Archived
Check NixOS configurations / eval-hosts (pull_request) Failing after 11m12s
variables.nix's nixCacheHostKey no longer matched nix-cache's actual SSH host key (confirmed via ssh-keyscan against the live container), so every declaratively-configured client's programs.ssh.knownHosts trusted the wrong key -- distributed builds would fail host-key verification. Also, modules/nix-cache/remote-builder-client.nix hardcoded sshKey to /root/.ssh/nixremote, but the `server` host only has its own default /root/.ssh/id_ed25519 installed (confirmed live via qm guest-agent) -- that file was never even present, so the build machine config pointed at nothing. Standardize on each client's own default identity, matching the per-host-key pattern vars.remoteBuilderAuthorizedKeys already uses instead of a shared/differently-named keypair, and add scripts/secrets/sync-nix-cache-host-key.sh (wired into codex-maintenance.sh's --check) so the host-key drift doesn't silently recur next time nix-cache is rebuilt or recreated. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V7yVH71vGrDVzovh9UaMu8
118 lines
3.7 KiB
Bash
Executable File
118 lines
3.7 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
# shellcheck source=lib/nix-bootstrap.sh
|
|
source "${script_dir}/lib/nix-bootstrap.sh"
|
|
# shellcheck source=lib/nix-eval.sh
|
|
source "${script_dir}/lib/nix-eval.sh"
|
|
|
|
MODE="${1:-validate}"
|
|
|
|
ensure_nix_profile
|
|
|
|
if ! command -v nix >/dev/null 2>&1; then
|
|
echo "ERROR: nix is not available in PATH. Run bash scripts/codex-setup.sh first." >&2
|
|
exit 127
|
|
fi
|
|
|
|
hosts="$(list_flake_targets .)"
|
|
|
|
echo "Hosts:"
|
|
echo "$hosts"
|
|
|
|
echo
|
|
echo "Checking for obvious committed secrets..."
|
|
if grep -RInE 'github_pat_|ghp_|access-tokens|hashedPassword[[:space:]]*=' \
|
|
--exclude-dir=.git \
|
|
--exclude=flake.lock \
|
|
.; then
|
|
echo
|
|
echo "WARNING: Potential secrets or password hashes found. Review before committing."
|
|
else
|
|
echo "No obvious token patterns found."
|
|
fi
|
|
|
|
echo
|
|
echo "Checking Nix formatting with nixpkgs-fmt..."
|
|
nix run "${NIX_EVAL_FLAGS[@]}" github:NixOS/nixpkgs/nixos-25.11#nixpkgs-fmt -- --check .
|
|
|
|
echo
|
|
echo "Running statix lint..."
|
|
nix run "${NIX_EVAL_FLAGS[@]}" github:NixOS/nixpkgs/nixos-25.11#statix -- check .
|
|
|
|
echo
|
|
echo "Checking nix-cache host key for drift..."
|
|
if bash "${script_dir}/secrets/sync-nix-cache-host-key.sh" --check; then
|
|
:
|
|
else
|
|
drift_status=$?
|
|
if [[ "$drift_status" -eq 2 ]]; then
|
|
echo "nix-cache unreachable from here -- skipping host-key drift check."
|
|
else
|
|
echo "WARNING: nix-cache's host key has drifted from variables.nix (see above)." >&2
|
|
echo " Run 'bash scripts/secrets/sync-nix-cache-host-key.sh' to fix." >&2
|
|
fi
|
|
fi
|
|
|
|
echo
|
|
echo "Evaluating host toplevel derivations..."
|
|
for host in $hosts; do
|
|
echo "==> $host"
|
|
nix eval --raw "${NIX_EVAL_FLAGS[@]}" ".#nixosConfigurations.${host}.config.system.build.toplevel.drvPath"
|
|
|
|
# lxc-* hosts deploy via a directly pct-restore-able tarball instead of
|
|
# nixos-install (see docs/auto-installer.md); proxmox-* hosts can
|
|
# alternatively be built as a standalone disk image (see
|
|
# docs/proxmox-images.md). Both are otherwise-unvalidated buildable
|
|
# surface, easy to silently break without this.
|
|
case "$host" in
|
|
lxc-*)
|
|
echo "==> $host (tarball)"
|
|
nix eval --raw "${NIX_EVAL_FLAGS[@]}" ".#nixosConfigurations.${host}.config.system.build.tarball.drvPath"
|
|
;;
|
|
proxmox-*)
|
|
echo "==> $host (diskoImagesScript)"
|
|
nix eval --raw "${NIX_EVAL_FLAGS[@]}" ".#nixosConfigurations.${host}.config.system.build.diskoImagesScript.drvPath"
|
|
;;
|
|
esac
|
|
done
|
|
|
|
echo
|
|
echo "Evaluating buildable packages..."
|
|
packages="$(nix eval --json "${NIX_EVAL_FLAGS[@]}" .#packages.x86_64-linux --apply builtins.attrNames | jq -r '.[]')"
|
|
for pkg in $packages; do
|
|
echo "==> packages.x86_64-linux.${pkg}"
|
|
nix eval --raw "${NIX_EVAL_FLAGS[@]}" ".#packages.x86_64-linux.${pkg}"
|
|
done
|
|
|
|
if [[ "$MODE" == "dry-run" ]]; then
|
|
echo
|
|
echo "Running dry-run builds for all hosts. This will not create result symlinks."
|
|
for host in $hosts; do
|
|
echo "==> Dry-run build: $host"
|
|
nix build --dry-run --no-link "${NIX_EVAL_FLAGS[@]}" ".#nixosConfigurations.${host}.config.system.build.toplevel"
|
|
|
|
case "$host" in
|
|
lxc-*)
|
|
echo "==> Dry-run build: $host (tarball)"
|
|
nix build --dry-run --no-link "${NIX_EVAL_FLAGS[@]}" ".#nixosConfigurations.${host}.config.system.build.tarball"
|
|
;;
|
|
proxmox-*)
|
|
echo "==> Dry-run build: $host (diskoImagesScript)"
|
|
nix build --dry-run --no-link "${NIX_EVAL_FLAGS[@]}" ".#nixosConfigurations.${host}.config.system.build.diskoImagesScript"
|
|
;;
|
|
esac
|
|
done
|
|
|
|
echo
|
|
echo "Running dry-run builds for all packages."
|
|
for pkg in $packages; do
|
|
echo "==> Dry-run build: packages.x86_64-linux.${pkg}"
|
|
nix build --dry-run --no-link "${NIX_EVAL_FLAGS[@]}" ".#packages.x86_64-linux.${pkg}"
|
|
done
|
|
fi
|
|
|
|
echo
|
|
echo "Maintenance checks complete."
|