- add disko input; jupiter partitions/formats OS disk declaratively - hardware-configuration.nix carries kernel modules only (disko owns fileSystems) - data disk stays a plain unformatted mount, out of disko - vbox unchanged (virtualbox-image supplies its own disk) - README: nixos-anywhere remote install + daily rebuild loop Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
83 lines
3.5 KiB
Markdown
83 lines
3.5 KiB
Markdown
# homelab
|
|
|
|
Flake-based NixOS config. Host: `jupiter` (ZimaBlade, NAS + services).
|
|
|
|
## Structure
|
|
|
|
```
|
|
flake.nix # inputs (nixpkgs, disko) + nixosConfigurations
|
|
jupiter/configuration.nix # real host: imports + bootloader + data mount
|
|
jupiter/disk-config.nix # disko: OS-disk partitions + filesystems
|
|
jupiter/hardware-configuration.nix # PLACEHOLDER — kernel modules, regenerate on target
|
|
jupiter/services.nix # shared: users, ssh, samba, containers, caddy
|
|
jupiter/vm.nix # VirtualBox test image (jupiter-vbox)
|
|
```
|
|
|
|
Two configs from one service definition: `jupiter` (real host, disko-partitioned)
|
|
and `jupiter-vbox` (test OVA). Both import `services.nix`.
|
|
|
|
## Test in VirtualBox (no hardware needed)
|
|
|
|
```
|
|
nix build .#nixosConfigurations.jupiter-vbox.config.system.build.virtualBoxOVA
|
|
VBoxManage import result/*.ova --vsys 0 --vmname jupiter-vbox
|
|
VBoxManage startvm jupiter-vbox --type headless
|
|
```
|
|
Login `darman` / `test`. Forward ports with `VBoxManage modifyvm ... --natpf1`.
|
|
|
|
## First install on the ZimaBlade — nixos-anywhere + disko
|
|
|
|
Wipes the OS disk and installs the flake over SSH. No USB needed if the box
|
|
already runs Linux (ZimaOS) reachable by root SSH — nixos-anywhere kexecs into
|
|
an installer, partitions via disko, installs.
|
|
|
|
> ⚠️ The OS disk in `disk-config.nix` is WIPED. Set `device` to the OS disk
|
|
> ONLY (by-id). Back up / physically identify the NAS data disk first — it must
|
|
> NOT appear in disko. `lsblk -o NAME,SERIAL,SIZE,MODEL` to identify.
|
|
|
|
1. Set the real OS disk id in `jupiter/disk-config.nix`
|
|
(`ls -l /dev/disk/by-id`), and the data-disk mount in `configuration.nix`.
|
|
2. Add your SSH pubkey to `users.users.darman.openssh.authorizedKeys.keys`.
|
|
3. Wire the samba secret (see Notes) — real password, not the VM's plaintext.
|
|
4. Run from your laptop:
|
|
```
|
|
nix run github:nix-community/nixos-anywhere -- \
|
|
--flake .#jupiter \
|
|
--generate-hardware-config nixos-generate-config ./jupiter/hardware-configuration.nix \
|
|
--target-host root@<zimablade-ip>
|
|
```
|
|
`--generate-hardware-config` pulls the target's real kernel modules into the
|
|
placeholder for you. Commit the result. Reboot into NixOS.
|
|
|
|
Manual alternative (USB ISO): boot installer, `disko` the disk, then
|
|
`nixos-install --flake .#jupiter`.
|
|
|
|
## Rebuild after changes (the daily loop)
|
|
|
|
```
|
|
# from laptop, build + activate on jupiter over SSH:
|
|
nixos-rebuild switch --flake .#jupiter \
|
|
--target-host darman@jupiter --use-remote-sudo
|
|
```
|
|
Rollback: `nixos-rebuild switch --rollback`, or pick a prior generation at boot.
|
|
|
|
## Adding a service
|
|
|
|
Copy the `whoami` block in `oci-containers.containers`, swap image/ports/volumes.
|
|
Native NixOS module exists for many apps (Nextcloud, Jellyfin, Grafana...) —
|
|
prefer `services.<app>` over a container when available. Add a `caddy`
|
|
`virtualHosts` block to expose it.
|
|
|
|
## Notes
|
|
|
|
- Backend is Podman with `dockerCompat` — `docker` CLI works, no daemon.
|
|
- Samba keeps its own password DB. `services.samba` never sets it; a systemd
|
|
oneshot (`samba-smbpasswd`) provisions it from `/etc/samba/smb-password`.
|
|
Real host: supply that file via **sops-nix / agenix**, never commit plaintext.
|
|
- Data disk: plain `fileSystems."/mnt/data"` in configuration.nix — kept out of
|
|
disko so it is never formatted. Reference by `by-id` / `by-uuid`.
|
|
- `system.stateVersion` = `26.05`, install-time schema. Do NOT bump on upgrades.
|
|
- Terraform is not used: a single bare-metal box has no provider API. disko +
|
|
nixos-anywhere cover provisioning natively.
|
|
```
|