Archived
Moves the auto-installer's shell script from an inline Nix string in
modules/installer/common.nix to scripts/installer/auto-install.sh, a
real, version-controlled, directly-editable/shellcheck-able file.
common.nix now wires it in with pkgs.replaceVars, substituting the one
value that actually needs to come from variables.nix (lanDomain) --
every other `${...}` in the script is a literal bash reference, left
untouched. replaceVars fails the build if any @name@-shaped placeholder
is left unsubstituted, so a typo'd or renamed variable is caught at
eval time rather than silently shipping broken.
Verified: built the substituted derivation and diffed it against the
source template -- identical except for the one substituted line, no
leftover unsubstituted placeholders. Full codex-maintenance.sh (secret
grep, fmt, statix, full eval of every host/package including the
installer/pxe artifacts that consume this) passes clean.
118 lines
3.8 KiB
Nix
118 lines
3.8 KiB
Nix
{ pkgs, lib, vars, ... }:
|
|
|
|
{
|
|
imports = [
|
|
./host-keys.nix
|
|
];
|
|
|
|
networking.useDHCP = lib.mkDefault true;
|
|
|
|
# Recommended over the true default (bypasses ZFS's own import safeguards)
|
|
# per the option's own docs. This installer environment has no ZFS pools
|
|
# of its own to import, so this is a no-op here — just silences the
|
|
# eval-time warning, matching modules/common/configuration.nix.
|
|
boot.zfs.forceImportRoot = false;
|
|
|
|
time.timeZone = vars.timeZone;
|
|
|
|
# Without this, the installer only ever sees cache.nixos.org, which
|
|
# doesn't carry sops-install-secrets (it's built straight from the
|
|
# sops-nix flake's own Go source, not part of nixpkgs) — every install
|
|
# would otherwise compile it from scratch, which is what ran an 8GB LXC
|
|
# container's disk out of space. Push a built copy to nix-cache once
|
|
# (from a machine with real disk headroom) and every future install,
|
|
# of any type, fetches instead of rebuilding.
|
|
nix.settings = {
|
|
substituters = [
|
|
"http://nix-cache"
|
|
"https://cache.nixos.org/"
|
|
];
|
|
trusted-public-keys = [
|
|
"cache.local-1:usoWYanY3Kpq2+kDIS2nhWoLZiRxanmdysdzqCFBHW4="
|
|
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
|
|
];
|
|
};
|
|
|
|
environment = {
|
|
systemPackages = with pkgs; [
|
|
git
|
|
curl
|
|
jq
|
|
parted
|
|
e2fsprogs
|
|
btrfs-progs
|
|
util-linux
|
|
disko
|
|
];
|
|
|
|
# Auto-install script, kept as a real, version-controlled shell file at
|
|
# scripts/installer/auto-install.sh rather than an inline Nix string --
|
|
# replaceVars only substitutes the one value (lanDomain) that genuinely
|
|
# needs to come from variables.nix; every other "@..." pattern in the
|
|
# script is a literal `${...}` bash reference, untouched by this.
|
|
etc."auto-install.sh" = {
|
|
source = pkgs.replaceVars ../../scripts/installer/auto-install.sh {
|
|
inherit (vars) lanDomain;
|
|
};
|
|
|
|
mode = "0755";
|
|
};
|
|
};
|
|
|
|
programs.git.enable = true;
|
|
|
|
# Run the installer on first login. Previously this copied an /etc file
|
|
# into the nixos user's ~/.bash_profile via an activation script that
|
|
# got dropped in a refactor (and only ever worked for that one user
|
|
# anyway) — loginShellInit is NixOS's native hook for this, applies to
|
|
# any user's login shell (root included), and needs no home-directory
|
|
# file-copying/chown.
|
|
programs.bash.loginShellInit = ''
|
|
if [ -n "$PS1" ] && [ ! -e "$HOME/.auto_install_ran" ]; then
|
|
sudo /etc/auto-install.sh
|
|
touch "$HOME/.auto_install_ran"
|
|
fi
|
|
'';
|
|
|
|
services.openssh.enable = true;
|
|
|
|
services.openssh.settings = {
|
|
PermitRootLogin = "yes";
|
|
PasswordAuthentication = true;
|
|
};
|
|
|
|
# nixpkgs' own installer profile (profiles/installation-device.nix, pulled
|
|
# in via installation-cd-minimal.nix) sets initialHashedPassword = "" for
|
|
# both users — its own passwordless-login convention for install media.
|
|
# That's a second, non-null password option alongside our hashedPassword
|
|
# below, which NixOS warns about as ambiguous precedence. Force it null
|
|
# rather than adopting passwordless login: this image now also boots over
|
|
# LAN PXE with PasswordAuthentication enabled, so passwordless root SSH
|
|
# would be reachable by anyone on the LAN, not just local console.
|
|
users.users.root = {
|
|
hashedPassword =
|
|
"$6$Kwv9KAyvcurAViQF$H4.u3feqGE7lVoNgkFXhE3n2Pmo//9JYDTCz8ifrVHBxPjwa1xMby7tEZ8Bpt5MXs9Rkx6/YbZWxs5CpH0s/70";
|
|
initialHashedPassword = lib.mkForce null;
|
|
};
|
|
|
|
users.users.${vars.primaryUser} = {
|
|
isNormalUser = true;
|
|
|
|
extraGroups = [
|
|
"wheel"
|
|
];
|
|
|
|
shell = pkgs.bashInteractive;
|
|
|
|
hashedPassword =
|
|
"$6$Kwv9KAyvcurAViQF$H4.u3feqGE7lVoNgkFXhE3n2Pmo//9JYDTCz8ifrVHBxPjwa1xMby7tEZ8Bpt5MXs9Rkx6/YbZWxs5CpH0s/70";
|
|
initialHashedPassword = lib.mkForce null;
|
|
|
|
openssh.authorizedKeys.keys = [
|
|
vars.adminSshKey
|
|
];
|
|
};
|
|
|
|
system.stateVersion = "26.05";
|
|
}
|