nixos: refactor flake
This commit is contained in:
parent
e0ca875df0
commit
c3f86d5ae5
2 changed files with 21 additions and 30 deletions
49
flake.nix
49
flake.nix
|
@ -18,14 +18,13 @@
|
||||||
inherit (nixpkgs) lib;
|
inherit (nixpkgs) lib;
|
||||||
inherit (builtins) filter;
|
inherit (builtins) filter;
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
merge = a: b: a // b;
|
|
||||||
|
|
||||||
# Create a nixosConfiguration based on a foldername (nixname) and if the host is an LXC container or a VM.
|
# Create a nixosConfiguration based on a foldername (nixname) and if the host is an LXC container or a VM.
|
||||||
mkConfig = nixname: lxc:
|
mkConfig = { hostname, profile ? hostname, lxc ? true, ... }: {
|
||||||
lib.nixosSystem {
|
"${profile}" = lib.nixosSystem {
|
||||||
inherit system;
|
inherit system;
|
||||||
modules =
|
modules =
|
||||||
[ "${./.}/nixos/hosts/${nixname}/configuration.nix" ./nixos/common ]
|
[ "${./.}/nixos/hosts/${profile}/configuration.nix" ./nixos/common ]
|
||||||
++ (if lxc then [
|
++ (if lxc then [
|
||||||
"${nixpkgs}/nixos/modules/virtualisation/lxc-container.nix"
|
"${nixpkgs}/nixos/modules/virtualisation/lxc-container.nix"
|
||||||
./nixos/common/generic-lxc.nix
|
./nixos/common/generic-lxc.nix
|
||||||
|
@ -33,36 +32,26 @@
|
||||||
[ ./nixos/common/generic-vm.nix ]);
|
[ ./nixos/common/generic-vm.nix ]);
|
||||||
specialArgs.inputs = inputs;
|
specialArgs.inputs = inputs;
|
||||||
};
|
};
|
||||||
|
};
|
||||||
|
|
||||||
# Create a deploy-rs config based on profile- and hostname.
|
# Same as above, but for the nodes part of deploy.
|
||||||
mkDeploy = hostname: profile: {
|
mkDeploy = { ip, hostname, profile ? hostname, ... }: {
|
||||||
inherit hostname;
|
"${hostname}" = {
|
||||||
fastConnection = true;
|
hostname = ip;
|
||||||
profiles.system = {
|
fastConnection = true;
|
||||||
user = "root";
|
profiles.system = {
|
||||||
path = deploy-rs.lib.${system}.activate.nixos
|
user = "root";
|
||||||
self.nixosConfigurations.${profile};
|
path = deploy-rs.lib.${system}.activate.nixos self.nixosConfigurations.${profile};
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
# Convert a host from hosts.nix to something nixosConfigurations understands
|
|
||||||
hostToConfig = { hostname, nixname ? hostname, lxc ? true, ... }:
|
|
||||||
merge {
|
|
||||||
"${nixname}" = mkConfig nixname lxc;
|
|
||||||
};
|
|
||||||
|
|
||||||
# Same as above, but for the nodes part of deploy.
|
|
||||||
hostToDeploy = { ip, hostname, nixname ? hostname, ... }:
|
|
||||||
merge {
|
|
||||||
"${nixname}" = mkDeploy ip nixname;
|
|
||||||
};
|
|
||||||
|
|
||||||
# Import all nixos host definitions that are actual nix machines
|
# Import all nixos host definitions that are actual nix machines
|
||||||
nixHosts = filter ({ nix ? true, ... }: nix) (import ./nixos/hosts.nix);
|
nixHosts = filter ({ nix ? true, ... }: nix) (import ./hosts.nix);
|
||||||
in {
|
in {
|
||||||
# Make the config and deploy sets
|
# Make the config and deploy sets
|
||||||
nixosConfigurations = lib.foldr hostToConfig { } nixHosts;
|
nixosConfigurations = lib.foldr (el: acc: acc // mkConfig el) { } nixHosts;
|
||||||
deploy.nodes = lib.foldr hostToDeploy { } nixHosts;
|
deploy.nodes = lib.foldr (el: acc: acc // mkDeploy el) { } nixHosts;
|
||||||
|
|
||||||
# Use by running `nix develop`
|
# Use by running `nix develop`
|
||||||
devShell.${system} = let
|
devShell.${system} = let
|
||||||
|
@ -70,12 +59,15 @@
|
||||||
[ vault-secrets.overlay ];
|
[ vault-secrets.overlay ];
|
||||||
in pkgs.mkShell {
|
in pkgs.mkShell {
|
||||||
VAULT_ADDR = "http://10.42.42.6:8200/";
|
VAULT_ADDR = "http://10.42.42.6:8200/";
|
||||||
|
# This only support bash so just execute zsh in bash as a workaround :/
|
||||||
|
shellHook = "${pkgs.zsh}/bin/zsh; exit";
|
||||||
buildInputs = with pkgs; [
|
buildInputs = with pkgs; [
|
||||||
deploy-rs.packages.${system}.deploy-rs
|
deploy-rs.packages.${system}.deploy-rs
|
||||||
fluxcd
|
fluxcd
|
||||||
k9s
|
k9s
|
||||||
kubectl
|
kubectl
|
||||||
kubectx
|
kubectx
|
||||||
|
terraform
|
||||||
nixfmt
|
nixfmt
|
||||||
nixUnstable
|
nixUnstable
|
||||||
vault
|
vault
|
||||||
|
@ -84,7 +76,6 @@
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
checks = builtins.mapAttrs
|
checks = builtins.mapAttrs (system: deployLib: deployLib.deployChecks self.deploy) deploy-rs.lib;
|
||||||
(system: deployLib: deployLib.deployChecks self.deploy) deploy-rs.lib;
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
@ -7,7 +7,7 @@
|
||||||
}
|
}
|
||||||
{
|
{
|
||||||
hostname = "k3s-node1";
|
hostname = "k3s-node1";
|
||||||
nixname = "k3s";
|
profile = "k3s";
|
||||||
ip = "10.42.42.10";
|
ip = "10.42.42.10";
|
||||||
mac = "2E:F8:55:23:D9:9B";
|
mac = "2E:F8:55:23:D9:9B";
|
||||||
lxc = false;
|
lxc = false;
|
Loading…
Reference in a new issue