Tom Hubrecht
6c4099d369
All checks were successful
Check meta / check_meta (pull_request) Successful in 17s
Check meta / check_dns (pull_request) Successful in 16s
build configuration / build_compute01 (pull_request) Successful in 1m19s
build configuration / build_storage01 (pull_request) Successful in 1m15s
build configuration / build_vault01 (pull_request) Successful in 1m10s
build configuration / build_krz01 (pull_request) Successful in 2m4s
build configuration / build_web01 (pull_request) Successful in 1m40s
build configuration / build_web02 (pull_request) Successful in 1m12s
lint / check (pull_request) Successful in 24s
build configuration / build_geo01 (pull_request) Successful in 1m7s
build configuration / build_rescue01 (pull_request) Successful in 1m10s
build configuration / build_geo02 (pull_request) Successful in 1m7s
build configuration / build_bridge01 (pull_request) Successful in 1m8s
build configuration / push_to_cache_vault01 (pull_request) Successful in 1m56s
build configuration / push_to_cache_storage01 (pull_request) Successful in 1m57s
build configuration / push_to_cache_compute01 (pull_request) Successful in 2m19s
build configuration / push_to_cache_web01 (pull_request) Successful in 2m21s
build configuration / push_to_cache_krz01 (pull_request) Successful in 2m30s
build configuration / push_to_cache_geo01 (pull_request) Successful in 1m8s
build configuration / push_to_cache_web02 (pull_request) Successful in 1m17s
Check meta / check_meta (push) Successful in 17s
Check meta / check_dns (push) Successful in 17s
build configuration / push_to_cache_geo02 (pull_request) Successful in 1m11s
build configuration / push_to_cache_bridge01 (pull_request) Successful in 1m10s
build configuration / push_to_cache_rescue01 (pull_request) Successful in 1m23s
build configuration / build_storage01 (push) Successful in 1m16s
build configuration / build_vault01 (push) Successful in 1m13s
build configuration / build_compute01 (push) Successful in 1m20s
build configuration / build_web01 (push) Successful in 1m38s
build configuration / build_krz01 (push) Successful in 1m58s
lint / check (push) Successful in 25s
build configuration / build_web02 (push) Successful in 1m9s
build configuration / build_geo01 (push) Successful in 1m9s
build configuration / build_geo02 (push) Successful in 1m10s
build configuration / build_rescue01 (push) Successful in 1m15s
build configuration / build_bridge01 (push) Successful in 1m2s
build configuration / push_to_cache_storage01 (push) Successful in 1m25s
build configuration / push_to_cache_vault01 (push) Successful in 1m37s
build configuration / push_to_cache_web02 (push) Successful in 1m21s
build configuration / push_to_cache_compute01 (push) Successful in 1m56s
build configuration / push_to_cache_web01 (push) Successful in 2m18s
build configuration / push_to_cache_geo01 (push) Successful in 1m15s
build configuration / push_to_cache_krz01 (push) Successful in 2m25s
build configuration / push_to_cache_geo02 (push) Successful in 1m8s
build configuration / push_to_cache_bridge01 (push) Successful in 1m8s
build configuration / push_to_cache_rescue01 (push) Successful in 1m23s
113 lines
2.7 KiB
Nix
113 lines
2.7 KiB
Nix
let
|
|
sources' = import ./npins;
|
|
|
|
# Patch sources directly
|
|
sources = builtins.mapAttrs (patch.base { pkgs = import sources'.nixos-unstable { }; })
|
|
.applyPatches' sources';
|
|
|
|
nix-lib = import ./lib/nix-lib;
|
|
|
|
patch = import ./lib/nix-patches { patchFile = ./patches; };
|
|
|
|
nodes' = import ./meta/nodes.nix;
|
|
nodes = builtins.attrNames nodes';
|
|
|
|
mkNode = node: {
|
|
# Import the base configuration for each node
|
|
imports = [ ./machines/${node}/_configuration.nix ];
|
|
};
|
|
|
|
nixpkgs' = import ./meta/nixpkgs.nix;
|
|
# All supported nixpkgs versions, instanciated
|
|
nixpkgs = nix-lib.mapSingleFuse mkNixpkgs nixpkgs'.supported;
|
|
|
|
# Get the configured nixos version for the node,
|
|
# defaulting to the one defined in meta/nixpkgs
|
|
version = node: nodes'.${node}.nixpkgs or nixpkgs'.default;
|
|
|
|
# Builds a patched version of nixpkgs, only as the source
|
|
mkNixpkgs' =
|
|
v:
|
|
patch.mkNixpkgsSrc rec {
|
|
src = sources'.${name};
|
|
name = "nixos-${v}";
|
|
};
|
|
|
|
# Instanciates the required nixpkgs version
|
|
mkNixpkgs = version: import (mkNixpkgs' version) { };
|
|
|
|
###
|
|
# Function to create arguments based on the node
|
|
#
|
|
mkArgs = node: rec {
|
|
lib = nixpkgs.${version node}.lib // {
|
|
extra = nix-lib;
|
|
};
|
|
|
|
meta = (import ./meta) lib;
|
|
|
|
nodeMeta = meta.nodes.${node};
|
|
};
|
|
in
|
|
|
|
{
|
|
meta = {
|
|
nodeNixpkgs = nix-lib.mapSingleFuse (n: nixpkgs.${version n}) nodes;
|
|
|
|
specialArgs = {
|
|
inherit nixpkgs sources;
|
|
|
|
dgn-keys = import ./keys;
|
|
};
|
|
|
|
nodeSpecialArgs = nix-lib.mapSingleFuse mkArgs nodes;
|
|
};
|
|
|
|
defaults =
|
|
{
|
|
pkgs,
|
|
name,
|
|
nodeMeta,
|
|
...
|
|
}:
|
|
{
|
|
# Import the default modules
|
|
imports = [
|
|
./modules
|
|
(import "${sources.lix-module}/module.nix" {
|
|
lix = pkgs.applyPatches {
|
|
name = "lix-2.90.patched";
|
|
src = sources.lix;
|
|
patches = [ ./patches/00-disable-installChecks-lix.patch ];
|
|
};
|
|
})
|
|
];
|
|
|
|
# Include default secrets
|
|
age-secrets.sources = [ ./machines/${name}/secrets ];
|
|
|
|
# Deployment config is specified in meta.nodes.${node}.deployment
|
|
inherit (nodeMeta) deployment;
|
|
|
|
nix = {
|
|
# Set NIX_PATH to the patched version of nixpkgs
|
|
nixPath = [ "nixpkgs=${mkNixpkgs' (version name)}" ];
|
|
optimise.automatic = true;
|
|
|
|
gc = {
|
|
automatic = true;
|
|
dates = "weekly";
|
|
options = "--delete-older-than 7d";
|
|
};
|
|
};
|
|
|
|
# Allow unfree packages
|
|
nixpkgs.config.allowUnfree = true;
|
|
|
|
# Use the stateVersion declared in the metadata
|
|
system = {
|
|
inherit (nodeMeta) stateVersion;
|
|
};
|
|
};
|
|
}
|
|
// (nix-lib.mapSingleFuse mkNode nodes)
|