nixos

NixOS server files. Mirror from https://git.nordgedanken.dev/kubernetes/nixos
git clone git://archive.git.mtrnord.blog/MTRNord/nixos.git
Log | Files | Refs | README

commit 74093c43498951224008cf194d8104dc9400a542
parent 287c8c20c5568ebeeeba21d3d89d1b1cda4f092c
Author: MTRNord <mtrnord1@gmail.com>
Date:   Wed,  9 Aug 2023 15:30:22 +0200

Activate Darling Erasure

Diffstat:
Mnixos/worker-1/configuration.nix | 108++++++++++++++++++++++++++++++++++++++++----------------------------------------
1 file changed, 54 insertions(+), 54 deletions(-)

diff --git a/nixos/worker-1/configuration.nix b/nixos/worker-1/configuration.nix @@ -214,60 +214,60 @@ }; }; - # # Darling Erasure - # environment.etc = { - # nixos.source = "/persist/etc/nixos"; - # adjtime.source = "/persist/etc/adjtime"; - # NIXOS.source = "/persist/etc/NIXOS"; - # machine-id.source = "/persist/etc/machine-id"; - # }; - # systemd.tmpfiles.rules = [ - # "L /etc/secrets/initrd/ssh_host_ed25519_key - - - - /persist/etc/secrets/initrd/ssh_host_ed25519_key" - # "L /etc/secrets/initrd/ssh_host_ed25519_key.pub - - - - /persist/etc/secrets/initrd/ssh_host_ed25519_key.pub" - # ]; - # security.sudo.extraConfig = '' - # # rollback results in sudo lectures after each reboot - # Defaults lecture = never - # ''; - # # Note `lib.mkBefore` is used instead of `lib.mkAfter` here. - # boot.initrd.postDeviceCommands = pkgs.lib.mkBefore '' - # mkdir -p /mnt - - # # We first mount the btrfs root to /mnt - # # so we can manipulate btrfs subvolumes. - # mount -o subvol=/ /dev/mapper/enc /mnt - - # # While we're tempted to just delete /root and create - # # a new snapshot from /root-blank, /root is already - # # populated at this point with a number of subvolumes, - # # which makes `btrfs subvolume delete` fail. - # # So, we remove them first. - # # - # # /root contains subvolumes: - # # - /root/var/lib/portables - # # - /root/var/lib/machines - # # - # # I suspect these are related to systemd-nspawn, but - # # since I don't use it I'm not 100% sure. - # # Anyhow, deleting these subvolumes hasn't resulted - # # in any issues so far, except for fairly - # # benign-looking errors from systemd-tmpfiles. - # btrfs subvolume list -o /mnt/root | - # cut -f9 -d' ' | - # while read subvolume; do - # echo "deleting /$subvolume subvolume..." - # btrfs subvolume delete "/mnt/$subvolume" - # done && - # echo "deleting /root subvolume..." && - # btrfs subvolume delete /mnt/root - - # echo "restoring blank /root subvolume..." - # btrfs subvolume snapshot /mnt/root-blank /mnt/root - - # # Once we're done rolling back to a blank snapshot, - # # we can unmount /mnt and continue on the boot process. - # umount /mnt - # ''; + # Darling Erasure + environment.etc = { + nixos.source = "/persist/etc/nixos"; + adjtime.source = "/persist/etc/adjtime"; + NIXOS.source = "/persist/etc/NIXOS"; + machine-id.source = "/persist/etc/machine-id"; + }; + systemd.tmpfiles.rules = [ + "L /etc/secrets/initrd/ssh_host_ed25519_key - - - - /persist/etc/secrets/initrd/ssh_host_ed25519_key" + "L /etc/secrets/initrd/ssh_host_ed25519_key.pub - - - - /persist/etc/secrets/initrd/ssh_host_ed25519_key.pub" + ]; + security.sudo.extraConfig = '' + # rollback results in sudo lectures after each reboot + Defaults lecture = never + ''; + # Note `lib.mkBefore` is used instead of `lib.mkAfter` here. + boot.initrd.postDeviceCommands = pkgs.lib.mkBefore '' + mkdir -p /mnt + + # We first mount the btrfs root to /mnt + # so we can manipulate btrfs subvolumes. + mount -o subvol=/ /dev/mapper/enc /mnt + + # While we're tempted to just delete /root and create + # a new snapshot from /root-blank, /root is already + # populated at this point with a number of subvolumes, + # which makes `btrfs subvolume delete` fail. + # So, we remove them first. + # + # /root contains subvolumes: + # - /root/var/lib/portables + # - /root/var/lib/machines + # + # I suspect these are related to systemd-nspawn, but + # since I don't use it I'm not 100% sure. + # Anyhow, deleting these subvolumes hasn't resulted + # in any issues so far, except for fairly + # benign-looking errors from systemd-tmpfiles. + btrfs subvolume list -o /mnt/root | + cut -f9 -d' ' | + while read subvolume; do + echo "deleting /$subvolume subvolume..." + btrfs subvolume delete "/mnt/$subvolume" + done && + echo "deleting /root subvolume..." && + btrfs subvolume delete /mnt/root + + echo "restoring blank /root subvolume..." + btrfs subvolume snapshot /mnt/root-blank /mnt/root + + # Once we're done rolling back to a blank snapshot, + # we can unmount /mnt and continue on the boot process. + umount /mnt + ''; # https://nixos.wiki/wiki/FAQ/When_do_I_update_stateVersion system.stateVersion = "23.05";