Archived
Deduplicate reusable shell code in scripts/ into scripts/lib/
Check NixOS configurations / eval-hosts (pull_request) Failing after 11m29s
Check NixOS configurations / eval-hosts (pull_request) Failing after 11m29s
Three chunks of copy-pasted logic were drifting across scripts/*.sh: - codex-setup.sh and codex-maintenance.sh each carried an identical NIX_CONFIG bootstrap + ensure_nix_profile() -> scripts/lib/nix-bootstrap.sh - sync-host-keys.sh and prepare-host-key.sh each ran the same ssh-keygen/ssh-to-age nix-shell invocations -> scripts/lib/ssh-host-keys.sh (prepare-host-key.sh now also calls env.sh's nix_extra_opts before using them, closing a gap where it alone skipped the nix-cache reachability check env.sh exists for) - the "list nixosConfigurations attrNames" / "get one target's hostName" nix eval pattern was repeated across codex-setup.sh, codex-maintenance.sh, sync-host-keys.sh and create-proxmox-resource.sh (the latter twice, in its own --list and --host lookup) -> scripts/lib/nix-eval.sh, which also centralizes the --no-use-registries --no-accept-flake-config flag pair used on every such call Verified against the real flake/node config (nix is available here): create-proxmox-resource.sh --list for both --type lxc/vm, a full --dry-run create, and prepare-host-key.sh generating and cleaning up a real key/age-pubkey pair. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -31,6 +31,10 @@ editor="${repo_root}/scripts/lib/sync-host-keys-edit-sops.py"
|
||||
|
||||
# shellcheck source=env.sh
|
||||
source "${repo_root}/scripts/env.sh"
|
||||
# shellcheck source=lib/nix-eval.sh
|
||||
source "${repo_root}/scripts/lib/nix-eval.sh"
|
||||
# shellcheck source=lib/ssh-host-keys.sh
|
||||
source "${repo_root}/scripts/lib/ssh-host-keys.sh"
|
||||
|
||||
mkdir -p "$keydir"
|
||||
|
||||
@@ -118,12 +122,10 @@ EOF
|
||||
}
|
||||
|
||||
discover_targets() {
|
||||
nix eval --json --no-use-registries --no-accept-flake-config \
|
||||
"${repo_root}#nixosConfigurations" --apply builtins.attrNames \
|
||||
| jq -r '.[] | select(. != "installer")'
|
||||
# installer is the one nixosConfigurations target that doesn't import
|
||||
# sops-nix at all (see CLAUDE.md's "Security Notes" -- hardcoded login
|
||||
# password instead) -- config.sops.secrets doesn't exist for it.
|
||||
list_flake_targets "$repo_root" | grep -v '^installer$'
|
||||
}
|
||||
|
||||
locally_managed_hosts() {
|
||||
@@ -159,7 +161,7 @@ queue_host_sync() {
|
||||
echo "[dry-run] ${host}: would generate host key"
|
||||
else
|
||||
echo "==> ${host}: generating host key"
|
||||
nix-shell "${NIX_OPTS[@]}" -p openssh --run "ssh-keygen -t ed25519 -N '' -C '${host}' -f '${keyfile}'" >/dev/null
|
||||
generate_host_ed25519_key "$host" "$keyfile"
|
||||
fi
|
||||
else
|
||||
echo "==> ${host}: host key already present"
|
||||
@@ -170,7 +172,7 @@ queue_host_sync() {
|
||||
if [[ "$dry_run" -eq 1 ]]; then
|
||||
age_pub="dry-run-placeholder-not-a-real-key"
|
||||
else
|
||||
age_pub="$(nix-shell "${NIX_OPTS[@]}" -p ssh-to-age --run "ssh-to-age -i '${keyfile}.pub'")"
|
||||
age_pub="$(ssh_pubkey_to_age "${keyfile}.pub")"
|
||||
fi
|
||||
add_keys_json="$(jq --arg host "$host" --arg key "$age_pub" \
|
||||
'. + [{host: $host, age_key: $key}]' <<<"$add_keys_json")"
|
||||
|
||||
Reference in New Issue
Block a user