From e92aab617f36248d9a6f6342196aee9a32b93738 Mon Sep 17 00:00:00 2001 From: beatzaplenty Date: Tue, 21 Jul 2026 22:45:25 +0000 Subject: [PATCH] Rename PXE installer menu entry, add vanilla NixOS minimal netboot entry MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The iPXE menu's "nixos" entry actually chain-loads this flake's own custom auto-installer image, not a stock NixOS image — rename it to "auto-installer" (label "NixOS Auto-Installer") so the menu says what it boots, and set networking.hostName on netbootSystem to match, so the generated system name (nixos-system-auto-installer-*) and staged directory (/srv/pxe/http/auto-installer) agree with the menu entry too. Add a second, genuinely vanilla NixOS minimal netboot image (netbootMinimalSystem in flake.nix — nixpkgs' netboot-minimal.nix on its own, none of modules/installer/common.nix's auto-installer wiring), built from source the same way as the auto-installer image and exposed as packages.x86_64-linux.pxe-minimal. Staged and menu-wired the same way, as "nixos-minimal" (item, hostname, and directory all matching). modules/pxe-boot/stage-installer-artifacts.nix is generalized to stage both images via a shared rule-builder instead of one hardcoded set of paths. Verified: nix eval confirms both images' config.system.name matches their menu entry/directory names, the pxe-boot host itself builds clean with the new menu.ipxe, and the new pxe-minimal image was booted directly under QEMU (kernel+initrd, no KVM) to a working login shell with hostname nixos-minimal, no hang. --- docs/auto-installer.md | 6 ++- docs/pxe-boot.md | 51 +++++++++++++------ flake.nix | 39 +++++++++++++- modules/build-types/pxe-boot.nix | 13 +++-- .../pxe-boot/stage-installer-artifacts.nix | 37 +++++++++----- 5 files changed, 110 insertions(+), 36 deletions(-) diff --git a/docs/auto-installer.md b/docs/auto-installer.md index 8e92f03..7c5c638 100644 --- a/docs/auto-installer.md +++ b/docs/auto-installer.md @@ -150,7 +150,11 @@ use case. The `pxe` variant is also built automatically as part of the `pxe-boot` host itself (`modules/pxe-boot/stage-installer-artifacts.nix`) and served over -iPXE — see `docs/pxe-boot.md`. +iPXE as the menu's "NixOS Auto-Installer" entry — see `docs/pxe-boot.md`. +That same host also builds and serves `packages.x86_64-linux.pxe-minimal`, +a vanilla NixOS minimal netboot image with none of this auto-installer's +wiring, as a separate "NixOS Minimal" menu entry — also documented in +`docs/pxe-boot.md`, not covered further here since it's not this installer. ## Host keys diff --git a/docs/pxe-boot.md b/docs/pxe-boot.md index 7529768..5d1fe18 100644 --- a/docs/pxe-boot.md +++ b/docs/pxe-boot.md @@ -1,9 +1,10 @@ # pxe-boot -The `pxe-boot` host serves HTTP boot assets for iPXE clients — including a -self-staged copy of this flake's own auto-installer netboot image, see -`docs/auto-installer.md` for what that image actually is and does once -booted. +The `pxe-boot` host serves HTTP boot assets for iPXE clients — including +self-staged copies of both this flake's own auto-installer netboot image +(see `docs/auto-installer.md` for what that image actually is and does once +booted) and a vanilla, unmodified NixOS minimal netboot image for plain +rescue/inspection use. ## Host Role @@ -28,7 +29,8 @@ The host creates these directories with systemd tmpfiles: /srv/pxe /srv/pxe/http /srv/pxe/http/images -/srv/pxe/http/nixos +/srv/pxe/http/auto-installer +/srv/pxe/http/nixos-minimal /srv/pxe/http/systemrescue /srv/pxe/http/ubuntu /srv/pxe/http/rescue @@ -37,7 +39,7 @@ The host creates these directories with systemd tmpfiles: Mount shared image storage under `/srv/pxe/http`, preferably `/srv/pxe/http/images` unless a menu entry expects files in a specific -directory such as `/srv/pxe/http/nixos`. +directory such as `/srv/pxe/http/auto-installer`. The HTTP iPXE chain is: @@ -50,20 +52,37 @@ undionly.kpxe or ipxe.efi The generated menu currently exposes entries for: -- NixOS installer +- NixOS Auto-Installer +- NixOS Minimal - SystemRescue environment - iPXE shell - Reboot -The NixOS installer entry chain-loads `/srv/pxe/http/nixos/netboot.ipxe`, -which is nixpkgs' own generated netboot iPXE script (correct `init=`/`initrd=` -kernel parameters included) rather than a hand-rolled boot line — that script -in turn expects its kernel/initrd siblings in the same directory. All three -files (`bzImage`, `initrd`, `netboot.ipxe`) are built from this flake's own -`modules/installer/iso.nix` netboot image (the same one `nix build .