Archived
Reorganize scripts/ into secrets/, proxmox/, and lib/ subfolders
Check NixOS configurations / eval-hosts (pull_request) Failing after 30m6s
Check NixOS configurations / eval-hosts (pull_request) Failing after 30m6s
scripts/ had grown to 10 top-level scripts covering three distinct concerns (sops/age + SSH host-key management, Proxmox deployment, and repo-wide bootstrap/CI) with no grouping. Move the key-management scripts (backup-admin-key.sh, rotate-admin-key.sh, prepare-host-key.sh, sync-host-keys.sh) into scripts/secrets/, and the Proxmox scripts (create-proxmox-resource.sh, configure-nix-cache-client.sh) into scripts/proxmox/; leave env.sh, codex-setup.sh, codex-maintenance.sh, and bump-nixpkgs-release.sh at the top level (frequently hand-typed or pure shared config) and scripts/lib/ as-is. Updates every cross-reference: each moved script's repo_root computation (now one directory deeper), shellcheck source= directives, inter-script paths (create-proxmox-resource.sh's call into sync-host-keys.sh and its remote bootstrap of configure-nix-cache-client.sh on the Proxmox node), and every doc/module mention (CLAUDE.md's Scripts section reorganized to match, README.md, docs/auto-installer.md, docs/proxmox-images.md, modules/installer/common.nix, modules/platforms/lxc.nix). CI workflows need no change -- they only invoke codex-maintenance.sh, which didn't move. Verified via bash -n, shellcheck (no new warnings beyond the pre-existing SC1091/SC2029/SC2095 baseline), and live dry-runs of sync-host-keys.sh --all and create-proxmox-resource.sh --list from their new paths. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Executable
+83
@@ -0,0 +1,83 @@
|
||||
#!/usr/bin/env bash
|
||||
# Generates a new machine's SSH host key by an arbitrary name, before it
|
||||
# necessarily has a flake target yet -- prints the .sops.yaml snippet to
|
||||
# add by hand. For any host that already has a flake target,
|
||||
# scripts/secrets/sync-host-keys.sh <target> does this same job plus the
|
||||
# .sops.yaml/key_groups registration and re-encryption automatically; use
|
||||
# this script only to pre-generate a key ahead of adding the flake target
|
||||
# itself.
|
||||
#
|
||||
# Why a host key is needed at all: sops-nix derives each host's decryption key from
|
||||
# its own /etc/ssh/ssh_host_ed25519_key at *activation* time, but that
|
||||
# activation runs before systemd would otherwise generate this key on
|
||||
# first boot (sshd-keygen is a normal systemd service gated behind
|
||||
# multi-user.target; activation scripts run earlier than that). Without
|
||||
# pre-seeding, secrets — including the root/nixos login password — fail
|
||||
# to decrypt on the machine's very first boot.
|
||||
#
|
||||
# This script only touches your admin workstation and this repo's
|
||||
# .sops.yaml (it never contacts the target machine). Run it, follow the
|
||||
# printed next steps, then use the resulting key with the auto-install.sh
|
||||
# prompt (see modules/installer/common.nix) when you actually install the
|
||||
# new machine.
|
||||
set -euo pipefail
|
||||
|
||||
repo_root="$(cd "$(dirname "$0")/../.." && pwd)"
|
||||
# shellcheck source=../env.sh
|
||||
source "${repo_root}/scripts/env.sh"
|
||||
# shellcheck source=../lib/ssh-host-keys.sh
|
||||
source "${repo_root}/scripts/lib/ssh-host-keys.sh"
|
||||
|
||||
hostname="${1:?usage: scripts/secrets/prepare-host-key.sh <hostname>}"
|
||||
sops_yaml="${repo_root}/.sops.yaml"
|
||||
|
||||
if [[ ! -f "$sops_yaml" ]]; then
|
||||
echo "ERROR: $sops_yaml not found — is this script still under nixos/scripts/?" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
keydir="${repo_root}/host-keys"
|
||||
mkdir -p "$keydir"
|
||||
keyfile="${keydir}/${hostname}_ssh_host_ed25519_key"
|
||||
|
||||
if [[ -f "$keyfile" ]]; then
|
||||
echo "ERROR: $keyfile already exists. Remove it first if you want to regenerate." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
nix_extra_opts
|
||||
generate_host_ed25519_key "$hostname" "$keyfile"
|
||||
|
||||
age_pub="$(ssh_pubkey_to_age "${keyfile}.pub")"
|
||||
|
||||
cat <<EOF
|
||||
|
||||
Generated: ${keyfile}(.pub)
|
||||
|
||||
=== 1. Add this line under keys: in ${sops_yaml} ===
|
||||
- &${hostname} ${age_pub}
|
||||
|
||||
=== 2. Add *${hostname} to whichever creation_rules key_groups this host needs ===
|
||||
(e.g. secrets/common.yaml always; add a per-host secrets/${hostname}.yaml
|
||||
block too if this host will get its own secrets, same pattern as
|
||||
nix-cache/server.)
|
||||
|
||||
=== 3. Re-encrypt every secrets file you just added it to ===
|
||||
nix-shell -p sops --run 'sops updatekeys ${repo_root}/secrets/common.yaml'
|
||||
|
||||
=== 4. Commit + push this repo so the flake build picks up the new recipient ===
|
||||
|
||||
=== 5. Get the key onto the installer, one of two ways ===
|
||||
a) Rebuild the installer image with all host-keys/ baked in (see
|
||||
docs/auto-installer.md):
|
||||
NIXOS_HOST_KEYS_DIR="${keydir}" nix build .#iso --impure
|
||||
(or .#pxe — --impure is required since host-keys/ is gitignored and
|
||||
flakes can't see it otherwise)
|
||||
|
||||
b) Or, for an image already built without keys, scp it in after boot:
|
||||
scp ${keyfile}{,.pub} root@<target-ip>:/root/host-keys/
|
||||
|
||||
Then continue with /etc/auto-install.sh as normal — it checks
|
||||
/etc/host-keys (baked in) before /root/host-keys (scp'd) and installs
|
||||
whichever it finds before running nixos-install.
|
||||
EOF
|
||||
Reference in New Issue
Block a user