From e7d6f67805b03ec7fdaa30d4a778d832edbada14 Mon Sep 17 00:00:00 2001 From: Ladas552 Date: Sun, 12 Oct 2025 12:36:06 +0500 Subject: [PATCH] some more on impermanence, next are persist datasets --- content/posts/Impermanence.norg | 85 +++++++++++++++++++++++++++++++-- flake.lock | 8 ++-- 2 files changed, 84 insertions(+), 9 deletions(-) diff --git a/content/posts/Impermanence.norg b/content/posts/Impermanence.norg index 2c9ca12..e03cb39 100644 --- a/content/posts/Impermanence.norg +++ b/content/posts/Impermanence.norg @@ -14,21 +14,39 @@ version: 1.1.1 @end * Impermanence ** What is Impermanence - It wipes your /root on reboot and your startup is a blank canvas, but you can persist mounts and bind mount directories from it in your normal root to save stuff like cache and tokens. So you wipe all the junk and save actually useful stuff. + It wipes your `/root` on reboot and your startup is a blank canvas, but you can persist mounts and bind mount directories from it in your normal root to save stuff like cache and tokens. So you wipe all the junk and save actually useful stuff. For example you can install full KDE Plasma session, run it, and if you get bored. Just disable it and no KDE junk left. -*** Why use Impermanence - Makes system reproducible by disabling any imperative changes, and makes you think what your system actually has. - Only snapshot and back up things you care about, not cache or login details. + *Important to note*: That impermanence of my setup uses tmpfs, so it writes `/root` to RAM, so nothing actually gets erased on the Disk. Meaning no continuous I/O rewrites wearing out your Drive. But the state isn't saved between reboots, as with anything on RAM + + Also when I refer to `/root`, it's actually the whole `/`, not just root user directory. *** Why did you set it up I was bored. I don't find benefits of impermanence so crucial to completely overhaul how your system behaves and I don't trust myself to maintain it. - But again, I was really bored in hospital and made this work. + But there are some benefits to it: + - I only backup important files, no cache, no states, only files and media; + - I always know what's on my system because it's declared in the config; + - It opens up possibilities to experiment more with my system, because if I could setup impermanence and not loose all my files, I am unstoppable; *** What's the meaning of writing this page? It's not that hard to setup impermanence, but to requires reading a lot of stuff, and if you don't use ZFS or BTRFS even full reinstall for rearranging partitions. I have read several articles, watched videos, and stole code from many GitHub repos. Plus most guides just go to the wipe stage right away, without saying how to persist, or how it practically works for the user to not loose their files. I will try to compete in these aspects. + +*** What is your current setup? + I got ZFS with tmpfs, with 2 persistence datasets. /cache and /persist. + + `/cache` is for rust targets, everything in `~/.cache`, .local states, etc. + + `/persist` is for Media, browser profiles, Projects, etc. This is the only datasets that get's backed up by `sanoid`. + + tmpfs is erased on reboot, so `/` and everything below it, including `/home` is gone, unless put into `/cache` or `/persist` datasets. + tmpfs is on RAM, so it can overload if exceeds certain size, to prevent that I got several more zfs datasets, that aren't persisted, meaning they don't have connection to files in other datasets, but aren't erased by default. + + `/nix` for /nix/store. I am not about to redownload all of my system on every reboot, and it also stores the generations. All the files that aren't persisted, but appear on my system are symlinked from `/nix`. That includes config files and services. + + `/tmp` for /tmp. yeah, anyways it's to not overload tmpfs when downloading something on browser. with `boot.tmp.cleanOnBoot = true;` it is cleared on boot anyways. + ** What we need? *** Partitions A new way to manage your system. NixOS. @@ -78,3 +96,60 @@ version: 1.1.1 inputs.impermanence.url = "github:nix-community/impermanence"; } @end + And then just import the module, like: + @code nix + imports = [ + inputs.impermanence.nixosModules.impermanence + ]; + @end +*** Immutable users + As we delete everything in `/root`, it means passwords for users, and most importantly `root` user will be deleted. + + So just make them immutable. You can store the password file in sops, or just provide raw path from `/persist` directory. + + @code nix + # setup immutable users for impermanence + + # silence warning about setting multiple user password options + # https://github.com/NixOS/nixpkgs/pull/287506#issuecomment-1950958990 + # Stolen from Iynaix https://github.com/iynaix/dotfiles/blob/4880969e7797451f4adc3475cf33f33cc3ceb86e/nixos/users.nix#L18-L24 + options = { + warnings = lib.mkOption { + apply = lib.filter ( + w: !(lib.hasInfix "If multiple of these password options are set at the same time" w) + ); + }; + }; + + config = { + users.mutableUsers = false; + users.users.ladas552 = { + isNormalUser = true; + description = "Ladas552"; + extraGroups = [ + "networkmanager" + "wheel" + ]; + initialPassword = "pass"; + hashedPasswordFile = config.sops.secrets."mystuff/host_pwd".path; + }; + nix.settings.trusted-users = [ "ladas552" ]; + + users.users.root = { + initialPassword = "pass"; + hashedPasswordFile = config.sops.secrets."mystuff/host_pwd".path; + }; + + + }; + + @end + + Other features for immutable users: + - Can use `--no-root-password` flag in `nixos-install` command. Meaning you don't ever have to monitor it, it will install password automatically. + - Can't use `passwd ` command. So if you mess up your password path the first time, you have to reboot to previous generation to set it correctly. + +*** When do we start deleting stuff? + Not so fast bakaru, we first need to save our stuff. + + So you need to create persist directories diff --git a/flake.lock b/flake.lock index 74108f2..3a00e75 100644 --- a/flake.lock +++ b/flake.lock @@ -20,11 +20,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1758813675, - "narHash": "sha256-cTjOAzgVQrjBvZLAdnY4+AhWdiAzdvEQ69/ZcxNo3Lo=", - "rev": "e643668fd71b949c53f8626614b21ff71a07379d", + "lastModified": 1760116735, + "narHash": "sha256-CtJvXEn1BAMg0dug9LUJXEw/1Sq0MqX52BToFKFHeG8=", + "rev": "0b4defa2584313f3b781240b29d61f6f9f7e0df3", "type": "tarball", - "url": "https://releases.nixos.org/nixos/unstable/nixos-25.11pre866707.e643668fd71b/nixexprs.tar.xz" + "url": "https://releases.nixos.org/nixos/unstable/nixos-25.11pre875086.0b4defa25843/nixexprs.tar.xz" }, "original": { "type": "tarball", -- 2.51.2