Archived
Check NixOS configurations / eval-hosts (pull_request) Failing after 9m53s
Script fixes: - Rename HOSTNAME variable to TARGET (shadowed the bash builtin) - Fix ipa-getkeytab -s to always use IPA_SERVER, not DC_HOST (diverge if --dc is overridden to a jump host) - Remove dead REALM variable - Add EXIT trap to delete the plaintext keytab if the script aborts before sops encryption completes; cleared after successful encrypt - Distinguish real ipa host-add failures from "already exists" instead of swallowing all errors with || true - Warn explicitly when no platform age keys exist for the target (keytab would be admin-only and the host couldn't decrypt it at boot) - Fix sops fallback from pinned nixos-25.11 channel to nixpkgs (uses the repo's own flake.lock) - Expand "next steps" output to include networking.domain and nameservers lines that host.nix requires for IPA membership Module docs: - Point to the script as the primary setup path; move manual steps to a fallback section - Note that certs/ipa-ca.crt is already committed (no need to re-fetch) - Document the networking.domain and nameservers requirements in the header - Add sync-host-keys.sh as explicit step 0 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>