commit 02f984068264dd725a8853b4ded25495a7d4360d
parent 9324377d43b3b7634f17b3dee2cce4b360e585ef
Author: MTRNord <mtrnord1@gmail.com>
Date: Wed, 9 Aug 2023 12:07:28 +0200
Disable darling erasure on first boot
Diffstat:
4 files changed, 81 insertions(+), 58 deletions(-)
diff --git a/decrypt.sh b/decrypt.sh
diff --git a/encrypt.sh b/encrypt.sh
diff --git a/fs-diff.sh b/fs-diff.sh
@@ -0,0 +1,22 @@
+#!/usr/bin/env bash
+# fs-diff.sh
+set -euo pipefail
+
+OLD_TRANSID=$(sudo btrfs subvolume find-new /mnt/root-blank 9999999)
+OLD_TRANSID=${OLD_TRANSID#transid marker was }
+
+sudo btrfs subvolume find-new "/mnt/root" "$OLD_TRANSID" |
+sed '$d' |
+cut -f17- -d' ' |
+sort |
+uniq |
+while read path; do
+ path="/$path"
+ if [ -L "$path" ]; then
+ : # The path is a symbolic link, so is probably handled by NixOS already
+ elif [ -d "$path" ]; then
+ : # The path is a directory, ignore
+ else
+ echo "$path"
+ fi
+done
+\ No newline at end of file
diff --git a/nixos/worker-1/configuration.nix b/nixos/worker-1/configuration.nix
@@ -181,66 +181,66 @@
# Forbid root login through SSH.
permitRootLogin = "no";
# Use keys only. Remove if you want to SSH using password (not recommended)
- passwordAuthentication = true;
+ passwordAuthentication = false;
};
- # Darling Erasure
- environment.etc = {
- nixos.source = "/persist/etc/nixos";
- "NetworkManager/system-connections".source = "/persist/etc/NetworkManager/system-connections";
- adjtime.source = "/persist/etc/adjtime";
- NIXOS.source = "/persist/etc/NIXOS";
- machine-id.source = "/persist/etc/machine-id";
- };
- systemd.tmpfiles.rules = [
- "L /var/lib/NetworkManager/secret_key - - - - /persist/var/lib/NetworkManager/secret_key"
- "L /var/lib/NetworkManager/seen-bssids - - - - /persist/var/lib/NetworkManager/seen-bssids"
- "L /var/lib/NetworkManager/timestamps - - - - /persist/var/lib/NetworkManager/timestamps"
- "L /kubernetes - - - - /persist/kubernetes"
- ];
- security.sudo.extraConfig = ''
- # rollback results in sudo lectures after each reboot
- Defaults lecture = never
- '';
- # Note `lib.mkBefore` is used instead of `lib.mkAfter` here.
- boot.initrd.postDeviceCommands = pkgs.lib.mkBefore ''
- mkdir -p /mnt
-
- # We first mount the btrfs root to /mnt
- # so we can manipulate btrfs subvolumes.
- mount -o subvol=/ /dev/mapper/enc /mnt
-
- # While we're tempted to just delete /root and create
- # a new snapshot from /root-blank, /root is already
- # populated at this point with a number of subvolumes,
- # which makes `btrfs subvolume delete` fail.
- # So, we remove them first.
- #
- # /root contains subvolumes:
- # - /root/var/lib/portables
- # - /root/var/lib/machines
- #
- # I suspect these are related to systemd-nspawn, but
- # since I don't use it I'm not 100% sure.
- # Anyhow, deleting these subvolumes hasn't resulted
- # in any issues so far, except for fairly
- # benign-looking errors from systemd-tmpfiles.
- btrfs subvolume list -o /mnt/root |
- cut -f9 -d' ' |
- while read subvolume; do
- echo "deleting /$subvolume subvolume..."
- btrfs subvolume delete "/mnt/$subvolume"
- done &&
- echo "deleting /root subvolume..." &&
- btrfs subvolume delete /mnt/root
-
- echo "restoring blank /root subvolume..."
- btrfs subvolume snapshot /mnt/root-blank /mnt/root
-
- # Once we're done rolling back to a blank snapshot,
- # we can unmount /mnt and continue on the boot process.
- umount /mnt
- '';
+ # # Darling Erasure
+ # environment.etc = {
+ # nixos.source = "/persist/etc/nixos";
+ # "NetworkManager/system-connections".source = "/persist/etc/NetworkManager/system-connections";
+ # adjtime.source = "/persist/etc/adjtime";
+ # NIXOS.source = "/persist/etc/NIXOS";
+ # machine-id.source = "/persist/etc/machine-id";
+ # };
+ # systemd.tmpfiles.rules = [
+ # "L /var/lib/NetworkManager/secret_key - - - - /persist/var/lib/NetworkManager/secret_key"
+ # "L /var/lib/NetworkManager/seen-bssids - - - - /persist/var/lib/NetworkManager/seen-bssids"
+ # "L /var/lib/NetworkManager/timestamps - - - - /persist/var/lib/NetworkManager/timestamps"
+ # "L /kubernetes - - - - /persist/kubernetes"
+ # ];
+ # security.sudo.extraConfig = ''
+ # # rollback results in sudo lectures after each reboot
+ # Defaults lecture = never
+ # '';
+ # # Note `lib.mkBefore` is used instead of `lib.mkAfter` here.
+ # boot.initrd.postDeviceCommands = pkgs.lib.mkBefore ''
+ # mkdir -p /mnt
+
+ # # We first mount the btrfs root to /mnt
+ # # so we can manipulate btrfs subvolumes.
+ # mount -o subvol=/ /dev/mapper/enc /mnt
+
+ # # While we're tempted to just delete /root and create
+ # # a new snapshot from /root-blank, /root is already
+ # # populated at this point with a number of subvolumes,
+ # # which makes `btrfs subvolume delete` fail.
+ # # So, we remove them first.
+ # #
+ # # /root contains subvolumes:
+ # # - /root/var/lib/portables
+ # # - /root/var/lib/machines
+ # #
+ # # I suspect these are related to systemd-nspawn, but
+ # # since I don't use it I'm not 100% sure.
+ # # Anyhow, deleting these subvolumes hasn't resulted
+ # # in any issues so far, except for fairly
+ # # benign-looking errors from systemd-tmpfiles.
+ # btrfs subvolume list -o /mnt/root |
+ # cut -f9 -d' ' |
+ # while read subvolume; do
+ # echo "deleting /$subvolume subvolume..."
+ # btrfs subvolume delete "/mnt/$subvolume"
+ # done &&
+ # echo "deleting /root subvolume..." &&
+ # btrfs subvolume delete /mnt/root
+
+ # echo "restoring blank /root subvolume..."
+ # btrfs subvolume snapshot /mnt/root-blank /mnt/root
+
+ # # Once we're done rolling back to a blank snapshot,
+ # # we can unmount /mnt and continue on the boot process.
+ # umount /mnt
+ # '';
# https://nixos.wiki/wiki/FAQ/When_do_I_update_stateVersion
system.stateVersion = "23.05";