diff --git a/modules/cli/git.nix b/modules/cli/git.nix index fd2f251..9ae5d86 100644 --- a/modules/cli/git.nix +++ b/modules/cli/git.nix @@ -38,6 +38,7 @@ in result* *.qcow2 *.fd + .nixos-test-history ''; }; diff --git a/modules/desktop/steam.nix b/modules/desktop/steam.nix index fae9730..e5bc036 100644 --- a/modules/desktop/steam.nix +++ b/modules/desktop/steam.nix @@ -1,7 +1,12 @@ +{ lib, ... }: { flake.modules.nixos.desktop = - { lib, pkgs, ... }: + { config, pkgs, ... }: { - nixpkgs.config.allowUnfreePredicate = pkg: lib.hasPrefix "steam" pkg.pname; + nixpkgs.config = lib.mkIf config.programs.steam.enable { + allowUnfreePredicate = pkg: lib.hasPrefix "steam" pkg.pname; + }; }; + + flake.modules.nixos.test.programs.steam.enable = lib.mkForce false; } diff --git a/modules/hosts/crossbell/default.nix b/modules/hosts/crossbell/default.nix index 5431bc7..a804d0f 100644 --- a/modules/hosts/crossbell/default.nix +++ b/modules/hosts/crossbell/default.nix @@ -39,6 +39,14 @@ in }; }; + local.testScript = '' + machine.wait_for_open_port(80) + machine.wait_for_open_port(443) + format = "'%{response_code}->%{redirect_url}'" + result = machine.succeed(f"curl -f -H 'host: pvsr.dev' http://localhost -w {format}") + t.assertEqual("308->https://pvsr.dev/", result) + ''; + services.openssh.listenAddresses = [ { addr = "0.0.0.0"; @@ -62,4 +70,6 @@ in system.stateVersion = "24.05"; }; + + flake.modules.nixos.test.services.cloud-init.enable = false; } diff --git a/modules/nixos/documentation.nix b/modules/nixos/documentation.nix index 23d0cfb..ae708e0 100644 --- a/modules/nixos/documentation.nix +++ b/modules/nixos/documentation.nix @@ -1,8 +1,8 @@ { lib, ... }: { - flake.modules = { - nixos.core.documentation.man.generateCaches = lib.mkOverride 500 false; - nixos.desktop = + flake.modules.nixos = { + core.documentation.man.generateCaches = lib.mkOverride 500 false; + desktop = { pkgs, ... }: { documentation.enable = true; @@ -13,5 +13,9 @@ documentation.man.generateCaches = true; environment.systemPackages = [ pkgs.man-pages ]; }; + test = { + documentation.enable = lib.mkForce false; + documentation.nixos.enable = lib.mkForce false; + }; }; } diff --git a/modules/nixos/tests.nix b/modules/nixos/tests.nix new file mode 100644 index 0000000..3bcba4c --- /dev/null +++ b/modules/nixos/tests.nix @@ -0,0 +1,31 @@ +{ self, config, ... }: +{ + flake.modules.nixos.core = + { lib, ... }: + { + options.local.testScript = lib.mkOption { + type = lib.types.lines; + default = ""; + }; + }; + + flake.modules.nixos.test.hardware.facter.report = { }; + + perSystem = + { pkgs, ... }: + { + checks = builtins.mapAttrs ( + name: host: + pkgs.testers.runNixOSTest { + inherit name; + nodes.machine = { + imports = [ + host + self.modules.nixos.test + ]; + }; + inherit (self.nixosConfigurations.${name}.config.local) testScript; + } + ) config.local.hosts; + }; +} diff --git a/modules/nixos/yggdrasil/dns.nix b/modules/nixos/yggdrasil/dns.nix index 4ef3855..8d336f7 100644 --- a/modules/nixos/yggdrasil/dns.nix +++ b/modules/nixos/yggdrasil/dns.nix @@ -11,7 +11,6 @@ in nameservers = lib.mkForce [ hosts.ruan.config.local.ip ]; }; - local.desktops.ruan.imports = [ self.modules.nixos.yggdrasilNameServer ]; flake.modules.nixos.yggdrasilNameServer = { networking.firewall.interfaces.ygg0 = { allowedTCPPorts = [ 53 ]; @@ -44,6 +43,18 @@ in }; }; + local.desktops.ruan = + { config, pkgs, ... }: + { + imports = [ self.modules.nixos.yggdrasilNameServer ]; + local.testScript = '' + machine.wait_for_unit("dnsmasq.service") + address = machine.succeed("yggdrasilctl -json getself | ${pkgs.jq}/bin/jq -r .address").strip() + t.assertIn(address, machine.succeed(f"dig @{address} ${config.networking.fqdn} AAAA")) + machine.succeed(f"dig @{address} ${hosts.grancel.config.networking.fqdn} AAAA") + ''; + }; + flake.modules.nixos.incus = { config, pkgs, ... }: { diff --git a/modules/nixos/yggdrasil/network.nix b/modules/nixos/yggdrasil/network.nix index db2d2ba..3ced637 100644 --- a/modules/nixos/yggdrasil/network.nix +++ b/modules/nixos/yggdrasil/network.nix @@ -1,3 +1,4 @@ +{ lib, ... }: let peerPort = 33933; multicastPort = 48147; @@ -5,7 +6,7 @@ let in { flake.modules.nixos.core = - { config, lib, ... }: + { config, ... }: { services.yggdrasil = { enable = !config.boot.isContainer; @@ -16,6 +17,8 @@ in environment.persistence.nixos.files = [ keyPath ]; networking.firewall.interfaces.ygg0.allowedTCPPorts = [ 22 ]; networking.firewall.allowedTCPPorts = [ 2808 ]; + + local.testScript = "machine.wait_for_unit('yggdrasil.service')"; }; flake.modules.nixos.yggdrasilClient = { @@ -25,7 +28,7 @@ in Peers = [ "tls://internal.pvsr.dev:${toString peerPort}" ]; MulticastInterfaces = [ { - Regex = "en.*"; + Regex = "e(n|th).*"; Port = multicastPort; } ]; @@ -38,4 +41,18 @@ in services.yggdrasil.settings.Listen = [ "tls://[::]:${toString peerPort}" ]; networking.firewall.allowedTCPPorts = [ peerPort ]; }; + + flake.modules.nixos.test = + { pkgs, ... }: + let + ygg = lib.getExe pkgs.yggdrasil; + in + { + services.yggdrasil.settings = { + Peers = lib.mkForce [ ]; + PrivateKeyPath = lib.mkForce ( + pkgs.runCommandLocal "export-test-key" { } "${ygg} -genconf | ${ygg} -useconf -exportkey > $out" + ); + }; + }; }