2021-10-13 16:49:41 +02:00
|
|
|
{
|
|
|
|
description = "Delft Deployment";
|
|
|
|
|
2021-11-16 21:52:43 +01:00
|
|
|
# Based on: https://github.com/serokell/pegasus-infra/blob/master/flake.nix
|
|
|
|
|
2021-11-16 16:28:55 +01:00
|
|
|
inputs = {
|
|
|
|
deploy-rs.url = "github:serokell/deploy-rs";
|
|
|
|
nixpkgs.url = "github:NixOS/nixpkgs/master";
|
|
|
|
serokell-nix.url = "github:serokell/serokell.nix";
|
|
|
|
vault-secrets.url = "github:serokell/vault-secrets";
|
|
|
|
};
|
2021-10-13 16:49:41 +02:00
|
|
|
|
2021-11-17 00:55:01 +01:00
|
|
|
outputs =
|
|
|
|
{ self, nixpkgs, deploy-rs, vault-secrets, serokell-nix, ... }@inputs:
|
2021-11-16 21:52:43 +01:00
|
|
|
let
|
|
|
|
system = "x86_64-linux";
|
2021-11-17 00:55:01 +01:00
|
|
|
mkSystem = { host, lxc ? true }:
|
2021-11-16 21:52:43 +01:00
|
|
|
nixpkgs.lib.nixosSystem {
|
|
|
|
inherit system;
|
2021-11-21 13:34:39 +01:00
|
|
|
modules = [ ./nixos/hosts/${host}/configuration.nix ./nixos/common.nix ] ++ (if lxc then
|
2021-11-17 00:55:01 +01:00
|
|
|
[ "${nixpkgs}/nixos/modules/virtualisation/lxc-container.nix" ]
|
|
|
|
else
|
|
|
|
[ ]);
|
|
|
|
specialArgs.inputs = inputs;
|
2021-11-16 16:28:55 +01:00
|
|
|
};
|
2021-11-16 21:52:43 +01:00
|
|
|
mkDeploy = hostname: profile: {
|
|
|
|
hostname = hostname;
|
2021-11-16 16:28:55 +01:00
|
|
|
fastConnection = true;
|
|
|
|
profiles.system = {
|
|
|
|
user = "root";
|
2021-11-16 21:52:43 +01:00
|
|
|
path = deploy-rs.lib.${system}.activate.nixos self.nixosConfigurations.${profile};
|
2021-11-16 16:28:55 +01:00
|
|
|
};
|
2021-10-17 21:02:20 +02:00
|
|
|
};
|
2021-11-16 21:52:43 +01:00
|
|
|
in {
|
2021-11-17 00:55:01 +01:00
|
|
|
# VMs
|
|
|
|
nixosConfigurations.bastion = mkSystem { host = "bastion"; lxc = false; };
|
|
|
|
nixosConfigurations.k3s = mkSystem { host = "k3s"; lxc = false; };
|
2021-10-18 18:54:07 +02:00
|
|
|
|
2021-11-17 00:55:01 +01:00
|
|
|
# LXCs
|
|
|
|
nixosConfigurations.vault = mkSystem { host = "vault"; };
|
|
|
|
nixosConfigurations.mosquitto = mkSystem { host = "mosquitto"; };
|
|
|
|
nixosConfigurations.nginx = mkSystem { host = "nginx"; };
|
|
|
|
nixosConfigurations.consul = mkSystem { host = "consul"; };
|
2021-10-18 23:26:26 +02:00
|
|
|
|
2021-11-16 21:52:43 +01:00
|
|
|
# Deploys
|
|
|
|
deploy.nodes.bastion = mkDeploy "10.42.42.4" "bastion";
|
2021-11-20 23:41:11 +01:00
|
|
|
deploy.nodes.k3s = mkDeploy "10.42.42.10" "k3s";
|
2021-11-16 21:52:43 +01:00
|
|
|
deploy.nodes.vault = mkDeploy "10.42.42.6" "vault";
|
|
|
|
deploy.nodes.mosquitto = mkDeploy "10.42.42.7" "mosquitto";
|
|
|
|
deploy.nodes.nginx = mkDeploy "10.42.42.9" "nginx";
|
|
|
|
deploy.nodes.consul = mkDeploy "10.42.42.14" "consul";
|
2021-11-03 22:55:03 +01:00
|
|
|
|
2021-11-16 21:52:43 +01:00
|
|
|
# Use by running `nix develop`
|
2021-11-16 16:28:55 +01:00
|
|
|
devShell.${system} = let
|
|
|
|
pkgs = serokell-nix.lib.pkgsWith nixpkgs.legacyPackages.${system}
|
|
|
|
[ vault-secrets.overlay ];
|
|
|
|
in pkgs.mkShell {
|
2021-11-20 23:41:11 +01:00
|
|
|
VAULT_ADDR = "http://10.42.42.6:8200/";
|
2021-11-16 16:28:55 +01:00
|
|
|
buildInputs = [
|
|
|
|
deploy-rs.packages.${system}.deploy-rs
|
|
|
|
pkgs.vault
|
|
|
|
(pkgs.vault-push-approle-envs self)
|
|
|
|
(pkgs.vault-push-approles self)
|
|
|
|
pkgs.nixUnstable
|
|
|
|
];
|
|
|
|
};
|
|
|
|
|
|
|
|
checks = builtins.mapAttrs
|
|
|
|
(system: deployLib: deployLib.deployChecks self.deploy) deploy-rs.lib;
|
|
|
|
};
|
2021-10-13 16:49:41 +02:00
|
|
|
}
|