diff --git a/doc/package.nix b/doc/package.nix index 5ff512a..c627f48 100644 --- a/doc/package.nix +++ b/doc/package.nix @@ -1,5 +1,4 @@ { - pkgs, lib, nixosOptionsDoc, runCommand, diff --git a/intergration-testing/default.nix b/intergration-testing/default.nix index 20f792b..6a9e423 100644 --- a/intergration-testing/default.nix +++ b/intergration-testing/default.nix @@ -2,55 +2,63 @@ wire ? (import ../default.nix).flake.outputs.packages.x86_64-linux.wire, pkgs ? (import ./nixpkgs.nix), ... -}: let +}: +let inherit (pkgs) lib; sshKeys = import (pkgs.path + "/nixos/tests/ssh-keys.nix") pkgs; - commonModule = {pkgs, ...}: { - nix.nixPath = ["nixpkgs=${pkgs.path}"]; - nix.settings.substituters = lib.mkForce []; - virtualisation = { - memorySize = lib.mkForce (1024 * 5); - writableStore = true; - additionalPaths = [ - pkgs.path - (getPrebuiltNode "node") - (import ../default.nix).tarball - (import ../default.nix).flake.inputs.nixpkgs.outPath - ./.. - ]; - }; + commonModule = + { pkgs, ... }: + { + nix.nixPath = [ "nixpkgs=${pkgs.path}" ]; + nix.settings.substituters = lib.mkForce [ ]; + virtualisation = { + memorySize = lib.mkForce (1024 * 5); + writableStore = true; + additionalPaths = [ + pkgs.path + (getPrebuiltNode "node") + (import ../default.nix).tarball + (import ../default.nix).flake.inputs.nixpkgs.outPath + ./.. + ]; + }; - services.openssh.enable = true; - users.users.root.openssh.authorizedKeys.keys = [ - sshKeys.snakeOilPublicKey - ]; + services.openssh.enable = true; + users.users.root.openssh.authorizedKeys.keys = [ + sshKeys.snakeOilPublicKey + ]; - boot.loader.grub.enable = false; - }; + boot.loader.grub.enable = false; + }; - deployerModule = {pkgs, ...}: { - imports = [commonModule]; - environment.systemPackages = [ - wire - pkgs.git - (pkgs.writeShellScriptBin "run-copy-stderr" '' - exec "$@" 2>&1 - '') - ]; - }; + deployerModule = + { pkgs, ... }: + { + imports = [ commonModule ]; + environment.systemPackages = [ + wire + pkgs.git + (pkgs.writeShellScriptBin "run-copy-stderr" '' + exec "$@" 2>&1 + '') + ]; + }; - targetModule = {...}: { - imports = [commonModule]; - system.switch.enable = true; - }; + targetModule = + { ... }: + { + imports = [ commonModule ]; + system.switch.enable = true; + }; nodes = { deployer = deployerModule; node = targetModule; }; - evalTest = module: + evalTest = + module: pkgs.testers.runNixOSTest { inherit nodes; name = "deployer"; @@ -62,17 +70,19 @@ }; evaluate = import ../runtime/evaluate.nix; - getPrebuiltNode = name: + getPrebuiltNode = + name: (evaluate { hive = import ./hive.nix; path = ./.; - nixosConfigurations = {}; + nixosConfigurations = { }; nixpkgs = pkgs; - }) - .getTopLevel - name; + }).getTopLevel + name; in - evalTest ({pkgs, ...}: { +evalTest ( + { pkgs, ... }: + { testScript = _: '' start_all() @@ -94,4 +104,5 @@ in # node.succeed("stat /etc/post-switch") ''; - }) + } +) diff --git a/intergration-testing/hive.nix b/intergration-testing/hive.nix index 87a06cd..670c3b3 100644 --- a/intergration-testing/hive.nix +++ b/intergration-testing/hive.nix @@ -1,42 +1,47 @@ { meta.nixpkgs = import ./nixpkgs.nix; - node = { - pkgs, - lib, - ... - }: let - sshKeys = import (pkgs.path + "/nixos/tests/ssh-keys.nix") pkgs; - in { - deployment.target.host = "node"; - deployment.buildOnTarget = false; + node = + { + pkgs, + lib, + ... + }: + let + sshKeys = import (pkgs.path + "/nixos/tests/ssh-keys.nix") pkgs; + in + { + deployment.target.host = "node"; + deployment.buildOnTarget = false; - nix.nixPath = ["nixpkgs=/nixpkgs"]; - nix.settings.substituters = lib.mkForce []; - virtualisation = { - memorySize = lib.mkForce (1024 * 5); - writableStore = true; - additionalPaths = [pkgs.path]; - }; + nix.nixPath = [ "nixpkgs=/nixpkgs" ]; + nix.settings.substituters = lib.mkForce [ ]; + virtualisation = { + memorySize = lib.mkForce (1024 * 5); + writableStore = true; + additionalPaths = [ pkgs.path ]; + }; - services.openssh.enable = true; - users.users.root.openssh.authorizedKeys.keys = [ - sshKeys.snakeOilPublicKey - ]; + services.openssh.enable = true; + users.users.root.openssh.authorizedKeys.keys = [ + sshKeys.snakeOilPublicKey + ]; - system.switch.enable = true; + system.switch.enable = true; - imports = let - # WTF is this and why does it work? - pkgs = import ./nixpkgs.nix; - in [ - (pkgs.path + "/nixos/lib/testing/nixos-test-base.nix") - ]; + imports = + let + # WTF is this and why does it work? + pkgs = import ./nixpkgs.nix; + in + [ + (pkgs.path + "/nixos/lib/testing/nixos-test-base.nix") + ]; - boot.loader.grub.enable = false; + boot.loader.grub.enable = false; - environment.etc."post-switch" = { - text = "exists"; + environment.etc."post-switch" = { + text = "exists"; + }; }; - }; } diff --git a/intergration-testing/nixpkgs.nix b/intergration-testing/nixpkgs.nix index 9605ebf..02f63a0 100644 --- a/intergration-testing/nixpkgs.nix +++ b/intergration-testing/nixpkgs.nix @@ -1 +1,4 @@ -let nixpkgs = (import ../default.nix).flake.inputs.nixpkgs.outPath; in import nixpkgs {} +let + nixpkgs = (import ../default.nix).flake.inputs.nixpkgs.outPath; +in +import nixpkgs { } diff --git a/runtime/evaluate.nix b/runtime/evaluate.nix index 3d7e0b2..b6bae6b 100644 --- a/runtime/evaluate.nix +++ b/runtime/evaluate.nix @@ -1,47 +1,50 @@ { hive, path, - nixosConfigurations ? {}, + nixosConfigurations ? { }, nixpkgs ? null, -}: let +}: +let module = import ./module.nix; mergedHive = { - meta = {}; + meta = { }; - defaults = {}; + defaults = { }; } // hive # Map nixosConfigurations into nodes // (builtins.mapAttrs (name: value: { - imports = - value._module.args.modules - # Include any custom stuff within `colmena` - ++ [hive.${name} or {}]; - }) - nixosConfigurations); + imports = + value._module.args.modules + # Include any custom stuff within `colmena` + ++ [ hive.${name} or { } ]; + }) nixosConfigurations); nodeNames = builtins.filter ( name: - !builtins.elem name [ - "meta" - "defaults" - ] + !builtins.elem name [ + "meta" + "defaults" + ] ) (builtins.attrNames mergedHive); resolvedNixpkgs = - if mergedHive.meta ? "nixpkgs" - then + if mergedHive.meta ? "nixpkgs" then # support '' and 'import {}' - if builtins.isPath mergedHive.meta.nixpkgs - then import mergedHive.meta.nixpkgs {} - else mergedHive.meta.nixpkgs - else import nixpkgs {}; + if builtins.isPath mergedHive.meta.nixpkgs then + import mergedHive.meta.nixpkgs { } + else + mergedHive.meta.nixpkgs + else + import nixpkgs { }; - evaluateNode = name: let - evalConfig = import (resolvedNixpkgs.path + "/nixos/lib/eval-config.nix"); - in + evaluateNode = + name: + let + evalConfig = import (resolvedNixpkgs.path + "/nixos/lib/eval-config.nix"); + in evalConfig { modules = [ module @@ -50,22 +53,20 @@ mergedHive.