#pxe` -produces) and staged automatically by -`modules/pxe-boot/stage-installer-artifacts.nix` via `systemd.tmpfiles.rules` -— no manual operator step required. +Both NixOS entries chain-load a `netboot.ipxe` staged into their own +directory (`/srv/pxe/http/auto-installer/netboot.ipxe` and +`/srv/pxe/http/nixos-minimal/netboot.ipxe`), each nixpkgs' own generated +netboot iPXE script (correct `init=`/`initrd=` kernel parameters included) +rather than a hand-rolled boot line — that script in turn expects its +kernel/initrd siblings in the same directory. Each directory's three files +(`bzImage`, `initrd`, `netboot.ipxe`) are built from source and staged +automatically by `modules/pxe-boot/stage-installer-artifacts.nix` via +`systemd.tmpfiles.rules` — no manual operator step required: + +- `auto-installer` is this flake's own `netbootSystem` (`flake.nix`) — the + same auto-installer image `nix build .#pxe` produces. See + `docs/auto-installer.md`. +- `nixos-minimal` is `netbootMinimalSystem` (`flake.nix`) — nixpkgs' + `netboot-minimal.nix` composed on its own, with none of this flake's + auto-installer wiring (no `common.nix`, no `auto-install.sh`, no baked + host keys or custom users). Same `nix build .#pxe-minimal` mechanism as + the auto-installer image, just a different module composition. Useful + as a plain rescue/inspection shell that doesn't assume anything about + this flake. + +Both images set `networking.hostName` to match their menu entry/staged +directory name (`auto-installer` / `nixos-minimal`), so each one's +generated system name (`nixos-system--*`) is self-describing rather +than the nixpkgs default of `nixos-system-nixos-*` for both. The SystemRescue entry expects the source ISO at: diff --git a/flake.nix b/flake.nix index 8549f40..85a9a9c 100644 --- a/flake.nix +++ b/flake.nix @@ -65,7 +65,7 @@ # file without a same-option circular dependency (a module # contributing to environment.etc can't read the merged # environment.etc it's itself contributing to). - specialArgs = { inherit inputs vars netbootSystem flakeTarget; }; + specialArgs = { inherit inputs vars netbootSystem netbootMinimalSystem flakeTarget; }; }; # Generated platform x build-type matrix. pxe-boot has no linode @@ -133,6 +133,12 @@ # profiles/installation-device.nix independently, so common.nix's # initialHashedPassword override (which assumes that profile is # present) still applies correctly without iso.nix in the mix. + # + # networking.hostName is set explicitly (rather than left at nixpkgs' + # own "nixos" default) so this image's generated system name + # (nixos-system-auto-installer-*) matches its iPXE menu entry — + # see modules/build-types/pxe-boot.nix's :auto-installer item — and + # its staged directory, /srv/pxe/http/auto-installer. netbootSystem = nixpkgs.lib.nixosSystem { inherit system; modules = [ @@ -142,10 +148,32 @@ (modulesPath + "/installer/netboot/netboot-minimal.nix") ]; }) + { networking.hostName = "auto-installer"; } ]; specialArgs = { inherit vars; }; }; + # A genuinely vanilla NixOS minimal netboot image: nixpkgs' + # netboot-minimal.nix on its own, with none of this flake's + # auto-installer wiring (no common.nix — no auto-install.sh, no + # baked host keys, no custom users/passwords). Built from source via + # the same nixosSystem + netboot-minimal.nix path as netbootSystem + # above, so both go through an identical build mechanism; the only + # difference is what's composed in. hostName again matches this + # image's iPXE menu entry (:nixos-minimal) and staged directory + # (/srv/pxe/http/nixos-minimal). + netbootMinimalSystem = nixpkgs.lib.nixosSystem { + inherit system; + modules = [ + ({ modulesPath, ... }: { + imports = [ + (modulesPath + "/installer/netboot/netboot-minimal.nix") + ]; + }) + { networking.hostName = "nixos-minimal"; } + ]; + }; + in { @@ -167,6 +195,15 @@ { name = "initrd"; path = netbootSystem.config.system.build.netbootRamdisk; } { name = "kernel"; path = netbootSystem.config.system.build.kernel; } ]; + + # Vanilla