Some checks failed
Check meta / check_meta (pull_request) Failing after 16s
Check meta / check_dns (pull_request) Successful in 16s
Check workflows / check_workflows (pull_request) Successful in 17s
Build all the nodes / netaccess01 (pull_request) Successful in 22s
Build all the nodes / netcore02 (pull_request) Successful in 21s
Build all the nodes / netcore01 (pull_request) Successful in 22s
Run pre-commit on all files / pre-commit (push) Successful in 27s
Build all the nodes / ap01 (pull_request) Successful in 32s
Build the shell / build-shell (pull_request) Successful in 24s
Run pre-commit on all files / pre-commit (pull_request) Successful in 24s
Build all the nodes / tower01 (pull_request) Successful in 1m52s
Build all the nodes / geo01 (pull_request) Successful in 2m2s
Build all the nodes / geo02 (pull_request) Successful in 2m3s
Build all the nodes / rescue01 (pull_request) Successful in 2m11s
Build all the nodes / bridge01 (pull_request) Successful in 3m19s
Build all the nodes / hypervisor02 (pull_request) Successful in 3m31s
Build all the nodes / web02 (pull_request) Successful in 3m18s
Build all the nodes / build01 (pull_request) Successful in 3m46s
Build all the nodes / hypervisor01 (pull_request) Successful in 3m46s
Build all the nodes / vault01 (pull_request) Successful in 3m50s
Build all the nodes / hypervisor03 (pull_request) Successful in 4m7s
Build all the nodes / compute01 (pull_request) Successful in 4m9s
Build all the nodes / storage01 (pull_request) Successful in 4m11s
Build all the nodes / web01 (pull_request) Successful in 4m7s
Build all the nodes / web03 (pull_request) Successful in 4m6s
226 lines
6 KiB
Nix
226 lines
6 KiB
Nix
# SPDX-FileCopyrightText: 2024 Ryan Lahfa <ryan.lahfa@dgnum.eu>
|
||
# SPDX-FileCopyrightText: 2024 Tom Hubrecht <tom.hubrecht@dgnum.eu>
|
||
# SPDX-FileContributor: Maurice Debray <maurice.debray@dgnum.eu>
|
||
#
|
||
# SPDX-License-Identifier: EUPL-1.2
|
||
|
||
# TODO: change comments to ### \n # [text] \n #
|
||
|
||
let
|
||
### Init some tooling
|
||
|
||
bootstrap = import ./bootstrap.nix;
|
||
|
||
inherit (bootstrap.pkgs) lib;
|
||
inherit (lib.extra) mapSingleFuse;
|
||
|
||
inherit (bootstrap) sources;
|
||
|
||
### Let's build meta
|
||
metadata = (import ./meta) lib;
|
||
|
||
nodes = builtins.attrNames metadata.nodes;
|
||
|
||
### Nixpkgs instanciation
|
||
|
||
nixpkgs' = import ./meta/nixpkgs.nix;
|
||
|
||
# Build up the nixpkgs configuration for Liminix embedded systems
|
||
mkLiminixConfig =
|
||
system: _:
|
||
(import "${sources.liminix}/devices/${system}").system
|
||
// {
|
||
overlays = [ (import "${sources.liminix}/overlay.nix") ];
|
||
config = {
|
||
allowUnsupportedSystem = true; # mipsel
|
||
permittedInsecurePackages = [
|
||
"python-2.7.18.8" # Python < 3.x is needed for kernel backports.
|
||
];
|
||
};
|
||
};
