{ config, lib, pkgs, inputs, vars, ... }: let pxeRoot = "/srv/pxe"; httpRoot = "${pxeRoot}/http"; tftpRoot = "${pxeRoot}/tftp"; pxeBaseUrl = "http://${vars.pxeServerIp}"; bootIpxe = pkgs.writeText "boot.ipxe" '' #!ipxe dhcp echo Booting from PXE server... chain ${pxeBaseUrl}/menu.ipxe ''; autoexecIpxe = pkgs.writeText "autoexec.ipxe" '' #!ipxe dhcp chain ${pxeBaseUrl}/boot.ipxe ''; debianRelease = "bookworm"; debianMirror = "https://deb.debian.org/debian"; debianNetbootBase = "${debianMirror}/dists/${debianRelease}/main/installer-amd64/current/images/netboot/debian-installer/amd64"; debianIpxe = pkgs.writeText "debian.ipxe" '' #!ipxe set base ${pxeBaseUrl} kernel ''${base}/debian/linux initrd ''${base}/debian/initrd.gz boot ''; fetchDebianNetboot = pkgs.writeShellScript "fetch-debian-netboot" '' set -eu dir="${httpRoot}/debian" mirror="${debianNetbootBase}" if [ -f "$dir/linux" ] && [ -f "$dir/initrd.gz" ]; then echo "Debian ${debianRelease} netboot files already present; skipping download." exit 0 fi echo "Downloading Debian ${debianRelease} netboot kernel and initrd from $mirror ..." ${pkgs.curl}/bin/curl -fsSL -o "$dir/linux.tmp" "$mirror/linux" ${pkgs.curl}/bin/curl -fsSL -o "$dir/initrd.gz.tmp" "$mirror/initrd.gz" mv "$dir/linux.tmp" "$dir/linux" mv "$dir/initrd.gz.tmp" "$dir/initrd.gz" echo "Debian ${debianRelease} netboot files staged." ''; systemRescueIpxe = pkgs.writeText "systemrescue.ipxe" '' #!ipxe set base ${pxeBaseUrl} kernel ''${base}/systemrescue/sysresccd/boot/x86_64/vmlinuz initrd=sysresccd.img archisobasedir=sysresccd archiso_http_srv=''${base}/systemrescue/ ip=dhcp checksum initrd ''${base}/systemrescue/sysresccd/boot/x86_64/sysresccd.img sysresccd.img boot ''; stageSystemRescue = pkgs.writeShellScript "stage-systemrescue" '' set -eu iso="${httpRoot}/images/systemrescue.iso" staged="${httpRoot}/systemrescue" tmp="${httpRoot}/.systemrescue.tmp" previous="${httpRoot}/.systemrescue.previous" if [ ! -e "$iso" ]; then echo "SystemRescue ISO not found at $iso; skipping staging." exit 0 fi rm -rf "$tmp" mkdir -p "$tmp" ${pkgs.libarchive}/bin/bsdtar -C "$tmp" -xf "$iso" test -f "$tmp/sysresccd/boot/x86_64/vmlinuz" test -f "$tmp/sysresccd/boot/x86_64/sysresccd.img" chmod -R a+rX "$tmp" rm -rf "$previous" if [ -e "$staged" ]; then mv "$staged" "$previous" fi mv "$tmp" "$staged" rm -rf "$previous" ''; menuIpxe = pkgs.writeText "menu.ipxe" '' #!ipxe set base ${pxeBaseUrl} menu PXE Boot Menu item auto-installer NixOS Auto-Installer item nixos-minimal NixOS Minimal item debian Debian Minimal item rescue Rescue Environment item shell iPXE Shell item reboot Reboot choose target && goto ''${target} :auto-installer chain ''${base}/auto-installer/netboot.ipxe :nixos-minimal chain ''${base}/nixos-minimal/netboot.ipxe :debian chain ''${base}/debian.ipxe :rescue chain ''${base}/systemrescue.ipxe :shell shell :reboot reboot ''; in { imports = [ ../pxe-boot/stage-installer-artifacts.nix ]; environment.systemPackages = with pkgs; [ ipxe ]; services = { nginx = { enable = true; virtualHosts."pxe-boot" = { default = true; root = httpRoot; locations."/" = { extraConfig = '' autoindex on; ''; }; }; }; # TFTP is only used to deliver the initial iPXE bootloader. After iPXE # starts, all further assets are fetched via nginx over HTTP. atftpd = { enable = true; root = tftpRoot; extraOptions = [ "--verbose=5" ]; }; openssh.settings.PermitRootLogin = "yes"; }; systemd = { tmpfiles.rules = [ "d ${pxeRoot} 0755 root root -" "d ${httpRoot} 0755 root root -" "d ${httpRoot}/images 0755 root root -" "d ${httpRoot}/auto-installer 0755 root root -" "d ${httpRoot}/nixos-minimal 0755 root root -" "d ${httpRoot}/systemrescue 0755 root root -" "d ${httpRoot}/debian 0755 root root -" "d ${httpRoot}/ubuntu 0755 root root -" "d ${httpRoot}/rescue 0755 root root -" "d ${tftpRoot} 0755 root root -" "C+ ${httpRoot}/boot.ipxe 0644 root root - ${bootIpxe}" "C+ ${httpRoot}/menu.ipxe 0644 root root - ${menuIpxe}" "C+ ${httpRoot}/debian.ipxe 0644 root root - ${debianIpxe}" "C+ ${httpRoot}/systemrescue.ipxe 0644 root root - ${systemRescueIpxe}" "C+ ${tftpRoot}/autoexec.ipxe 0644 root root - ${autoexecIpxe}" "C+ ${tftpRoot}/ipxe.efi 0644 root root - ${pkgs.ipxe}/ipxe.efi" "C+ ${tftpRoot}/undionly.kpxe 0644 root root - ${pkgs.ipxe}/undionly.kpxe" ]; services = { fetch-debian-netboot = { description = "Download Debian ${debianRelease} netboot kernel and initrd for HTTP PXE boot"; after = [ "local-fs.target" "systemd-tmpfiles-setup.service" "network-online.target" ]; wants = [ "network-online.target" ]; wantedBy = [ "multi-user.target" ]; serviceConfig = { Type = "oneshot"; ExecStart = fetchDebianNetboot; RemainAfterExit = true; }; }; stage-systemrescue = { description = "Stage SystemRescue ISO contents for HTTP PXE boot"; after = [ "local-fs.target" "systemd-tmpfiles-setup.service" ]; wantedBy = [ "multi-user.target" ]; serviceConfig = { Type = "oneshot"; ExecStart = stageSystemRescue; }; }; }; }; networking.firewall.allowedTCPPorts = [ vars.ports.pxeBootHttp ]; networking.firewall.allowedUDPPorts = [ vars.ports.pxeBootTftp ]; }