Archived
Check NixOS configurations / eval-hosts (push) Failing after 11m18s
Finishes the nix-auto-installer migration: scripts/prepare-host-key.sh
and the local host-keys/ directory (gitignored, private key material,
never committed — moved as plain files, not through git history)
weren't carried over in the initial migration.
Also implements automatic key staging, replacing the manual
scp-after-boot step:
- modules/installer/host-keys.nix reads host-keys/ via
builtins.getEnv, which Nix silently returns as "" under normal
(non---impure) evaluation — the module is a no-op by default, safe
for CI, until explicitly opted into:
NIXOS_HOST_KEYS_DIR=$(pwd)/host-keys nix build .#iso --impure
When built this way every key present gets baked into the image at
/etc/host-keys/, and auto-install.sh installs whichever one matches
the flake target selected at install time — no manual per-host scp.
- This deliberately includes the PXE netboot variant, even though
pxe-boot serves it unauthenticated over LAN HTTP: accepted
explicitly as a reasonable trade-off for a network that sits behind
LAN-only infrastructure, not the open internet. auto-install.sh
still falls back to /root/host-keys (manual scp) if a key isn't
baked in, so images built without --impure keep working exactly as
before.
- docs/auto-installer.md replaces nix-auto-installer's README,
updated for in-repo paths and the new build flow.
Verified: normal `nix eval` (no --impure) evaluates identically across
all 19 nixosConfigurations + 4 packages with zero host-keys/* entries
(CI-unaffected); with --impure + the env var set, all three installer
variants (installer/ISO, proxmox-lxc, pxe) correctly embed every key
in host-keys/.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01La55Nsss8jZ7ZuzUV9mfot
76 lines
2.9 KiB
Bash
Executable File
76 lines
2.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Generates a new machine's SSH host key ahead of installing it, so
|
|
# sops-nix has something to derive an age key from before the target
|
|
# ever boots.
|
|
#
|
|
# Why this is needed: sops-nix derives each host's decryption key from
|
|
# its own /etc/ssh/ssh_host_ed25519_key at *activation* time, but that
|
|
# activation runs before systemd would otherwise generate this key on
|
|
# first boot (sshd-keygen is a normal systemd service gated behind
|
|
# multi-user.target; activation scripts run earlier than that). Without
|
|
# pre-seeding, secrets — including the root/nixos login password — fail
|
|
# to decrypt on the machine's very first boot.
|
|
#
|
|
# This script only touches your admin workstation and this repo's
|
|
# .sops.yaml (it never contacts the target machine). Run it, follow the
|
|
# printed next steps, then use the resulting key with the auto-install.sh
|
|
# prompt (see modules/installer/common.nix) when you actually install the
|
|
# new machine.
|
|
set -euo pipefail
|
|
|
|
repo_root="$(cd "$(dirname "$0")/.." && pwd)"
|
|
|
|
hostname="${1:?usage: scripts/prepare-host-key.sh <hostname> [path-to-nixos-repo]}"
|
|
nixos_repo="${2:-$repo_root}"
|
|
sops_yaml="${nixos_repo}/.sops.yaml"
|
|
|
|
if [[ ! -f "$sops_yaml" ]]; then
|
|
echo "ERROR: $sops_yaml not found. Pass the nixos repo path as the 2nd argument." >&2
|
|
exit 1
|
|
fi
|
|
|
|
keydir="${repo_root}/host-keys"
|
|
mkdir -p "$keydir"
|
|
keyfile="${keydir}/${hostname}_ssh_host_ed25519_key"
|
|
|
|
if [[ -f "$keyfile" ]]; then
|
|
echo "ERROR: $keyfile already exists. Remove it first if you want to regenerate." >&2
|
|
exit 1
|
|
fi
|
|
|
|
nix-shell -p openssh --run "ssh-keygen -t ed25519 -N '' -C '${hostname}' -f '${keyfile}'" >/dev/null
|
|
|
|
age_pub="$(nix-shell -p ssh-to-age --run "ssh-to-age -i '${keyfile}.pub'")"
|
|
|
|
cat <<EOF
|
|
|
|
Generated: ${keyfile}(.pub)
|
|
|
|
=== 1. Add this line under keys: in ${sops_yaml} ===
|
|
- &${hostname} ${age_pub}
|
|
|
|
=== 2. Add *${hostname} to whichever creation_rules key_groups this host needs ===
|
|
(e.g. secrets/common.yaml always; add a per-host secrets/${hostname}.yaml
|
|
block too if this host will get its own secrets, same pattern as
|
|
nix-cache/server.)
|
|
|
|
=== 3. Re-encrypt every secrets file you just added it to ===
|
|
nix-shell -p sops --run 'sops updatekeys ${nixos_repo}/secrets/common.yaml'
|
|
|
|
=== 4. Commit + push this repo so the flake build picks up the new recipient ===
|
|
|
|
=== 5. Get the key onto the installer, one of two ways ===
|
|
a) Rebuild the installer image with all host-keys/ baked in (see
|
|
docs/auto-installer.md):
|
|
NIXOS_HOST_KEYS_DIR="${keydir}" nix build .#iso --impure
|
|
(or .#lxc / .#pxe / .#all — --impure is required since host-keys/
|
|
is gitignored and flakes can't see it otherwise)
|
|
|
|
b) Or, for an image already built without keys, scp it in after boot:
|
|
scp ${keyfile}{,.pub} root@<target-ip>:/root/host-keys/
|
|
|
|
Then continue with /etc/auto-install.sh as normal — it checks
|
|
/etc/host-keys (baked in) before /root/host-keys (scp'd) and installs
|
|
whichever it finds before running nixos-install.
|
|
EOF
|