Archived
Adds modules/pxe-boot/mount-pxe-images.nix, which mounts server.sweet.home:/tank/proxmox/pxe-images at /mnt/pxe-images via NFSv4.2 (x-systemd.automount on Proxmox VMs, nofail on LXC containers — same pattern as docker/mount-data.nix). The pxe-boot build-type now imports this module and replaces the previous local /srv/pxe/http/images directory rule with an L+ symlink pointing to /mnt/pxe-images, so large images (ISOs, disk images) live on the NFS share rather than the host's own root disk. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
226 lines
5.9 KiB
Nix
226 lines
5.9 KiB
Nix
{ config, lib, pkgs, inputs, vars, ... }:
|
|
|
|
let
|
|
pxeRoot = "/srv/pxe";
|
|
httpRoot = "${pxeRoot}/http";
|
|
tftpRoot = "${pxeRoot}/tftp";
|
|
pxeBaseUrl = "http://${vars.pxeServerIp}";
|
|
|
|
bootIpxe = pkgs.writeText "boot.ipxe" ''
|
|
#!ipxe
|
|
|
|
dhcp
|
|
echo Booting from PXE server...
|
|
chain ${pxeBaseUrl}/menu.ipxe
|
|
'';
|
|
|
|
autoexecIpxe = pkgs.writeText "autoexec.ipxe" ''
|
|
#!ipxe
|
|
|
|
dhcp
|
|
chain ${pxeBaseUrl}/boot.ipxe
|
|
'';
|
|
|
|
debianRelease = "bookworm";
|
|
debianMirror = "https://deb.debian.org/debian";
|
|
debianNetbootBase = "${debianMirror}/dists/${debianRelease}/main/installer-amd64/current/images/netboot/debian-installer/amd64";
|
|
|
|
debianIpxe = pkgs.writeText "debian.ipxe" ''
|
|
#!ipxe
|
|
|
|
set base ${pxeBaseUrl}
|
|
|
|
kernel ''${base}/debian/linux
|
|
initrd ''${base}/debian/initrd.gz
|
|
boot
|
|
'';
|
|
|
|
fetchDebianNetboot = pkgs.writeShellScript "fetch-debian-netboot" ''
|
|
set -eu
|
|
|
|
dir="${httpRoot}/debian"
|
|
mirror="${debianNetbootBase}"
|
|
|
|
if [ -f "$dir/linux" ] && [ -f "$dir/initrd.gz" ]; then
|
|
echo "Debian ${debianRelease} netboot files already present; skipping download."
|
|
exit 0
|
|
fi
|
|
|
|
echo "Downloading Debian ${debianRelease} netboot kernel and initrd from $mirror ..."
|
|
${pkgs.curl}/bin/curl -fsSL -o "$dir/linux.tmp" "$mirror/linux"
|
|
${pkgs.curl}/bin/curl -fsSL -o "$dir/initrd.gz.tmp" "$mirror/initrd.gz"
|
|
mv "$dir/linux.tmp" "$dir/linux"
|
|
mv "$dir/initrd.gz.tmp" "$dir/initrd.gz"
|
|
echo "Debian ${debianRelease} netboot files staged."
|
|
'';
|
|
|
|
systemRescueIpxe = pkgs.writeText "systemrescue.ipxe" ''
|
|
#!ipxe
|
|
|
|
set base ${pxeBaseUrl}
|
|
|
|
kernel ''${base}/systemrescue/sysresccd/boot/x86_64/vmlinuz initrd=sysresccd.img archisobasedir=sysresccd archiso_http_srv=''${base}/systemrescue/ ip=dhcp checksum
|
|
initrd ''${base}/systemrescue/sysresccd/boot/x86_64/sysresccd.img sysresccd.img
|
|
boot
|
|
'';
|
|
|
|
stageSystemRescue = pkgs.writeShellScript "stage-systemrescue" ''
|
|
set -eu
|
|
|
|
iso="${httpRoot}/images/systemrescue.iso"
|
|
staged="${httpRoot}/systemrescue"
|
|
tmp="${httpRoot}/.systemrescue.tmp"
|
|
previous="${httpRoot}/.systemrescue.previous"
|
|
|
|
if [ ! -e "$iso" ]; then
|
|
echo "SystemRescue ISO not found at $iso; skipping staging."
