diff --git a/modules/ipa/client.nix b/modules/ipa/client.nix index 88f7fea..16a10c9 100644 --- a/modules/ipa/client.nix +++ b/modules/ipa/client.nix @@ -153,6 +153,14 @@ lib.mkIf enabled { createHome = false; }; + # home-manager-.service fails on first enrollment because /home/wayne + # doesn't exist until the user's first login (pam_mkhomedir creates it then). + # ConditionPathExists makes systemd skip the service (exit 0, condition not + # met) instead of failing. After first login the dir exists and subsequent + # rebuilds activate HM normally. + systemd.services."home-manager-${vars.ipaUser}".unitConfig.ConditionPathExists = + "/home/${vars.ipaUser}"; + security.sudo.extraRules = [{ users = [ vars.ipaUser ]; commands = [{ command = "ALL"; options = [ "NOPASSWD" ]; }]; diff --git a/scripts/ipa/create-nixos-ipa-host-account.sh b/scripts/ipa/create-nixos-ipa-host-account.sh index a93b507..635dba2 100755 --- a/scripts/ipa/create-nixos-ipa-host-account.sh +++ b/scripts/ipa/create-nixos-ipa-host-account.sh @@ -81,6 +81,14 @@ if [[ -z "${TARGET}" ]]; then usage 1 fi +# Reject FQDNs passed by mistake — the script appends HOME_DOMAIN itself. +# "nixos.sweet.home" → FQDN would become "nixos.sweet.home.sweet.home". +if [[ "${TARGET}" == *"."* ]]; then + echo "Error: must be the short name (e.g. 'nixos'), not a FQDN." >&2 + echo " The FQDN is derived automatically as ${TARGET}.${HOME_DOMAIN}." >&2 + exit 1 +fi + FQDN="${TARGET}.${HOME_DOMAIN}" KEYTAB_SECRET="${REPO_ROOT}/secrets/${TARGET}.keytab" # Temp path on the domain controller — use a name that won't collide.