Archived
lxc-* hosts need NIXOS_HOST_KEYS_DIR + --impure to bake in a pre-seeded SSH host key, otherwise sops-nix's .sops.yaml recipient never matches and every secret permanently fails to decrypt on first boot. That invocation is easy to forget, so wrap it as `buildImage <flake-target>` alongside the existing Switch-nix/Test-nix helpers. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
51 lines
1.8 KiB
Nix
51 lines
1.8 KiB
Nix
{ config, pkgs, lib, vars, ... }:
|
|
|
|
let
|
|
# Flake attribute names are now <platform>-<buildtype> (e.g. proxmox-docker)
|
|
# and no longer match networking.hostName, since a host's hostname stays
|
|
# fixed while the platform backing it can change. Each nixosConfiguration
|
|
# stamps its own active target name into /etc/flake-target at build time.
|
|
mySwitchCmd = ''
|
|
sudo nixos-rebuild switch \
|
|
--no-write-lock-file \
|
|
--refresh \
|
|
--flake git+https://${vars.lanDomain}/beatzaplenty/nixos.git#$(cat /etc/flake-target)
|
|
'';
|
|
myTestCmd = ''
|
|
sudo nixos-rebuild test \
|
|
--no-write-lock-file \
|
|
--refresh \
|
|
--flake git+https://${vars.lanDomain}/beatzaplenty/nixos.git#$(cat /etc/flake-target)
|
|
'';
|
|
|
|
# lxc-* hosts pre-seed their SSH host key at build time (see
|
|
# modules/platforms/lxc.nix) so sops-nix's .sops.yaml recipient matches on
|
|
# first boot -- without it, secrets permanently fail to decrypt (see that
|
|
# file's comment for the confirmed failure). That requires --impure plus
|
|
# NIXOS_HOST_KEYS_DIR pointing at the repo's host-keys/ dir, same pattern
|
|
# docs/auto-installer.md uses for the installer ISO. A function, not a
|
|
# shellAlias, since the target name has to interpolate into the middle of
|
|
# the flake attribute path, not just append after it. Must be run from the
|
|
# repo root, same as every other host-keys/ command in this repo.
|
|
buildImageFn = ''
|
|
buildImage() {
|
|
if [ -z "$1" ]; then
|
|
echo "usage: buildImage <flake-target> (e.g. lxc-docker)" >&2
|
|
return 1
|
|
fi
|
|
NIXOS_HOST_KEYS_DIR="$(pwd)/host-keys" nix build --impure \
|
|
".#nixosConfigurations.$1.config.system.build.tarball"
|
|
}
|
|
'';
|
|
in
|
|
{
|
|
programs.bash = {
|
|
enable = true;
|
|
shellAliases = {
|
|
"Switch-nix" = mySwitchCmd;
|
|
"Test-nix" = myTestCmd;
|
|
};
|
|
initExtra = buildImageFn;
|
|
};
|
|
}
|