diff --git a/modules/common/aliases.nix b/modules/common/aliases.nix index 41bddc1..c04cf56 100644 --- a/modules/common/aliases.nix +++ b/modules/common/aliases.nix @@ -17,6 +17,26 @@ let --refresh \ --flake git+https://${vars.lanDomain}/beatzaplenty/nixos.git#$(cat /etc/flake-target) ''; + + # lxc-* hosts pre-seed their SSH host key at build time (see + # modules/platforms/lxc.nix) so sops-nix's .sops.yaml recipient matches on + # first boot -- without it, secrets permanently fail to decrypt (see that + # file's comment for the confirmed failure). That requires --impure plus + # NIXOS_HOST_KEYS_DIR pointing at the repo's host-keys/ dir, same pattern + # docs/auto-installer.md uses for the installer ISO. A function, not a + # shellAlias, since the target name has to interpolate into the middle of + # the flake attribute path, not just append after it. Must be run from the + # repo root, same as every other host-keys/ command in this repo. + buildImageFn = '' + buildImage() { + if [ -z "$1" ]; then + echo "usage: buildImage (e.g. lxc-docker)" >&2 + return 1 + fi + NIXOS_HOST_KEYS_DIR="$(pwd)/host-keys" nix build --impure \ + ".#nixosConfigurations.$1.config.system.build.tarball" + } + ''; in { programs.bash = { @@ -25,5 +45,6 @@ in "Switch-nix" = mySwitchCmd; "Test-nix" = myTestCmd; }; + initExtra = buildImageFn; }; }