nix and nixos configs
Something went wrong. Try again.
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788default: help# Build the 13-inch-thin-cannon install ISO (disko-backed, hardened)build: nix build .#nixosConfigurations."13-inch-thin-cannon-iso".config.system.build.isoImage# Alias for buildiso: build# Copy OVMF firmware into the tests dir (result/iso and result/FV cannot coexist)ovmf: chmod -R u+w 13-inch-thin-cannon/tests/ovmf 2>/dev/null || true rm -rf 13-inch-thin-cannon/tests/ovmf mkdir -p 13-inch-thin-cannon/tests/ovmf cp -a $(nix build .#ovmf --no-link --print-out-paths)/FV 13-inch-thin-cannon/tests/ovmf/# Full lifecycle: build the ISO, then test live boot, installation, and bootup: build test-iso# Decrypt an age secret with this machine's SSH host identity.# Usage: `just decrypt-secret secrets/example.age`decrypt-secret secret: nix shell nixpkgs#age --command sudo age --decrypt -i /etc/ssh/ssh_host_ed25519_key -o - "{{secret}}"# Encrypt a yescrypt hash for the file_magic account with agenix. Set# AGE_RECIPIENT to the target host's SSH public key when running remotely.set-file-magic-password: #!/usr/bin/env bash set -euo pipefail secret_file="secrets/file_magic-password.age" recipient_source="${AGE_RECIPIENT:-/etc/ssh/ssh_host_ed25519_key.pub}" if [[ -f "$recipient_source" ]]; then recipient="$(<"$recipient_source")" else recipient="$recipient_source" fi if [[ -z "$recipient" ]]; then echo "AGE_RECIPIENT or /etc/ssh/ssh_host_ed25519_key.pub is required" >&2 exit 1 fi read -r -s -p "file_magic password: " password printf '\n' read -r -s -p "Repeat password: " password_repeat printf '\n' if [[ "$password" != "$password_repeat" ]]; then echo "Passwords do not match" >&2 exit 1 fi hash="$(printf '%s' "$password" | mkpasswd -m yescrypt -s)" unset password password_repeat rules_file="$(mktemp)" hash_file="$(mktemp)" trap 'rm -f "$rules_file" "$hash_file"' EXIT cat >"$rules_file" <<EOF { "secrets/file_magic-password.age" = { publicKeys = [ "$recipient" ]; }; } EOF printf '%s' "$hash" >"$hash_file" unset hash RULES="$rules_file" nix develop --command agenix -e "$secret_file" <"$hash_file" echo "Encrypted $secret_file (local console/PAM password; SSH password auth remains disabled)"# Boot the generated ISO in QEMU (OVMF UEFI) and verify ittest-iso: ovmf ./13-inch-thin-cannon/tests/iso-test.sh# Run a single phase: live | install | bootlive: ovmf ./13-inch-thin-cannon/tests/iso-test.sh liveinstall: ovmf ./13-inch-thin-cannon/tests/iso-test.sh installboot: ovmf ./13-inch-thin-cannon/tests/iso-test.sh boot# Debug: boot the installed system interactively (asks you to type the LUKS# passphrase on the serial console; monitor on port 5555, serial on 5557)debug: ovmf INTERACTIVE=1 ./13-inch-thin-cannon/tests/iso-test.sh boot# Show available targetshelp: @just --list