Archived
Check NixOS configurations / eval-hosts (pull_request) Failing after 11m29s
Three chunks of copy-pasted logic were drifting across scripts/*.sh: - codex-setup.sh and codex-maintenance.sh each carried an identical NIX_CONFIG bootstrap + ensure_nix_profile() -> scripts/lib/nix-bootstrap.sh - sync-host-keys.sh and prepare-host-key.sh each ran the same ssh-keygen/ssh-to-age nix-shell invocations -> scripts/lib/ssh-host-keys.sh (prepare-host-key.sh now also calls env.sh's nix_extra_opts before using them, closing a gap where it alone skipped the nix-cache reachability check env.sh exists for) - the "list nixosConfigurations attrNames" / "get one target's hostName" nix eval pattern was repeated across codex-setup.sh, codex-maintenance.sh, sync-host-keys.sh and create-proxmox-resource.sh (the latter twice, in its own --list and --host lookup) -> scripts/lib/nix-eval.sh, which also centralizes the --no-use-registries --no-accept-flake-config flag pair used on every such call Verified against the real flake/node config (nix is available here): create-proxmox-resource.sh --list for both --type lxc/vm, a full --dry-run create, and prepare-host-key.sh generating and cleaning up a real key/age-pubkey pair. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
84 lines
1.9 KiB
Bash
Executable File
84 lines
1.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
# shellcheck source=lib/nix-bootstrap.sh
|
|
source "${script_dir}/lib/nix-bootstrap.sh"
|
|
# shellcheck source=lib/nix-eval.sh
|
|
source "${script_dir}/lib/nix-eval.sh"
|
|
|
|
install_nix_if_missing() {
|
|
if command -v nix >/dev/null 2>&1; then
|
|
return
|
|
fi
|
|
|
|
echo "Nix not found. Installing Nix..."
|
|
|
|
if [ "$(id -u)" -eq 0 ]; then
|
|
echo "Running as root; preparing nixbld users for container/Codex environment..."
|
|
|
|
if ! getent group nixbld >/dev/null; then
|
|
groupadd -r nixbld
|
|
fi
|
|
|
|
for i in $(seq 1 10); do
|
|
if ! id "nixbld$i" >/dev/null 2>&1; then
|
|
useradd \
|
|
-r \
|
|
-g nixbld \
|
|
-G nixbld \
|
|
-d /var/empty \
|
|
-s /usr/sbin/nologin \
|
|
"nixbld$i" || true
|
|
fi
|
|
done
|
|
|
|
mkdir -p /etc/nix
|
|
cat > /etc/nix/nix.conf <<'EOF'
|
|
experimental-features = nix-command flakes
|
|
accept-flake-config = false
|
|
warn-dirty = false
|
|
build-users-group = nixbld
|
|
EOF
|
|
|
|
sh <(curl -L https://nixos.org/nix/install) --no-daemon
|
|
else
|
|
sh <(curl -L https://nixos.org/nix/install) --no-daemon
|
|
fi
|
|
|
|
ensure_nix_profile
|
|
}
|
|
|
|
install_nix_if_missing
|
|
ensure_nix_profile
|
|
|
|
mkdir -p "$HOME/.config/nix"
|
|
cat > "$HOME/.config/nix/nix.conf" <<'EOF'
|
|
experimental-features = nix-command flakes
|
|
accept-flake-config = false
|
|
warn-dirty = false
|
|
EOF
|
|
|
|
echo "Nix version:"
|
|
nix --version
|
|
|
|
echo "Enabling tracked git hooks (pre-commit secret scan)..."
|
|
git config core.hooksPath .githooks
|
|
|
|
echo "Installing jq if unavailable..."
|
|
if ! command -v jq >/dev/null 2>&1; then
|
|
nix profile install nixpkgs#jq
|
|
fi
|
|
|
|
echo "Available NixOS hosts:"
|
|
hosts="$(list_flake_targets .)"
|
|
echo "$hosts"
|
|
|
|
echo "Evaluating all host toplevel derivations..."
|
|
for host in $hosts; do
|
|
echo "==> Evaluating $host"
|
|
nix eval --raw "${NIX_EVAL_FLAGS[@]}" ".#nixosConfigurations.${host}.config.system.build.toplevel.drvPath"
|
|
done
|
|
|
|
echo "Codex setup complete."
|