From ec309c8fe1001f75a2c9cb73dca95513cdfd22dc Mon Sep 17 00:00:00 2001 From: erik Date: Mon, 13 Jul 2026 01:05:28 +0200 Subject: [PATCH] refactor(deploy): generalize to any config, all params mandatory (no defaults) --- README.md | 22 ++++++++++++++---- deploy | 68 ++++++++++++++++++++++++++++++------------------------- 2 files changed, 54 insertions(+), 36 deletions(-) diff --git a/README.md b/README.md index f2d5198..46d393c 100644 --- a/README.md +++ b/README.md @@ -67,14 +67,26 @@ an installer, partitions via disko, installs. Manual alternative (USB ISO): boot installer, `disko` the disk, then `nixos-install --flake .#jupiter`. -## Rebuild after changes (the daily loop) +## Deploy (the `./deploy` wrapper) + +All arguments mandatory — no default host, no default config. ``` -# from laptop, build + activate on jupiter over SSH: -nixos-rebuild switch --flake .#jupiter \ - --target-host darman@jupiter --use-remote-sudo +./deploy kexec # headless kexec into a RAM installer (RO-root box) +./deploy install # first install; wipes OS disk, ships host key +./deploy switch # rebuild + activate on a running host +./deploy boot|test # stage for next boot / activate without boot entry ``` -Rollback: `nixos-rebuild switch --rollback`, or pick a prior generation at boot. +`` is a `nixosConfigurations` name (`jupiter`, `vps`). Its pre-generated +SSH host key lives at `~/.config/homelab//ssh_host_ed25519_key`. + +Examples: +``` +./deploy switch jupiter jupiter.sol +./deploy install vps 159.195.64.117 +``` +Rollback: `nixos-rebuild switch --rollback` on the host, or pick a prior +generation at boot. ## Adding a service diff --git a/deploy b/deploy index 15029b7..b3f6860 100755 --- a/deploy +++ b/deploy @@ -1,15 +1,18 @@ #!/usr/bin/env bash -# Deploy the jupiter NixOS config. +# Deploy a NixOS host from this flake. ALL arguments are mandatory (no defaults). # -# ./deploy kexec headless-only: for a read-only-root box (ZimaOS) -# where nixos-anywhere can't ssh-copy-id. Uploads a -# kexec installer (our SSH key baked in) to /tmp and -# boots into it. Then run `install`. -# ./deploy install first install onto a fresh box / running installer -# (nixos-anywhere). Wipes the OS disk. Ships host key. -# ./deploy [switch] [host] rebuild + activate on a running jupiter (default). -# ./deploy boot [host] stage for next boot, don't activate now. -# ./deploy test [host] activate without adding a boot entry. +# ./deploy kexec headless kexec into a RAM installer, for a +# read-only-root box (ZimaOS) where +# nixos-anywhere can't ssh-copy-id. Ships our +# SSH login key. Then run `install`. +# ./deploy install first install (nixos-anywhere). Wipes the +# OS disk. Ships the host's sops key. +# ./deploy switch rebuild + activate on a running host. +# ./deploy boot stage for next boot, don't activate now. +# ./deploy test activate without adding a boot entry. +# +# = a nixosConfigurations name (e.g. jupiter, vps). Its pre-generated +# SSH host key must be at ~/.config/homelab//ssh_host_ed25519_key. # # Runs from a non-NixOS host too (nixos-rebuild / nixos-anywhere via `nix run`). set -euo pipefail @@ -18,18 +21,13 @@ REPO="$(cd "$(dirname "$0")" && pwd)" cd "$REPO" export PATH="/nix/var/nix/profiles/default/bin:$PATH" -HOSTKEY="$HOME/.config/homelab/jupiter/ssh_host_ed25519_key" +die() { echo "error: $*" >&2; exit 1; } -cmd="${1:-switch}" -case "$cmd" in - switch|boot|test|install|kexec) shift || true ;; - *) cmd="switch" ;; -esac +cmd="${1:-}"; [ -n "$cmd" ] || die "usage: ./deploy ..." case "$cmd" in kexec) - host="${1:-}" - [ -n "$host" ] || { echo "usage: ./deploy kexec " >&2; exit 1; } + host="${2:-}"; [ -n "$host" ] || die "usage: ./deploy kexec " echo ">> building kexec installer + static tools" nix build .#nixosConfigurations.kexec.config.system.build.kexecInstallerTarball \ @@ -45,7 +43,7 @@ case "$cmd" in o=(-o ControlMaster=auto -o "ControlPath=$cm" -o ControlPersist=300 \ -o StrictHostKeyChecking=accept-new) - echo ">> connecting to root@$host (enter the ZimaOS root password once)" + echo ">> connecting to root@$host (enter the root password once)" ssh "${o[@]}" "root@$host" 'mkdir -p /tmp/bin' scp "${o[@]}" "$cpio" "root@$host:/tmp/bin/cpio" scp "${o[@]}" "$bbox" "root@$host:/tmp/bin/gzip" # busybox as gzip (argv0) @@ -58,34 +56,42 @@ case "$cmd" in ssh "${o[@]}" -O exit "root@$host" 2>/dev/null || true # close control socket echo ">> box is kexec-ing. Wait ~1-2 min for the installer + network, then:" - echo " ./deploy install $host" + echo " ./deploy install $host" ;; install) - host="${1:-}" - [ -n "$host" ] || { echo "usage: ./deploy install " >&2; exit 1; } - [ -f "$HOSTKEY" ] || { echo "missing host key: $HOSTKEY" >&2; exit 1; } + config="${2:-}"; host="${3:-}" + { [ -n "$config" ] && [ -n "$host" ]; } || die "usage: ./deploy install " + hostkey="$HOME/.config/homelab/$config/ssh_host_ed25519_key" + [ -f "$hostkey" ] || die "missing host key: $hostkey" + [ -d "./$config" ] || die "no ./$config directory in the repo" # Stage the pre-generated SSH host key so sops can decrypt on boot #1. stage="$(mktemp -d)" trap 'rm -rf "$stage"' EXIT - install -Dm600 "$HOSTKEY" "$stage/etc/ssh/ssh_host_ed25519_key" - install -Dm644 "$HOSTKEY.pub" "$stage/etc/ssh/ssh_host_ed25519_key.pub" + install -Dm600 "$hostkey" "$stage/etc/ssh/ssh_host_ed25519_key" + install -Dm644 "$hostkey.pub" "$stage/etc/ssh/ssh_host_ed25519_key.pub" - echo ">> nixos-anywhere onto root@$host (OS disk WILL be wiped)" + echo ">> nixos-anywhere .#$config onto root@$host (OS disk WILL be wiped)" nix run github:nix-community/nixos-anywhere -- \ - --flake ".#jupiter" \ + --flake ".#$config" \ --extra-files "$stage" \ - --generate-hardware-config nixos-generate-config ./jupiter/hardware-configuration.nix \ + --generate-hardware-config nixos-generate-config "./$config/hardware-configuration.nix" \ --target-host "root@$host" ;; switch|boot|test) - host="${1:-jupiter}" - echo ">> nixos-rebuild $cmd on darman@$host" + config="${2:-}"; host="${3:-}" + { [ -n "$config" ] && [ -n "$host" ]; } || die "usage: ./deploy $cmd " + + echo ">> nixos-rebuild $cmd .#$config on darman@$host" nix run nixpkgs#nixos-rebuild -- "$cmd" \ - --flake ".#jupiter" \ + --flake ".#$config" \ --target-host "darman@$host" \ --use-remote-sudo ;; + + *) + die "unknown command '$cmd' (kexec|install|switch|boot|test)" + ;; esac