diff --git a/modules/common/aliases.nix b/modules/common/aliases.nix index c04cf56..8b4a35c 100644 --- a/modules/common/aliases.nix +++ b/modules/common/aliases.nix @@ -1,50 +1,7 @@ -{ config, pkgs, lib, vars, ... }: +_: -let - # Flake attribute names are now - (e.g. proxmox-docker) - # and no longer match networking.hostName, since a host's hostname stays - # fixed while the platform backing it can change. Each nixosConfiguration - # stamps its own active target name into /etc/flake-target at build time. - mySwitchCmd = '' - sudo nixos-rebuild switch \ - --no-write-lock-file \ - --refresh \ - --flake git+https://${vars.lanDomain}/beatzaplenty/nixos.git#$(cat /etc/flake-target) - ''; - myTestCmd = '' - sudo nixos-rebuild test \ - --no-write-lock-file \ - --refresh \ - --flake git+https://${vars.lanDomain}/beatzaplenty/nixos.git#$(cat /etc/flake-target) - ''; - - # lxc-* hosts pre-seed their SSH host key at build time (see - # modules/platforms/lxc.nix) so sops-nix's .sops.yaml recipient matches on - # first boot -- without it, secrets permanently fail to decrypt (see that - # file's comment for the confirmed failure). That requires --impure plus - # NIXOS_HOST_KEYS_DIR pointing at the repo's host-keys/ dir, same pattern - # docs/auto-installer.md uses for the installer ISO. A function, not a - # shellAlias, since the target name has to interpolate into the middle of - # the flake attribute path, not just append after it. Must be run from the - # repo root, same as every other host-keys/ command in this repo. - buildImageFn = '' - buildImage() { - if [ -z "$1" ]; then - echo "usage: buildImage (e.g. lxc-docker)" >&2 - return 1 - fi - NIXOS_HOST_KEYS_DIR="$(pwd)/host-keys" nix build --impure \ - ".#nixosConfigurations.$1.config.system.build.tarball" - } - ''; -in { - programs.bash = { - enable = true; - shellAliases = { - "Switch-nix" = mySwitchCmd; - "Test-nix" = myTestCmd; - }; - initExtra = buildImageFn; - }; + # Switch-nix, Test-nix, and buildImage are defined system-wide in + # modules/common/configuration.nix so all users (including IPA accounts) + # get them. Add any Home-Manager-only per-user shell config here. } diff --git a/modules/common/configuration.nix b/modules/common/configuration.nix index 68fa68e..0144331 100644 --- a/modules/common/configuration.nix +++ b/modules/common/configuration.nix @@ -1,5 +1,29 @@ { config, lib, pkgs, vars, ... }: +let + switchCmd = '' + sudo nixos-rebuild switch \ + --no-write-lock-file \ + --refresh \ + --flake git+https://${vars.lanDomain}/beatzaplenty/nixos.git#$(cat /etc/flake-target) + ''; + testCmd = '' + sudo nixos-rebuild test \ + --no-write-lock-file \ + --refresh \ + --flake git+https://${vars.lanDomain}/beatzaplenty/nixos.git#$(cat /etc/flake-target) + ''; + buildImageFn = '' + buildImage() { + if [ -z "$1" ]; then + echo "usage: buildImage (e.g. lxc-docker)" >&2 + return 1 + fi + NIXOS_HOST_KEYS_DIR="$(pwd)/host-keys" nix build --impure \ + ".#nixosConfigurations.$1.config.system.build.tarball" + } + ''; +in { imports = [ @@ -8,6 +32,16 @@ ./set-locale.nix ../ipa/client.nix ]; + + # System-wide shell config so all users (including IPA accounts) get the + # same management aliases as the local nixos user's Home Manager provides. + programs.bash = { + shellAliases = { + "Switch-nix" = switchCmd; + "Test-nix" = testCmd; + }; + interactiveShellInit = buildImageFn; + }; # Use the GRUB 2 boot loader. # boot.loader.grub.enable = true; #boot.loader.grub.device = "/dev/sda"; # or "nodev" for efi only