NixOS minimal netboot bundle — see netbootMinimalSystem + # above. Staged onto the pxe-boot host alongside packages.pxe by + # modules/pxe-boot/stage-installer-artifacts.nix. + pxe-minimal = pkgs.linkFarm "pxe-minimal" [ + { name = "netboot.ipxe"; path = netbootMinimalSystem.config.system.build.netbootIpxeScript; } + { name = "initrd"; path = netbootMinimalSystem.config.system.build.netbootRamdisk; } + { name = "kernel"; path = netbootMinimalSystem.config.system.build.kernel; } + ]; }; }; } diff --git a/modules/build-types/pxe-boot.nix b/modules/build-types/pxe-boot.nix index 66c194d..4dcd88b 100644 --- a/modules/build-types/pxe-boot.nix +++ b/modules/build-types/pxe-boot.nix @@ -68,15 +68,19 @@ let set base ${pxeBaseUrl} menu PXE Boot Menu - item nixos NixOS Installer + item auto-installer NixOS Auto-Installer + item nixos-minimal NixOS Minimal item rescue Rescue Environment item shell iPXE Shell item reboot Reboot choose target && goto ''${target} - :nixos - chain ''${base}/nixos/netboot.ipxe + :auto-installer + chain ''${base}/auto-installer/netboot.ipxe + + :nixos-minimal + chain ''${base}/nixos-minimal/netboot.ipxe :rescue chain ''${base}/systemrescue.ipxe @@ -129,7 +133,8 @@ in "d ${pxeRoot} 0755 root root -" "d ${httpRoot} 0755 root root -" "d ${httpRoot}/images 0755 root root -" - "d ${httpRoot}/nixos 0755 root root -" + "d ${httpRoot}/auto-installer 0755 root root -" + "d ${httpRoot}/nixos-minimal 0755 root root -" "d ${httpRoot}/systemrescue 0755 root root -" "d ${httpRoot}/ubuntu 0755 root root -" "d ${httpRoot}/rescue 0755 root root -" diff --git a/modules/pxe-boot/stage-installer-artifacts.nix b/modules/pxe-boot/stage-installer-artifacts.nix index 4231306..1911a3c 100644 --- a/modules/pxe-boot/stage-installer-artifacts.nix +++ b/modules/pxe-boot/stage-installer-artifacts.nix @@ -1,23 +1,32 @@ -{ netbootSystem, ... }: +{ netbootSystem, netbootMinimalSystem, ... }: let # config.system.build.kernel and .netbootRamdisk are directories, not the # files themselves — nixpkgs' own system.build.kexecTree does the same # ${...}/ dereference for the same reason. - inherit (netbootSystem.config.system.boot.loader) kernelFile; + mkStageRules = { dirName, system }: + let + inherit (system.config.system.boot.loader) kernelFile; + dir = "/srv/pxe/http/${dirName}"; + in + [ + # Declared here too (not just in build-types/pxe-boot.nix) so this + # module's C+ rules don't depend on cross-module list-merge ordering — + # tmpfiles' C type needs the target directory to already exist. + "d ${dir} 0755 root root -" + "C+ ${dir}/${kernelFile} 0644 root root - ${system.config.system.build.kernel}/${kernelFile}" + "C+ ${dir}/initrd 0644 root root - ${system.config.system.build.netbootRamdisk}/initrd" + "C+ ${dir}/netboot.ipxe 0644 root root - ${system.config.system.build.netbootIpxeScript}/netboot.ipxe" + ]; in { # Builds this flake's own installer netboot image (the same one - # `nix build .#pxe` produces) and stages it where menu.ipxe's :nixos - # entry expects it, so the pxe-boot host is self-contained — no manual - # operator step to populate /srv/pxe/http/nixos after deploy. - systemd.tmpfiles.rules = [ - # Declared here too (not just in build-types/pxe-boot.nix) so this - # module's C+ rules don't depend on cross-module list-merge ordering — - # tmpfiles' C type needs the target directory to already exist. - "d /srv/pxe/http/nixos 0755 root root -" - "C+ /srv/pxe/http/nixos/${kernelFile} 0644 root root - ${netbootSystem.config.system.build.kernel}/${kernelFile}" - "C+ /srv/pxe/http/nixos/initrd 0644 root root - ${netbootSystem.config.system.build.netbootRamdisk}/initrd" - "C+ /srv/pxe/http/nixos/netboot.ipxe 0644 root root - ${netbootSystem.config.system.build.netbootIpxeScript}/netboot.ipxe" - ]; + # `nix build .#pxe` produces) plus the vanilla NixOS minimal netboot image + # (`nix build .#pxe-minimal`), and stages both where menu.ipxe's + # :auto-installer / :nixos-minimal entries expect them, so the pxe-boot + # host is self-contained — no manual operator step to populate + # /srv/pxe/http after deploy. + systemd.tmpfiles.rules = + mkStageRules { dirName = "auto-installer"; system = netbootSystem; } + ++ mkStageRules { dirName = "nixos-minimal"; system = netbootMinimalSystem; }; }