|
|
exit 0
|
|
fi
|
|
|
|
rm -rf "$tmp"
|
|
mkdir -p "$tmp"
|
|
|
|
${pkgs.libarchive}/bin/bsdtar -C "$tmp" -xf "$iso"
|
|
|
|
test -f "$tmp/sysresccd/boot/x86_64/vmlinuz"
|
|
test -f "$tmp/sysresccd/boot/x86_64/sysresccd.img"
|
|
chmod -R a+rX "$tmp"
|
|
|
|
rm -rf "$previous"
|
|
if [ -e "$staged" ]; then
|
|
mv "$staged" "$previous"
|
|
fi
|
|
|
|
mv "$tmp" "$staged"
|
|
rm -rf "$previous"
|
|
'';
|
|
|
|
menuIpxe = pkgs.writeText "menu.ipxe" ''
|
|
#!ipxe
|
|
|
|
set base ${pxeBaseUrl}
|
|
|
|
menu PXE Boot Menu
|
|
item auto-installer NixOS Auto-Installer
|
|
item nixos-minimal NixOS Minimal
|
|
item debian Debian Minimal
|
|
item rescue Rescue Environment
|
|
item shell iPXE Shell
|
|
item reboot Reboot
|
|
|
|
choose target && goto ''${target}
|
|
|
|
:auto-installer
|
|
chain ''${base}/auto-installer/netboot.ipxe
|
|
|
|
:nixos-minimal
|
|
chain ''${base}/nixos-minimal/netboot.ipxe
|
|
|
|
:debian
|
|
chain ''${base}/debian.ipxe
|
|
|
|
:rescue
|
|
chain ''${base}/systemrescue.ipxe
|
|
|
|
:shell
|
|
shell
|
|
|
|
:reboot
|
|
reboot
|
|
'';
|
|
in
|
|
{
|
|
imports = [
|
|
../pxe-boot/stage-installer-artifacts.nix
|
|
../pxe-boot/mount-pxe-images.nix
|
|
];
|
|
|
|
environment.systemPackages = with pkgs; [
|
|
ipxe
|
|
];
|
|
|
|
services = {
|
|
nginx = {
|
|
enable = true;
|
|
|
|
virtualHosts."pxe-boot" = {
|
|
default = true;
|
|
root = httpRoot;
|
|
locations."/" = {
|
|
extraConfig = ''
|
|
autoindex on;
|
|
'';
|
|
};
|
|
};
|
|
};
|
|
|
|
# TFTP is only used to deliver the initial iPXE bootloader. After iPXE
|
|
# starts, all further assets are fetched via nginx over HTTP.
|
|
atftpd = {
|
|
enable = true;
|
|
root = tftpRoot;
|
|
extraOptions = [
|
|
"--verbose=5"
|
|
];
|
|
};
|
|
|
|
openssh.settings.PermitRootLogin = "yes";
|
|
};
|
|
|
|
systemd = {
|
|
tmpfiles.rules = [
|
|
"d ${pxeRoot} 0755 root root -"
|
|
"d ${httpRoot} 0755 root root -"
|
|
"L+ ${httpRoot}/images - - - - ${vars.nfsShares.proxmoxPxeImages.mountpoint}"
|
|
"d ${httpRoot}/auto-installer 0755 root root -"
|
|
"d ${httpRoot}/nixos-minimal 0755 root root -"
|
|
"d ${httpRoot}/systemrescue 0755 root root -"
|
|
"d ${httpRoot}/debian 0755 root root -"
|
|
"d ${httpRoot}/ubuntu 0755 root root -"
|
|
"d ${httpRoot}/rescue 0755 root root -"
|
|
"d ${tftpRoot} 0755 root root -"
|
|
"C+ ${httpRoot}/boot.ipxe 0644 root root - ${bootIpxe}"
|
|
"C+ ${httpRoot}/menu.ipxe 0644 root root - ${menuIpxe}"
|
|
"C+ ${httpRoot}/debian.ipxe 0644 root root - ${debianIpxe}"
|
|
"C+ ${httpRoot}/systemrescue.ipxe 0644 root root - ${systemRescueIpxe}"
|
|
"C+ ${tftpRoot}/autoexec.ipxe 0644 root root - ${autoexecIpxe}"
|
|
"C+ ${tftpRoot}/ipxe.efi 0644 root root - ${pkgs.ipxe}/ipxe.efi"
|
|
"C+ ${tftpRoot}/undionly.kpxe 0644 root root - ${pkgs.ipxe}/undionly.kpxe"
|
|
];
|
|
|
|
services = {
|
|
fetch-debian-netboot = {
|
|
description = "Download Debian ${debianRelease} netboot kernel and initrd for HTTP PXE boot";
|
|
after = [
|
|
"local-fs.target"
|
|
"systemd-tmpfiles-setup.service"
|
|
"network-online.target"
|
|
];
|
|
wants = [ "network-online.target" ];
|
|
wantedBy = [ "multi-user.target" ];
|
|
serviceConfig = {
|
|
Type = "oneshot";
|
|
ExecStart = fetchDebianNetboot;
|
|
RemainAfterExit = true;
|
|
};
|
|
};
|
|
|
|
stage-systemrescue = {
|
|
description = "Stage SystemRescue ISO contents for HTTP PXE boot";
|
|
after = [
|
|
"local-fs.target"
|
|
"systemd-tmpfiles-setup.service"
|
|
];
|
|
wantedBy = [ "multi-user.target" ];
|
|
serviceConfig = {
|
|
Type = "oneshot";
|
|
ExecStart = stageSystemRescue;
|
|
};
|
|
};
|
|
};
|
|
};
|
|
|
|
networking.firewall.allowedTCPPorts = [ vars.ports.pxeBootHttp ];
|
|
networking.firewall.allowedUDPPorts = [ vars.ports.pxeBootTftp ];
|
|
}
|