Archived
Check NixOS configurations / eval-hosts (pull_request) Failing after 11m19s
variables.nix's deployedTargets was a manually-maintained list with no enforcement keeping it in sync with reality -- it caused two separate false refusals in a row (naming a VM as deployed well after it had been destroyed, then matching a target against itself once the list was "corrected"). Static files can't track whether a resource still actually exists. create-proxmox-resource.sh's duplicate-host guard now queries the Proxmox node directly (qm/pct's own name/hostname config, matched against --host) instead. Also fixes a gap in that live check: it originally swallowed ssh failures and would have silently treated "can't reach the node" the same as "checked, nothing there" -- it now refuses instead of guessing when the node can't be reached. deployedTargets is removed entirely from variables.nix since nothing else in the repo consumed it once this script no longer does; README.md's Hosts table remains the sole source of truth for "(real, deployed)" status. CLAUDE.md and the script's own --help/comments updated to match. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
160 lines
7.3 KiB
Nix
160 lines
7.3 KiB
Nix
{
|
|
# Network / domains
|
|
lanDomain = "gitea.lan.ddnsgeek.com"; # Gitea/DDNS domain
|
|
homeDomain = "sweet.home"; # base LAN domain for service subdomains (pve., docker.)
|
|
tailnetDomain = "tail13f623.ts.net"; # Tailscale MagicDNS suffix
|
|
lanCidr = "192.168.2.0/24"; # LAN subnet
|
|
pxeServerIp = "192.168.2.247"; # pxe-boot host's LAN IP
|
|
pbsIp = "192.168.2.108"; # Proxmox Backup Server LAN IP
|
|
|
|
# Cross-host references (LAN hostnames/users other hosts reach over the network)
|
|
nixCacheHost = "nix-cache"; # substituter/remote-builder hostname
|
|
nfsServerHost = "server"; # NFS export source hostname
|
|
dockerHost = "docker"; # docker-compose stack host
|
|
|
|
# Raspberry Pi's own Tailscale hostname (not fronted by `server` — it
|
|
# exports its own NFS share directly). Resolved as
|
|
# "${raspberryPiHost}.${tailnetDomain}" in modules/raspi/mount-data.nix.
|
|
raspberryPiHost = "raspberrypi";
|
|
|
|
remoteBuilderUser = "nixremote"; # remote builder SSH user
|
|
|
|
# nix-cache's own SSH host public key (not a secret — the private half
|
|
# never leaves the host). Wired into every client's
|
|
# programs.ssh.knownHosts by modules/nix-cache/remote-builder-client.nix
|
|
# so distributed builds don't hit "Host key verification failed" on a
|
|
# fresh client that has never manually ssh'd to nix-cache before. Update
|
|
# this if nix-cache's host key is ever rotated or the host is rebuilt
|
|
# from scratch.
|
|
nixCacheHostKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHrMKZlIGUd3pH9G3AqbsruqUGjxIXMAZw52u9MwiBCn lxc-nix-cache";
|
|
|
|
# Public keys authorized to SSH in as remoteBuilderUser on the nix-cache
|
|
# host (modules/nix-cache/server.nix) — one per client host that's allowed
|
|
# to use it as a distributed builder.
|
|
remoteBuilderAuthorizedKeys = [
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFDEA1S2ikpObREgbP5uVBWMxIOGbY8B+Wx7VTZK1m6t root@server"
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPAYIT9ormlmxZ0SziyDQaUntnKI8HK9/s3Qac1ZKjP2 root@docker"
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKKzoEPl/ZW9KBRHBcp6/ThOngGpwMv5EhkTlgC4aDf root@nixos"
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIGtOWOCS+ImHc7NehguoyD7PbonGosKMZqc9+QR3v/h root@nixos"
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHxXTQxFnArK5HXG7czeoybZebCGfxpUdusJkPn+BCSp root@server"
|
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICMJhrfFayLBG+gWtO6oAvgambw5nWWgztiTFEaaaVRH debian@surface"
|
|
];
|
|
|
|
# Admin SSH public key, authorized on the primary user of every host and
|
|
# the installer image's nixos/root users.
|
|
adminSshKey = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCq/Q5LvIXlZwO2kdeAN5nLGZ59nZB7JHYMEszHxmNtGMzv1lM31jiPNsr0z2EKVZhE7OOfa2IF9rhWYD7JUA9G0yzdZ4WTXFNGVVOJoOVH6vAF3XCxoVilOEwTc7h2Wiy+rzd0B28/3spffzQQWJhY6GRQVa8j+6xAGF60Fcvl1vLosYT9Bn2ZbK4TCWOwAn2jqXIieGpZdn/UNZbGOeKRiCvhktDfMAzuQzN/9jMu/oF4pkPn2X1UrsQdNlvp0Ci8md612MozIpncQJyAF1ADhunr3sMx0isUXiqD29R5DS4TftpekqLNLak+zcxFa8N7DcRNp3DcKfJvyTkwQrR4r+b7lFLYOLHLagSso9CzeW/paAS2q9I5SBm/2DtE1diLLg2jZikYcstsu/G5RgvbzbKqjiaMwTdXC3AMvDxQrs7U5pDRZFzoofG3cpODbTm+uy3m0kP70z0M1K45UbDG0p+itnTu9x40JbQEgefbx38AItNvAIx1A8HO4I1VX28= wayne@stream";
|
|
|
|
# System
|
|
timeZone = "Australia/Brisbane";