|
||
|
||
# Build up the arguments to instantiate a nixpkgs given a system and a version.
|
||
mkNixpkgsConfig =
|
||
system:
|
||
{
|
||
nixos = _: { }; # TODO: add nix-pkgs overlay here
|
||
zyxel-nwa50ax = mkLiminixConfig system;
|
||
netconf = _: { };
|
||
}
|
||
.${system} or (throw "Unknown system: ${system} for nixpkgs configuration instantiation");
|
||
|
||
# Instanciates the required nixpkgs version
|
||
mkSystemNixpkgs =
|
||
system: version: import sources."nixos-${version}" (mkNixpkgsConfig system version);
|
||
|
||
# All supported nixpkgs versions × systems, instanciated
|
||
nixpkgs = mapSingleFuse (s: mapSingleFuse (mkSystemNixpkgs s) nixpkgs'.versions) nixpkgs'.systems;
|
||
|
||
# Get the configured nixos version for the node,
|
||
# defaulting to the one defined in meta/nixpkgs
|
||
version = node: metadata.nodes.${node}.nixpkgs.version;
|
||
system = node: metadata.nodes.${node}.nixpkgs.system;
|
||
category = node: nixpkgs'.categories.${system node};
|
||
|
||
nodePkgs = node: nixpkgs.${system node}.${version node};
|
||
|
||
##########
|
||
# Function to create arguments based on the node
|
||
#
|
||
mkArgs = node: rec {
|
||
lib = sourcePkgs.lib.extend bootstrap.overlays.lib;
|
||
|
||
sourcePkgs = nodePkgs node;
|
||
meta = metadata;
|
||
|
||
nodeMeta = metadata.nodes.${node};
|
||
nodePath = "machines/${category node}/${node}";
|
||
};
|
||
|
||
##########
|
||
# Module for each node (quite empty since almost everything is in the default module)
|
||
#
|
||
mkNode = node: {
|
||
deployment.systemType = system node;
|
||
};
|
||
|
||
in
|
||
|
||
{
|
||
meta = {
|
||
nixpkgs = import nixpkgs.nixos.unstable.path;
|
||
nodeNixpkgs = mapSingleFuse nodePkgs nodes;
|
||
|
||
specialArgs = {
|
||
inherit nixpkgs sources;
|
||
|
||
dgn-keys = import ./lib/keys {
|
||
meta = metadata;
|
||
inherit lib;
|
||
};
|
||
};
|
||
|
||
nodeSpecialArgs = mapSingleFuse mkArgs nodes;
|
||
};
|
||
|
||
registry = {
|
||
zyxel-nwa50ax = {
|
||
evalConfig =
|
||
args:
|
||
(import "${sources.liminix}/lib/eval-config.nix" {
|
||
nixpkgs = args.specialArgs.sourcePkgs.path;
|
||
})
|
||
args;
|
||
|
||
defaults =
|
||
{ name, nodePath, ... }:
|
||
{
|
||
# Import the default modules
|
||
imports = [
|
||
# Import the base configuration for each node
|
||
./${nodePath}/_configuration.nix
|
||
./modules/generic
|
||
./modules/${category name}
|
||
];
|
||
# It's impure, but who cares?
|
||
# Can Flakes even do that? :)
|
||
nixpkgs.buildPlatform = builtins.currentSystem;
|
||
};
|
||
};
|
||
|
||
netconf = {
|
||
evalConfig = nixpkgs.nixos.unstable.lib.evalModules;
|
||
|
||
defaults =
|
||
{
|
||
name,
|
||
nodeMeta,
|
||
nodePath,
|
||
...
|
||
}:
|
||
{
|
||
_module.args = {
|
||
pkgs = nixpkgs.nixos.unstable;
|
||
};
|
||
|
||
# Import the default modules
|
||
imports = [
|
||
# Import the base configuration for each node
|
||
./${nodePath}.nix
|
||
./modules/netconf
|
||
./lib/netconf-junos
|
||
"${sources.nixos-unstable}/nixos/modules/misc/assertions.nix"
|
||
];
|
||
|
||
system.host-name = name;
|
||
|
||
inherit (nodeMeta) deployment;
|
||
};
|
||
};
|
||
|
||
nixos = {
|
||
evalConfig = args: import "${args.specialArgs.sourcePkgs.path}/nixos/lib/eval-config.nix" args;
|
||
defaults =
|
||
{
|
||
lib,
|
||
name,
|
||
nodes,
|
||
nodeMeta,
|
||
nodePath,
|
||
meta,
|
||
sourcePkgs,
|
||
...
|
||
}:
|
||
{
|
||
# Import the default modules
|
||
imports = [
|
||
# Import the base configuration for each node
|
||
./${nodePath}/_configuration.nix
|
||
./modules/generic
|
||
(import "${sources.lix-module}/module.nix" { inherit (sources) lix; })
|
||
./modules/${category name}
|
||
];
|
||
|
||
_module.args.serverNodes = lib.filterAttrs (
|
||
name: _: meta.nodes.${name}.nixpkgs.system == "nixos"
|
||
) nodes;
|
||
|
||
# Include default secrets
|
||
age-secrets.sources = [ ./${nodePath}/secrets ];
|
||
|
||
# Deployment config is specified in meta.nodes.${node}.deployment
|
||
inherit (nodeMeta) deployment;
|
||
|
||
nix = {
|
||
# Set NIX_PATH to the patched version of nixpkgs
|
||
nixPath = [ "nixpkgs=${builtins.storePath sourcePkgs.path}" ];
|
||
optimise.automatic = true;
|
||
|
||
gc = {
|
||
automatic = true;
|
||
dates = "weekly";
|
||
options = "--delete-older-than 7d";
|
||
};
|
||
|
||
settings =
|
||
{
|
||
substituters = [ "https://tvix-store.dgnum.eu/infra" ];
|
||
}
|
||
// (import ./machines/nixos/storage01/tvix-cache/cache-settings.nix {
|
||
caches = [ "infra" ];
|
||
});
|
||
};
|
||
|
||
# Allow unfree packages
|
||
nixpkgs.config.allowUnfree = true;
|
||
|
||
# Use the stateVersion declared in the metadata
|
||
system = {
|
||
inherit (nodeMeta) stateVersion;
|
||
};
|
||
};
|
||
};
|
||
};
|
||
|
||
}
|
||
// (mapSingleFuse mkNode nodes)
|