached the user yet. A minimal users.users stub satisfies NixOS's assertion requirements (isNormalUser + group) that arise because home-manager.useUserPackages creates a users.users entry to install packages to /etc/profiles/per-user/. The stub is shadowed by SSSD at runtime (security.ipa sets passwd: sss files). Co-Authored-By: Claude Sonnet 4.6 --- modules/ipa/client.nix | 44 +++++++++++++++++++++++++++++++++++++++++- variables.nix | 5 +++++ 2 files changed, 48 insertions(+), 1 deletion(-) diff --git a/modules/ipa/client.nix b/modules/ipa/client.nix index 9bfc498..7b6800e 100644 --- a/modules/ipa/client.nix +++ b/modules/ipa/client.nix @@ -19,7 +19,7 @@ # sops -e --input-type binary -i secrets/.keytab # d. Commit secrets/.keytab and the updated .sops.yaml, then deploy. # -# vars dependencies: homeDomain, ipaServer, domainControllerIp +# vars dependencies: homeDomain, ipaServer, domainControllerIp, ipaUser { config, lib, pkgs, vars, ... }: @@ -62,6 +62,11 @@ lib.mkIf enabled { "d /usr/local 0755 root root - -" "d /usr/local/bin 0755 root root - -" "C+ /usr/local/bin/sss_ssh_authorizedkeys 0555 root root - ${pkgs.sssd}/bin/sss_ssh_authorizedkeys" + # Pre-create the IPA user's home dir so Home Manager activation succeeds + # even before their first login. On a fresh system SSSD may not have + # resolved the user yet — tmpfiles warns and skips in that case (non-fatal), + # and pam_mkhomedir covers the first-login path as a fallback. + "d /home/${vars.ipaUser} 0700 ${vars.ipaUser} ${vars.ipaUser} - -" ]; services.openssh.extraConfig = '' @@ -120,4 +125,41 @@ lib.mkIf enabled { ''; }; }; + + # Home Manager config for the IPA primary user, applied on every enrolled + # host. Manages what IPA doesn't: dotfiles, user-scoped packages, session + # variables. Switch-nix/Test-nix/buildImage are system-wide (configuration.nix) + # so they don't need to be repeated here. + # NixOS requires isNormalUser/isSystemUser + group on any entry in + # users.users. HM with useUserPackages = true (set in flake.nix) adds a stub + # entry for each HM user so it can install packages to + # /etc/profiles/per-user//. This definition satisfies those assertions. + # With security.ipa setting "passwd: sss files" in nsswitch, SSSD's IPA entry + # takes priority for NSS lookups — this local stub is only a fallback when + # SSSD is unreachable (at which point auth fails anyway). + users.users.${vars.ipaUser} = { + isNormalUser = true; + group = "users"; + createHome = false; + }; + + # Home Manager config for the IPA primary user, applied on every enrolled + # host. Manages what IPA doesn't: dotfiles, user-scoped packages, session + # variables. Switch-nix/Test-nix/buildImage are system-wide (configuration.nix) + # so they don't need to be repeated here. + # + # homeDirectory uses mkForce because HM's NixOS integration module sets it to + # "/var/empty" for users not found in config.users.users at eval time (SSSD + # users aren't visible there). + home-manager.users.${vars.ipaUser} = { pkgs, ... }: { + home = { + username = vars.ipaUser; + homeDirectory = lib.mkForce "/home/${vars.ipaUser}"; + stateVersion = "26.05"; + packages = with pkgs; [ tmux sshfs ]; + sessionVariables.EDITOR = "nano"; + }; + programs.home-manager.enable = true; + programs.bash.enable = true; + }; } diff --git a/variables.nix b/variables.nix index e438178..45e64b6 100644 --- a/variables.nix +++ b/variables.nix @@ -80,6 +80,11 @@ # one-line change. primaryUser = "nixos"; + # Primary IPA/domain user. Home Manager is configured for this user on every + # IPA-enrolled host (see modules/ipa/client.nix) to manage the environment + # that IPA itself doesn't cover: dotfiles, user packages, session variables. + ipaUser = "wayne"; + # HA file server cluster # LAN IPs (vmbr0 / ens18) — client-facing: iSCSI initiators, NFS, management. # Storage IPs (vmbr1 / ens19) — isolated internal bridge, used for DRBD