|
|
|
|
# Main interactive user on every host. Every module that grants this user
|
|
# a group, a home directory, or tmpfiles ownership should reference
|
|
# vars.primaryUser rather than the literal "nixos", so renaming it is a
|
|
# one-line change.
|
|
primaryUser = "nixos";
|
|
|
|
# Storage
|
|
storageRoot = "/tank"; # ZFS pool root on `server`
|
|
|
|
# NFS datasets exported from `storageRoot` on `nfsServerHost` and mounted
|
|
# by client hosts. `subpath` is relative to `storageRoot` — combined with
|
|
# it to build both the export line in modules/build-types/server.nix and
|
|
# the "<nfsServerHost>:<storageRoot>/<subpath>" device string each client
|
|
# mount uses in modules/docker/mount-data.nix. `mountpoint` is the
|
|
# absolute local path clients mount it at, referenced by that same file's
|
|
# fileSystems attribute name plus every other place that needs to know
|
|
# where the share lives locally (modules/build-types/docker.nix's
|
|
# tmpfiles rules, modules/traefik/rotate-logs.nix's log path). Renaming a
|
|
# dataset or moving where it's mounted only needs changing it here — the
|
|
# export and every client reference follow automatically.
|
|
nfsShares = {
|
|
dockerConfig = {
|
|
subpath = "docker/config";
|
|
mountpoint = "/mnt/docker/config";
|
|
};
|
|
dockerDatabases = {
|
|
subpath = "docker/databases";
|
|
mountpoint = "/mnt/docker/databases";
|
|
};
|
|
dockerVolumes = {
|
|
subpath = "docker/volumes";
|
|
mountpoint = "/mnt/docker/volumes";
|
|
};
|
|
nextcloudData = {
|
|
subpath = "docker/nextcloud-data";
|
|
mountpoint = "/mnt/nextcloud-data";
|
|
};
|
|
raspiVolumes = {
|
|
subpath = "raspi/volumes";
|
|
mountpoint = "/mnt/raspi-backup";
|
|
};
|
|
};
|
|
|
|
# The Raspberry Pi's own NFS export — not under storageRoot/nfsServerHost,
|
|
# served directly by the Pi itself over Tailscale (see raspberryPiHost
|
|
# above) and mounted at raspiMountpoint by modules/raspi/mount-data.nix.
|
|
raspiNfsPath = "/home/raspi/raspi";
|
|
raspiMountpoint = "/mnt/raspi";
|
|
|
|
# Every literal port referenced from modules/ or hosts/, grouped by the
|
|
# service/host that opens or connects to it — kept as separate entries
|
|
# even where two happen to share a number today (e.g. nixCacheHttp and
|
|
# pxeBootHttp are both 80) so changing one service's port can never
|
|
# silently change an unrelated one.
|
|
ports = {
|
|
# nix-cache's nginx reverse proxy in front of nix-serve
|
|
# (modules/nix-cache/server.nix).
|
|
nixCacheHttp = 80;
|
|
|
|
# pxe-boot's nginx asset server, also used to build pxeBaseUrl
|
|
# (modules/build-types/pxe-boot.nix).
|
|
pxeBootHttp = 80;
|
|
|
|
# pxe-boot's atftpd TFTP server — UDP, not TCP
|
|
# (modules/build-types/pxe-boot.nix).
|
|
pxeBootTftp = 69;
|
|
|
|
# `server`'s NFS exports need both the portmapper (rpcbind) and the
|
|
# NFS data port itself opened (modules/build-types/server.nix).
|
|
nfsRpcbind = 111;
|
|
nfsd = 2049;
|
|
|
|
# Opened on the docker host's firewall for the Traefik-fronted
|
|
# container stack (docker-compose config lives in the separate
|
|
# /home/debian/docker repo, not here): 80/443 are Traefik's own
|
|
# HTTP/HTTPS listeners; 8080 is an additional exposed service whose
|
|
# exact backend isn't declared in this repo (modules/build-types/docker.nix).
|
|
dockerHttp = 80;
|
|
dockerHttps = 443;
|
|
dockerExtra = 8080;
|
|
|
|
# Beszel monitoring hub, reachable at
|
|
# http://<dockerHost>.<homeDomain>:<beszelHub> from every agent
|
|
# (modules/beszel/enable-agent.nix, hosts/nixos/home.nix).
|
|
beszelHub = 8090;
|
|
|
|
# Proxmox VE and Proxmox Backup Server web UIs, opened as desktop
|
|
# shortcuts on the gui build type (hosts/nixos/home.nix).
|
|
pveWeb = 8006;
|
|
pbsWeb = 8007;
|
|
};
|
|
|
|
# .raw disk image size for every proxmox-* host's standalone Disko image
|
|
# build (modules/disko/proxmox.nix, config.system.build.diskoImagesScript
|
|
# — see docs/proxmox-images.md). Root fills whatever's left after the ESP
|
|
# and swap partitions within this total.
|
|
proxmoxImageSize = "20G";
|
|
|
|
# nix-cache's Nix store garbage collection retention
|
|
# (modules/nix-cache/server.nix).
|
|
nixCacheGcMaxAge = "30d";
|
|
|
|
# Traefik access log rotation, watched on the docker host at
|
|
# nfsShares.dockerVolumes.mountpoint (modules/traefik/rotate-logs.nix).
|
|
traefikLogRotate = {
|
|
maxSize = "100M"; # rotate once a log file exceeds this size
|
|
keep = 20; # number of rotated logs to retain before deleting the oldest
|
|
};
|
|
|
|
}
|