default: help # Build the 13-inch-thin-cannon install ISO (disko-backed, hardened) build: nix build .#nixosConfigurations."13-inch-thin-cannon-iso".config.system.build.isoImage # Alias for build iso: build # Copy OVMF firmware into the tests dir (result/iso and result/FV cannot coexist) ovmf: chmod -R u+w 13-inch-thin-cannon/tests/ovmf 2>/dev/null || true rm -rf 13-inch-thin-cannon/tests/ovmf mkdir -p 13-inch-thin-cannon/tests/ovmf cp -a $(nix build .#ovmf --no-link --print-out-paths)/FV 13-inch-thin-cannon/tests/ovmf/ # Full lifecycle: build the ISO, then test live boot, installation, and boot up: build test-iso # Decrypt an age secret with this machine's SSH host identity. # Usage: `just decrypt-secret secrets/example.age` decrypt-secret secret: nix shell nixpkgs#age --command sudo age --decrypt -i /etc/ssh/ssh_host_ed25519_key -o - "{{secret}}" # Encrypt a yescrypt hash for the file_magic account with agenix. Set # AGE_RECIPIENT to the target host's SSH public key when running remotely. set-file-magic-password: #!/usr/bin/env bash set -euo pipefail secret_file="secrets/file_magic-password.age" recipient_source="${AGE_RECIPIENT:-/etc/ssh/ssh_host_ed25519_key.pub}" if [[ -f "$recipient_source" ]]; then recipient="$(<"$recipient_source")" else recipient="$recipient_source" fi if [[ -z "$recipient" ]]; then echo "AGE_RECIPIENT or /etc/ssh/ssh_host_ed25519_key.pub is required" >&2 exit 1 fi read -r -s -p "file_magic password: " password printf '\n' read -r -s -p "Repeat password: " password_repeat printf '\n' if [[ "$password" != "$password_repeat" ]]; then echo "Passwords do not match" >&2 exit 1 fi hash="$(printf '%s' "$password" | mkpasswd -m yescrypt -s)" unset password password_repeat rules_file="$(mktemp)" hash_file="$(mktemp)" trap 'rm -f "$rules_file" "$hash_file"' EXIT cat >"$rules_file" <"$hash_file" unset hash RULES="$rules_file" nix develop --command agenix -e "$secret_file" <"$hash_file" echo "Encrypted $secret_file (local console/PAM password; SSH password auth remains disabled)" # Boot the generated ISO in QEMU (OVMF UEFI) and verify it test-iso: ovmf ./13-inch-thin-cannon/tests/iso-test.sh # Run a single phase: live | install | boot live: ovmf ./13-inch-thin-cannon/tests/iso-test.sh live install: ovmf ./13-inch-thin-cannon/tests/iso-test.sh install boot: ovmf ./13-inch-thin-cannon/tests/iso-test.sh boot # Debug: boot the installed system interactively (asks you to type the LUKS # passphrase on the serial console; monitor on port 5555, serial on 5557) debug: ovmf INTERACTIVE=1 ./13-inch-thin-cannon/tests/iso-test.sh boot # Show available targets help: @just --list