Archived
Check NixOS configurations / eval-hosts (push) Successful in 10m30s
systemd-resolved only uses LLMNR for single-label hostnames, never DNS — same issue mount-data.nix already documented and fixed for NFS by switching to server.sweet.home. Change the substituter URL, SSH knownHosts, and remote-builder hostName from bare "nix-cache" to "nix-cache.sweet.home", and update nginx's virtualHost to match. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
41 lines
1.4 KiB
Nix
41 lines
1.4 KiB
Nix
{ pkgs, vars, ... }:
|
|
|
|
{
|
|
# Authenticate as nixremote using the client host's own default root SSH
|
|
# identity (/root/.ssh/id_ed25519) rather than a separately-named key --
|
|
# matches vars.remoteBuilderAuthorizedKeys, which already authorizes
|
|
# each host's own default key (one entry per host, not a shared
|
|
# dedicated keypair). If this host doesn't have one yet:
|
|
# sudo -u root ssh-keygen -t ed25519 -N '' -f /root/.ssh/id_ed25519
|
|
# # then add its .pub to vars.remoteBuilderAuthorizedKeys and rebuild nix-cache
|
|
# sudo ssh -i /root/.ssh/id_ed25519 nixremote@nix-cache.sweet.home nix-store --version
|
|
# Trust nix-cache's SSH host key declaratively so the nix-daemon (root)
|
|
# can connect the first time without a manual ssh-keyscan/known_hosts
|
|
# step on every new client.
|
|
programs.ssh.knownHosts."${vars.nixCacheHost}.${vars.homeDomain}" = {
|
|
hostNames = [ "${vars.nixCacheHost}.${vars.homeDomain}" ];
|
|
publicKey = vars.nixCacheHostKey;
|
|
};
|
|
|
|
nix = {
|
|
distributedBuilds = true;
|
|
|
|
buildMachines = [
|
|
{
|
|
hostName = "${vars.nixCacheHost}.${vars.homeDomain}";
|
|
sshUser = vars.remoteBuilderUser;
|
|
sshKey = "/root/.ssh/id_ed25519";
|
|
inherit (pkgs.stdenv.hostPlatform) system;
|
|
maxJobs = 4;
|
|
speedFactor = 2;
|
|
supportedFeatures = [ "nixos-test" "benchmark" "big-parallel" "kvm" ];
|
|
}
|
|
];
|
|
|
|
settings = {
|
|
builders-use-substitutes = true;
|
|
max-jobs = "auto";
|
|
};
|
|
};
|
|
}
|