${name} ]; - specialArgs = - { - inherit name nodes; - } - // mergedHive.meta.specialArgs or {}; + specialArgs = { + inherit name nodes; + } // mergedHive.meta.specialArgs or { }; }; nodes = builtins.listToAttrs ( map (name: { inherit name; value = evaluateNode name; - }) - nodeNames + }) nodeNames ); getTopLevel = node: (evaluateNode node).config.system.build.toplevel.drvPath; -in rec { +in +rec { inherit evaluateNode getTopLevel nodes; inspect = { diff --git a/runtime/module.nix b/runtime/module.nix index 7501e70..1ee0e26 100644 --- a/runtime/module.nix +++ b/runtime/module.nix @@ -3,16 +3,20 @@ name, config, ... -}: let +}: +let inherit (lib) types; -in { - imports = let - inherit (lib) mkAliasOptionModule; - in [ - (mkAliasOptionModule ["deployment" "targetHost"] ["deployment" "target" "host"]) - (mkAliasOptionModule ["deployment" "targetUser"] ["deployment" "target" "user"]) - (mkAliasOptionModule ["deployment" "targetPort"] ["deployment" "target" "port"]) - ]; +in +{ + imports = + let + inherit (lib) mkAliasOptionModule; + in + [ + (mkAliasOptionModule [ "deployment" "targetHost" ] [ "deployment" "target" "host" ]) + (mkAliasOptionModule [ "deployment" "targetUser" ] [ "deployment" "target" "user" ]) + (mkAliasOptionModule [ "deployment" "targetPort" ] [ "deployment" "target" "port" ]) + ]; options.deployment = { target = lib.mkOption { @@ -27,7 +31,7 @@ in { type = types.listOf types.str; description = "Additional hosts to attempt to connect to, if `deployment.target.host` cannot be reached."; default = lib.singleton name; - apply = list: lib.unique ([name] ++ list); + apply = list: lib.unique ([ name ] ++ list); }; user = lib.mkOption { type = types.str; @@ -42,7 +46,7 @@ in { }; }; description = "Describes the target for this node"; - default = {}; + default = { }; }; buildOnTarget = lib.mkOption { @@ -59,9 +63,12 @@ in { tags = lib.mkOption { type = types.listOf types.str; - default = []; + default = [ ]; description = "Tags for node."; - example = ["arm" "cloud"]; + example = [ + "arm" + "cloud" + ]; }; _keys = lib.mkOption { @@ -70,65 +77,83 @@ in { }; keys = lib.mkOption { - type = types.attrsOf (types.submodule ({ - name, - config, - ... - }: { - imports = let - inherit (lib) mkAliasOptionModule; - in [ - (mkAliasOptionModule ["keyFile"] ["source"]) - (mkAliasOptionModule ["keyCommand"] ["source"]) - (mkAliasOptionModule ["text"] ["source"]) - ]; - options = { - name = lib.mkOption { - type = types.str; - default = name; - description = "Filename of the secret."; - }; - destDir = lib.mkOption { - type = types.path; - default = "/run/keys/"; - description = "Destination directory for the secret. Change this to something other than `/run/keys/` for keys to persist past reboots."; - }; - path = lib.mkOption { - internal = true; - type = types.path; - default = "${config.destDir}/${config.name}"; - }; - group = lib.mkOption { - type = types.str; - default = "root"; - description = "Group to own the key. If this group does not exist this will silently fail and the key will be owned by gid 0."; - }; - user = lib.mkOption { - type = types.str; - default = "root"; - description = "User to own the key. If this user does not exist this will silently fail and the key will be owned by uid 0."; - }; - permissions = lib.mkOption { - type = types.str; - default = "0600"; - description = "Unix Octal permissions, in string format, for the key."; - }; - source = lib.mkOption { - type = types.oneOf [types.str types.path (types.listOf types.str)]; - description = "Source of the key. Either a path to a file, a literal string, or a command to generate the key."; - }; - uploadAt = lib.mkOption { - type = types.enum ["pre-activation" "post-activation"]; - default = "pre-activation"; - description = "When to upload the key. Either `pre-activation` or `post-activation`."; - }; - }; - })); + type = types.attrsOf ( + types.submodule ( + { + name, + config, + ... + }: + { + imports = + let + inherit (lib) mkAliasOptionModule; + in + [ + (mkAliasOptionModule [ "keyFile" ] [ "source" ]) + (mkAliasOptionModule [ "keyCommand" ] [ "source" ]) + (mkAliasOptionModule [ "text" ] [ "source" ]) + ]; + options = { + name = lib.mkOption { + type = types.str; + default = name; + description = "Filename of the secret."; + }; + destDir = lib.mkOption { + type = types.path; + default = "/run/keys/"; + description = "Destination directory for the secret. Change this to something other than `/run/keys/` for keys to persist past reboots."; + }; + path = lib.mkOption { + internal = true; + type = types.path; + default = "${config.destDir}/${config.name}"; + }; + group = lib.mkOption { + type = types.str; + default = "root"; + description = "Group to own the key. If this group does not exist this will silently fail and the key will be owned by gid 0."; + }; + user = lib.mkOption { + type = types.str; + default = "root"; + description = "User to own the key. If this user does not exist this will silently fail and the key will be owned by uid 0."; + }; + permissions = lib.mkOption { + type = types.str; + default = "0600"; + description = "Unix Octal permissions, in string format, for the key."; + }; + source = lib.mkOption { + type = types.oneOf [ + types.str + types.path + (types.listOf types.str) + ]; + description = "Source of the key. Either a path to a file, a literal string, or a command to generate the key."; + }; + uploadAt = lib.mkOption { + type = types.enum [ + "pre-activation" + "post-activation" + ]; + default = "pre-activation"; + description = "When to upload the key. Either `pre-activation` or `post-activation`."; + }; + }; + } + ) + ); description = "Secrets to be deployed to the node."; - default = {}; + default = { }; example = { "wireless.env" = { - source = ["gpg" "--decrypt" "secrets/wireless.env.gpg"]; + source = [ + "gpg" + "--decrypt" + "secrets/wireless.env.gpg" + ]; destDir = "/etc/keys/"; }; diff --git a/tests/rust/default_values_match/hive.nix b/tests/rust/default_values_match/hive.nix index bbc5b82..2e1b0c7 100644 --- a/tests/rust/default_values_match/hive.nix +++ b/tests/rust/default_values_match/hive.nix @@ -3,5 +3,5 @@ nixpkgs = ; }; - NAME = {}; + NAME = { }; } diff --git a/tests/rust/no_nixpkgs/hive.nix b/tests/rust/no_nixpkgs/hive.nix index e01f7da..2a0ca29 100644 --- a/tests/rust/no_nixpkgs/hive.nix +++ b/tests/rust/no_nixpkgs/hive.nix @@ -1,3 +1,3 @@ { - node-a = {}; + node-a = { }; } diff --git a/tests/rust/non_trivial_hive/hive.nix b/tests/rust/non_trivial_hive/hive.nix index ef599d5..a9e1d0a 100644 --- a/tests/rust/non_trivial_hive/hive.nix +++ b/tests/rust/non_trivial_hive/hive.nix @@ -3,23 +3,25 @@ nixpkgs = ; }; - defaults = { - name, - nodes, - lib, - ... - }: { - deployment.target = { - host = "name"; - user = "root"; - }; + defaults = + { + name, + nodes, + lib, + ... + }: + { + deployment.target = { + host = "name"; + user = "root"; + }; - assertions = [ - { - assertion = (lib.lists.elemAt nodes 1) == name; - } - ]; - }; + assertions = [ + { + assertion = (lib.lists.elemAt nodes 1) == name; + } + ]; + }; node-a = { deployment.keys."a" = { diff --git a/tests/rust/test_hive_dot_nix_priority/flake.nix b/tests/rust/test_hive_dot_nix_priority/flake.nix index 0967ef4..ffcd441 100644 --- a/tests/rust/test_hive_dot_nix_priority/flake.nix +++ b/tests/rust/test_hive_dot_nix_priority/flake.nix @@ -1 +1 @@ -{} +{ } diff --git a/tests/rust/test_hive_dot_nix_priority/hive.nix b/tests/rust/test_hive_dot_nix_priority/hive.nix index 0967ef4..ffcd441 100644 --- a/tests/rust/test_hive_dot_nix_priority/hive.nix +++ b/tests/rust/test_hive_dot_nix_priority/hive.nix @@ -1 +1 @@ -{} +{ }