nixos

NixOS server files. Mirror from https://git.nordgedanken.dev/kubernetes/nixos
git clone git://archive.git.mtrnord.blog/MTRNord/nixos.git
Log | Files | Refs | README

commit 02f984068264dd725a8853b4ded25495a7d4360d
parent 9324377d43b3b7634f17b3dee2cce4b360e585ef
Author: MTRNord <mtrnord1@gmail.com>
Date:   Wed,  9 Aug 2023 12:07:28 +0200

Disable darling erasure on first boot

Diffstat:
Mdecrypt.sh | 0
Mencrypt.sh | 0
Afs-diff.sh | 23+++++++++++++++++++++++
Mnixos/worker-1/configuration.nix | 116++++++++++++++++++++++++++++++++++++++++----------------------------------------
4 files changed, 81 insertions(+), 58 deletions(-)

diff --git a/decrypt.sh b/decrypt.sh diff --git a/encrypt.sh b/encrypt.sh diff --git a/fs-diff.sh b/fs-diff.sh @@ -0,0 +1,22 @@ +#!/usr/bin/env bash +# fs-diff.sh +set -euo pipefail + +OLD_TRANSID=$(sudo btrfs subvolume find-new /mnt/root-blank 9999999) +OLD_TRANSID=${OLD_TRANSID#transid marker was } + +sudo btrfs subvolume find-new "/mnt/root" "$OLD_TRANSID" | +sed '$d' | +cut -f17- -d' ' | +sort | +uniq | +while read path; do + path="/$path" + if [ -L "$path" ]; then + : # The path is a symbolic link, so is probably handled by NixOS already + elif [ -d "$path" ]; then + : # The path is a directory, ignore + else + echo "$path" + fi +done +\ No newline at end of file diff --git a/nixos/worker-1/configuration.nix b/nixos/worker-1/configuration.nix @@ -181,66 +181,66 @@ # Forbid root login through SSH. permitRootLogin = "no"; # Use keys only. Remove if you want to SSH using password (not recommended) - passwordAuthentication = true; + passwordAuthentication = false; }; - # Darling Erasure - environment.etc = { - nixos.source = "/persist/etc/nixos"; - "NetworkManager/system-connections".source = "/persist/etc/NetworkManager/system-connections"; - adjtime.source = "/persist/etc/adjtime"; - NIXOS.source = "/persist/etc/NIXOS"; - machine-id.source = "/persist/etc/machine-id"; - }; - systemd.tmpfiles.rules = [ - "L /var/lib/NetworkManager/secret_key - - - - /persist/var/lib/NetworkManager/secret_key" - "L /var/lib/NetworkManager/seen-bssids - - - - /persist/var/lib/NetworkManager/seen-bssids" - "L /var/lib/NetworkManager/timestamps - - - - /persist/var/lib/NetworkManager/timestamps" - "L /kubernetes - - - - /persist/kubernetes" - ]; - security.sudo.extraConfig = '' - # rollback results in sudo lectures after each reboot - Defaults lecture = never - ''; - # Note `lib.mkBefore` is used instead of `lib.mkAfter` here. - boot.initrd.postDeviceCommands = pkgs.lib.mkBefore '' - mkdir -p /mnt - - # We first mount the btrfs root to /mnt - # so we can manipulate btrfs subvolumes. - mount -o subvol=/ /dev/mapper/enc /mnt - - # While we're tempted to just delete /root and create - # a new snapshot from /root-blank, /root is already - # populated at this point with a number of subvolumes, - # which makes `btrfs subvolume delete` fail. - # So, we remove them first. - # - # /root contains subvolumes: - # - /root/var/lib/portables - # - /root/var/lib/machines - # - # I suspect these are related to systemd-nspawn, but - # since I don't use it I'm not 100% sure. - # Anyhow, deleting these subvolumes hasn't resulted - # in any issues so far, except for fairly - # benign-looking errors from systemd-tmpfiles. - btrfs subvolume list -o /mnt/root | - cut -f9 -d' ' | - while read subvolume; do - echo "deleting /$subvolume subvolume..." - btrfs subvolume delete "/mnt/$subvolume" - done && - echo "deleting /root subvolume..." && - btrfs subvolume delete /mnt/root - - echo "restoring blank /root subvolume..." - btrfs subvolume snapshot /mnt/root-blank /mnt/root - - # Once we're done rolling back to a blank snapshot, - # we can unmount /mnt and continue on the boot process. - umount /mnt - ''; + # # Darling Erasure + # environment.etc = { + # nixos.source = "/persist/etc/nixos"; + # "NetworkManager/system-connections".source = "/persist/etc/NetworkManager/system-connections"; + # adjtime.source = "/persist/etc/adjtime"; + # NIXOS.source = "/persist/etc/NIXOS"; + # machine-id.source = "/persist/etc/machine-id"; + # }; + # systemd.tmpfiles.rules = [ + # "L /var/lib/NetworkManager/secret_key - - - - /persist/var/lib/NetworkManager/secret_key" + # "L /var/lib/NetworkManager/seen-bssids - - - - /persist/var/lib/NetworkManager/seen-bssids" + # "L /var/lib/NetworkManager/timestamps - - - - /persist/var/lib/NetworkManager/timestamps" + # "L /kubernetes - - - - /persist/kubernetes" + # ]; + # security.sudo.extraConfig = '' + # # rollback results in sudo lectures after each reboot + # Defaults lecture = never + # ''; + # # Note `lib.mkBefore` is used instead of `lib.mkAfter` here. + # boot.initrd.postDeviceCommands = pkgs.lib.mkBefore '' + # mkdir -p /mnt + + # # We first mount the btrfs root to /mnt + # # so we can manipulate btrfs subvolumes. + # mount -o subvol=/ /dev/mapper/enc /mnt + + # # While we're tempted to just delete /root and create + # # a new snapshot from /root-blank, /root is already + # # populated at this point with a number of subvolumes, + # # which makes `btrfs subvolume delete` fail. + # # So, we remove them first. + # # + # # /root contains subvolumes: + # # - /root/var/lib/portables + # # - /root/var/lib/machines + # # + # # I suspect these are related to systemd-nspawn, but + # # since I don't use it I'm not 100% sure. + # # Anyhow, deleting these subvolumes hasn't resulted + # # in any issues so far, except for fairly + # # benign-looking errors from systemd-tmpfiles. + # btrfs subvolume list -o /mnt/root | + # cut -f9 -d' ' | + # while read subvolume; do + # echo "deleting /$subvolume subvolume..." + # btrfs subvolume delete "/mnt/$subvolume" + # done && + # echo "deleting /root subvolume..." && + # btrfs subvolume delete /mnt/root + + # echo "restoring blank /root subvolume..." + # btrfs subvolume snapshot /mnt/root-blank /mnt/root + + # # Once we're done rolling back to a blank snapshot, + # # we can unmount /mnt and continue on the boot process. + # umount /mnt + # ''; # https://nixos.wiki/wiki/FAQ/When_do_I_update_stateVersion system.stateVersion = "23.05";