Archived
Check NixOS configurations / eval-hosts (pull_request) Successful in 11m6s
Two real bugs, both hit live: 1. Shebang: #!/run/current-system/sw/bin/bash only resolves on an already-activated NixOS system -- running the checked-out script directly (e.g. from a stock ISO, cloned repo) failed with "cannot execute: required file not found" on a non-NixOS box. Switched to #!/usr/bin/env bash, which resolves identically on NixOS (environment.usrbinenv's own default) and any normal Linux distro. Also fixed the file's missing executable bit. 2. FLAKE_BASE_URL: previously depended on pkgs.replaceVars substituting a Nix-templated @lanDomain@ placeholder at build time -- meaning it only ever worked when baked into the built installer image, not when run straight from a checkout (the literal, unexpanded "@lanDomain@" string reached git as a bogus hostname). Replaced with LAN_DOMAIN in scripts/env.sh (manually kept in sync with variables.nix's lanDomain, same pattern as NIX_CACHE_HOST/nixCacheHost already), sourced by the script itself like every other script in scripts/. Dropped pkgs.replaceVars from modules/installer/common.nix entirely -- scripts/env.sh is now baked into the image alongside auto-install.sh at a matching relative path (/etc/nixos-installer/env.sh next to /etc/nixos-installer/installer/auto-install.sh) so the script's own relative `source` line resolves the same way in both contexts. loginShellInit's invocation path and docs/auto-installer.md updated to match. Verified: shellcheck clean on both scripts, the baked files are byte-identical to their checked-in sources (no templating left to verify), and codex-maintenance.sh (secret grep, fmt, statix, full eval of every host/package including the installer/pxe artifacts) passes clean.
122 lines
4.1 KiB
Nix
122 lines
4.1 KiB
Nix
{ pkgs, lib, vars, ... }:
|
|
|
|
{
|
|
imports = [
|
|
./host-keys.nix
|
|
];
|
|
|
|
networking.useDHCP = lib.mkDefault true;
|
|
|
|
# Recommended over the true default (bypasses ZFS's own import safeguards)
|
|
# per the option's own docs. This installer environment has no ZFS pools
|
|
# of its own to import, so this is a no-op here — just silences the
|
|
# eval-time warning, matching modules/common/configuration.nix.
|
|
boot.zfs.forceImportRoot = false;
|
|
|
|
time.timeZone = vars.timeZone;
|
|
|
|
# Without this, the installer only ever sees cache.nixos.org, which
|
|
# doesn't carry sops-install-secrets (it's built straight from the
|
|
# sops-nix flake's own Go source, not part of nixpkgs) — every install
|
|
# would otherwise compile it from scratch, which is what ran an 8GB LXC
|
|
# container's disk out of space. Push a built copy to nix-cache once
|
|
# (from a machine with real disk headroom) and every future install,
|
|
# of any type, fetches instead of rebuilding.
|
|
nix.settings = {
|
|
substituters = [
|
|
"http://nix-cache"
|
|
"https://cache.nixos.org/"
|
|
];
|
|
trusted-public-keys = [
|
|
"cache.local-1:usoWYanY3Kpq2+kDIS2nhWoLZiRxanmdysdzqCFBHW4="
|
|
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
|
|
];
|
|
};
|
|
|
|
environment = {
|
|
systemPackages = with pkgs; [
|
|
git
|
|
curl
|
|
jq
|
|
parted
|
|
e2fsprogs
|
|
btrfs-progs
|
|
util-linux
|
|
disko
|
|
];
|
|
|
|
# Auto-install script, kept as a real, version-controlled shell file at
|
|
# scripts/installer/auto-install.sh rather than an inline Nix string.
|
|
# It sources scripts/env.sh itself (for LAN_DOMAIN, same as every other
|
|
# script in this repo) rather than relying on Nix-level templating, so
|
|
# it behaves identically whether it's run straight from a git checkout
|
|
# or from here -- baking scripts/env.sh in alongside it at a matching
|
|
# relative path (installer/auto-install.sh -> ../env.sh) is what makes
|
|
# that resolve correctly in both places.
|
|
etc = {
|
|
"nixos-installer/env.sh".source = ../../scripts/env.sh;
|
|
|
|
"nixos-installer/installer/auto-install.sh" = {
|
|
source = ../../scripts/installer/auto-install.sh;
|
|
mode = "0755";
|
|
};
|
|
};
|
|
};
|
|
|
|
programs.git.enable = true;
|
|
|
|
# Run the installer on first login. Previously this copied an /etc file
|
|
# into the nixos user's ~/.bash_profile via an activation script that
|
|
# got dropped in a refactor (and only ever worked for that one user
|
|
# anyway) — loginShellInit is NixOS's native hook for this, applies to
|
|
# any user's login shell (root included), and needs no home-directory
|
|
# file-copying/chown.
|
|
programs.bash.loginShellInit = ''
|
|
if [ -n "$PS1" ] && [ ! -e "$HOME/.auto_install_ran" ]; then
|
|
sudo /etc/nixos-installer/installer/auto-install.sh
|
|
touch "$HOME/.auto_install_ran"
|
|
fi
|
|
'';
|
|
|
|
services.openssh.enable = true;
|
|
|
|
services.openssh.settings = {
|
|
PermitRootLogin = "yes";
|
|
PasswordAuthentication = true;
|
|
};
|
|
|
|
# nixpkgs' own installer profile (profiles/installation-device.nix, pulled
|
|
# in via installation-cd-minimal.nix) sets initialHashedPassword = "" for
|
|
# both users — its own passwordless-login convention for install media.
|
|
# That's a second, non-null password option alongside our hashedPassword
|
|
# below, which NixOS warns about as ambiguous precedence. Force it null
|
|
# rather than adopting passwordless login: this image now also boots over
|
|
# LAN PXE with PasswordAuthentication enabled, so passwordless root SSH
|
|
# would be reachable by anyone on the LAN, not just local console.
|
|
users.users.root = {
|
|
hashedPassword =
|
|
"$6$Kwv9KAyvcurAViQF$H4.u3feqGE7lVoNgkFXhE3n2Pmo//9JYDTCz8ifrVHBxPjwa1xMby7tEZ8Bpt5MXs9Rkx6/YbZWxs5CpH0s/70";
|
|
initialHashedPassword = lib.mkForce null;
|
|
};
|
|
|
|
users.users.${vars.primaryUser} = {
|
|
isNormalUser = true;
|
|
|
|
extraGroups = [
|
|
"wheel"
|
|
];
|
|
|
|
shell = pkgs.bashInteractive;
|
|
|
|
hashedPassword =
|
|
"$6$Kwv9KAyvcurAViQF$H4.u3feqGE7lVoNgkFXhE3n2Pmo//9JYDTCz8ifrVHBxPjwa1xMby7tEZ8Bpt5MXs9Rkx6/YbZWxs5CpH0s/70";
|
|
initialHashedPassword = lib.mkForce null;
|
|
|
|
openssh.authorizedKeys.keys = [
|
|
vars.adminSshKey
|
|
];
|
|
};
|
|
|
|
system.stateVersion = "26.05";
|
|
}
|