- git-mv jupiter/ vps/ into hosts/; fix ../ -> ../../ for common/services/secrets - flake.nix + deploy point at hosts/<config>/ - README structure updated - verified: jupiter/vps/vbox all eval
100 lines
4.4 KiB
Bash
Executable File
100 lines
4.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Deploy a NixOS host from this flake. ALL arguments are mandatory (no defaults).
|
|
#
|
|
# ./deploy kexec <host> headless kexec into a RAM installer, for a
|
|
# read-only-root box (ZimaOS) where
|
|
# nixos-anywhere can't ssh-copy-id. Ships our
|
|
# SSH login key. Then run `install`.
|
|
# ./deploy install <config> <host> first install (nixos-anywhere). Wipes the
|
|
# OS disk. Ships the host's sops key.
|
|
# ./deploy switch <config> <host> rebuild + activate on a running host.
|
|
# ./deploy boot <config> <host> stage for next boot, don't activate now.
|
|
# ./deploy test <config> <host> activate without adding a boot entry.
|
|
#
|
|
# <config> = a nixosConfigurations name (e.g. jupiter, vps). Its pre-generated
|
|
# SSH host key must be at ~/.config/homelab/<config>/ssh_host_ed25519_key.
|
|
#
|
|
# Runs from a non-NixOS host too (nixos-rebuild / nixos-anywhere via `nix run`).
|
|
set -euo pipefail
|
|
|
|
# Locate the repo root (flake dir) regardless of where this script lives on disk.
|
|
SCRIPT_DIR="$(cd "$(dirname "$(realpath "$0")")" && pwd)"
|
|
REPO="$(git -C "$SCRIPT_DIR" rev-parse --show-toplevel 2>/dev/null || dirname "$SCRIPT_DIR")"
|
|
cd "$REPO"
|
|
export PATH="/nix/var/nix/profiles/default/bin:$PATH"
|
|
|
|
die() { echo "error: $*" >&2; exit 1; }
|
|
|
|
cmd="${1:-}"; [ -n "$cmd" ] || die "usage: ./deploy <kexec|install|switch|boot|test> ..."
|
|
|
|
case "$cmd" in
|
|
kexec)
|
|
host="${2:-}"; [ -n "$host" ] || die "usage: ./deploy kexec <host>"
|
|
|
|
echo ">> building kexec installer + static tools"
|
|
nix build .#nixosConfigurations.kexec.config.system.build.kexecInstallerTarball \
|
|
-o result-kexec
|
|
tb="$(ls result-kexec/*.tar.gz | head -1)"
|
|
# kexec/run rebuilds an initrd with `cpio` + `gzip` from PATH — ZimaOS lacks
|
|
# both. Ship static ones: GNU cpio (reliable -o -H newc), busybox as gzip.
|
|
cpio="$(nix build --no-link --print-out-paths nixpkgs#pkgsStatic.cpio)/bin/cpio"
|
|
bbox="$(nix build --no-link --print-out-paths nixpkgs#pkgsStatic.busybox)/bin/busybox"
|
|
|
|
# One password prompt: multiplex scp + ssh over a shared control connection.
|
|
cm="/tmp/homelab-cm-%r@%h:%p"
|
|
o=(-o ControlMaster=auto -o "ControlPath=$cm" -o ControlPersist=300 \
|
|
-o StrictHostKeyChecking=accept-new)
|
|
|
|
echo ">> connecting to root@$host (enter the root password once)"
|
|
ssh "${o[@]}" "root@$host" 'mkdir -p /tmp/bin'
|
|
scp "${o[@]}" "$cpio" "root@$host:/tmp/bin/cpio"
|
|
scp "${o[@]}" "$bbox" "root@$host:/tmp/bin/gzip" # busybox as gzip (argv0)
|
|
|
|
echo ">> streaming installer + kexec-ing. SSH drops as the box jumps into the"
|
|
echo " RAM installer. Disks are untouched."
|
|
ssh "${o[@]}" "root@$host" \
|
|
'chmod +x /tmp/bin/*; mkdir -p /tmp/k && tar -C /tmp/k -xzf - && PATH=/tmp/bin:$PATH /tmp/k/kexec/run' \
|
|
< "$tb" || true
|
|
|
|
ssh "${o[@]}" -O exit "root@$host" 2>/dev/null || true # close control socket
|
|
echo ">> box is kexec-ing. Wait ~1-2 min for the installer + network, then:"
|
|
echo " ./deploy install <config> $host"
|
|
;;
|
|
|
|
install)
|
|
config="${2:-}"; host="${3:-}"
|
|
{ [ -n "$config" ] && [ -n "$host" ]; } || die "usage: ./deploy install <config> <host>"
|
|
hostkey="$HOME/.config/homelab/$config/ssh_host_ed25519_key"
|
|
[ -f "$hostkey" ] || die "missing host key: $hostkey"
|
|
[ -d "./hosts/$config" ] || die "no ./hosts/$config directory in the repo"
|
|
|
|
# Stage the pre-generated SSH host key so sops can decrypt on boot #1.
|
|
stage="$(mktemp -d)"
|
|
trap 'rm -rf "$stage"' EXIT
|
|
install -Dm600 "$hostkey" "$stage/etc/ssh/ssh_host_ed25519_key"
|
|
install -Dm644 "$hostkey.pub" "$stage/etc/ssh/ssh_host_ed25519_key.pub"
|
|
|
|
echo ">> nixos-anywhere .#$config onto root@$host (OS disk WILL be wiped)"
|
|
nix run github:nix-community/nixos-anywhere -- \
|
|
--flake ".#$config" \
|
|
--extra-files "$stage" \
|
|
--generate-hardware-config nixos-generate-config "./hosts/$config/hardware-configuration.nix" \
|
|
--target-host "root@$host"
|
|
;;
|
|
|
|
switch|boot|test)
|
|
config="${2:-}"; host="${3:-}"
|
|
{ [ -n "$config" ] && [ -n "$host" ]; } || die "usage: ./deploy $cmd <config> <host>"
|
|
|
|
echo ">> nixos-rebuild $cmd .#$config on darman@$host"
|
|
nix run nixpkgs#nixos-rebuild -- "$cmd" \
|
|
--flake ".#$config" \
|
|
--target-host "darman@$host" \
|
|
--use-remote-sudo
|
|
;;
|
|
|
|
*)
|
|
die "unknown command '$cmd' (kexec|install|switch|boot|test)"
|
|
;;
|
|
esac
|