Archived
Both existed only so the installer could boot as an LXC container and nixos-install some other host from within it, but lxc-* targets are already excluded from the install menu (nixos-install can't touch its own running root filesystem), and now have their own direct tarball path anyway. That left the installer's own LXC form with no real use case, and packages.all with only two members worth bundling. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01La55Nsss8jZ7ZuzUV9mfot
114 lines
3.9 KiB
Bash
Executable File
114 lines
3.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
export NIX_CONFIG="${NIX_CONFIG:-}
|
|
experimental-features = nix-command flakes
|
|
accept-flake-config = false
|
|
warn-dirty = false
|
|
"
|
|
|
|
MODE="${1:-validate}"
|
|
|
|
ensure_nix_profile() {
|
|
if [ -f /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh ]; then
|
|
. /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh
|
|
elif [ -f "$HOME/.nix-profile/etc/profile.d/nix.sh" ]; then
|
|
. "$HOME/.nix-profile/etc/profile.d/nix.sh"
|
|
fi
|
|
}
|
|
|
|
ensure_nix_profile
|
|
|
|
if ! command -v nix >/dev/null 2>&1; then
|
|
echo "ERROR: nix is not available in PATH. Run bash scripts/codex-setup.sh first." >&2
|
|
exit 127
|
|
fi
|
|
|
|
hosts_json="$(nix eval --json --no-use-registries --no-accept-flake-config .#nixosConfigurations --apply builtins.attrNames)"
|
|
hosts="$(echo "$hosts_json" | jq -r '.[]')"
|
|
|
|
echo "Hosts:"
|
|
echo "$hosts"
|
|
|
|
echo
|
|
echo "Checking for obvious committed secrets..."
|
|
if grep -RInE 'github_pat_|ghp_|access-tokens|hashedPassword[[:space:]]*=' \
|
|
--exclude-dir=.git \
|
|
--exclude=flake.lock \
|
|
.; then
|
|
echo
|
|
echo "WARNING: Potential secrets or password hashes found. Review before committing."
|
|
else
|
|
echo "No obvious token patterns found."
|
|
fi
|
|
|
|
echo
|
|
echo "Checking Nix formatting with nixpkgs-fmt..."
|
|
nix run --no-use-registries --no-accept-flake-config github:NixOS/nixpkgs/nixos-25.11#nixpkgs-fmt -- --check .
|
|
|
|
echo
|
|
echo "Running statix lint..."
|
|
nix run --no-use-registries --no-accept-flake-config github:NixOS/nixpkgs/nixos-25.11#statix -- check .
|
|
|
|
echo
|
|
echo "Evaluating host toplevel derivations..."
|
|
for host in $hosts; do
|
|
echo "==> $host"
|
|
nix eval --raw --no-use-registries --no-accept-flake-config ".#nixosConfigurations.${host}.config.system.build.toplevel.drvPath"
|
|
|
|
# lxc-* hosts deploy via a directly pct-restore-able tarball instead of
|
|
# nixos-install (see docs/auto-installer.md); proxmox-* hosts can
|
|
# alternatively be built as a standalone disk image (see
|
|
# docs/proxmox-images.md). Both are otherwise-unvalidated buildable
|
|
# surface, easy to silently break without this.
|
|
case "$host" in
|
|
lxc-*)
|
|
echo "==> $host (tarball)"
|
|
nix eval --raw --no-use-registries --no-accept-flake-config ".#nixosConfigurations.${host}.config.system.build.tarball.drvPath"
|
|
;;
|
|
proxmox-*)
|
|
echo "==> $host (diskoImagesScript)"
|
|
nix eval --raw --no-use-registries --no-accept-flake-config ".#nixosConfigurations.${host}.config.system.build.diskoImagesScript.drvPath"
|
|
;;
|
|
esac
|
|
done
|
|
|
|
echo
|
|
echo "Evaluating buildable packages..."
|
|
packages_json="$(nix eval --json --no-use-registries --no-accept-flake-config .#packages.x86_64-linux --apply builtins.attrNames)"
|
|
packages="$(echo "$packages_json" | jq -r '.[]')"
|
|
for pkg in $packages; do
|
|
echo "==> packages.x86_64-linux.${pkg}"
|
|
nix eval --raw --no-use-registries --no-accept-flake-config ".#packages.x86_64-linux.${pkg}"
|
|
done
|
|
|
|
if [[ "$MODE" == "dry-run" ]]; then
|
|
echo
|
|
echo "Running dry-run builds for all hosts. This will not create result symlinks."
|
|
for host in $hosts; do
|
|
echo "==> Dry-run build: $host"
|
|
nix build --dry-run --no-link --no-use-registries --no-accept-flake-config ".#nixosConfigurations.${host}.config.system.build.toplevel"
|
|
|
|
case "$host" in
|
|
lxc-*)
|
|
echo "==> Dry-run build: $host (tarball)"
|
|
nix build --dry-run --no-link --no-use-registries --no-accept-flake-config ".#nixosConfigurations.${host}.config.system.build.tarball"
|
|
;;
|
|
proxmox-*)
|
|
echo "==> Dry-run build: $host (diskoImagesScript)"
|
|
nix build --dry-run --no-link --no-use-registries --no-accept-flake-config ".#nixosConfigurations.${host}.config.system.build.diskoImagesScript"
|
|
;;
|
|
esac
|
|
done
|
|
|
|
echo
|
|
echo "Running dry-run builds for all packages."
|
|
for pkg in $packages; do
|
|
echo "==> Dry-run build: packages.x86_64-linux.${pkg}"
|
|
nix build --dry-run --no-link --no-use-registries --no-accept-flake-config ".#packages.x86_64-linux.${pkg}"
|
|
done
|
|
fi
|
|
|
|
echo
|
|
echo "Maintenance checks complete."
|