Zhaofeng Li
c42c97d2f6
Add internal command to render CLI usage text for manual
2021-11-17 22:21:00 -08:00
Zhaofeng Li
1535857acc
Also disallow pinning to a Nixpkgs lambda in Flakes
...
Somehow missed this one *shrugs*
2021-11-17 22:21:00 -08:00
Zhaofeng Li
006cb2c5ee
eval.nix: Make the uninitialized nixpkgs error more informative
2021-11-16 21:01:40 -08:00
Zhaofeng Li
f716daa3a1
Migrate to indicatif 0.7 beta
...
Now there is no need for the ugly hack where we drove the spinner
in a separate thread :)
2021-11-16 21:01:33 -08:00
Zhaofeng Li
7d15d08d6d
Add test command for progress spinners
2021-11-16 21:01:33 -08:00
Zhaofeng Li
86eeeece3c
command: Rename introspect
to eval
2021-10-28 17:27:30 -07:00
Zhaofeng Li
f7eb121260
Disallow uninitialized meta.nixpkgs in Flakes
2021-10-28 17:10:58 -07:00
Zhaofeng Li
765f42fa24
introspect: Support actually instantiating the expression
2021-10-28 14:09:35 -07:00
Zhaofeng Li
58f2bf391f
src/util.rs: No need to list
2021-10-28 14:09:35 -07:00
Zhaofeng Li
0e0a1e84f0
Make flake resolution (slightly) less terrible
...
Instead of using `path:` which always copies the entire directory,
we now try to resolve the Flake URI using `nix flake metadata` which
may give us a `git+file:`.
2021-10-25 23:38:10 -07:00
Zhaofeng Li
b48753239a
hive.rs: Canonicalize flake path
...
Relative paths are no longer allowed in newer Nix versions.
2021-10-25 21:53:38 -07:00
Zhaofeng Li
6d6e33fcd4
nix: Remove unneeded ok()
2021-10-23 20:49:14 -07:00
Bjørn Forsman
4106a73e75
Allow selecting ssh user dynamically
...
...by setting `deployment.targetUser = null`.
This allows sharing a deployment file (hive.nix/flake.nix) between
multiple admins, without having to use a shared root account.
2021-10-23 15:06:56 +02:00
Zhaofeng Li
37b43cd6d7
eval.nix: Support autocall for hive configuration
2021-08-26 19:59:22 -07:00
Zhaofeng Li
7cc6552ee3
hive.rs: Remove unwrap in builder_args()
2021-08-26 19:59:22 -07:00
Zhaofeng Li
7b69946d98
Ensure key ownerships are set correctly
...
Depending on when keys are uploaded (`deployment.keys.<name>.uploadAt`):
`pre-activation`:
We set the ownerships in the uploader script opportunistically and
continue if the user/group does not exist. Then, in the activation
script, we set the ownerships of all pre-activation keys.
`post-activation`:
We set the ownerships in the uploader script and fail if the
user/group does not exist.
The ownerships will be correct regardless of which mode is in use.
Fixes #23 . Also a more complete solution to #10 .
2021-08-26 12:54:41 -07:00
Zhaofeng Li
24339bcca7
Add deployment.keys.<name>.uploadAt
...
This mirrors the functionality recently added in morph and allows
for the uploading of keys after system profile activation.
Fixes #10 .
2021-08-24 23:25:46 -07:00
Zhaofeng Li
135a42b20f
eval.nix: Add meta.specialArgs
2021-07-16 22:52:23 -07:00
Zhaofeng Li
671cf38796
hive.rs: Pass --builders to nix-instantiate as well
2021-07-13 01:38:52 -07:00
Zhaofeng Li
c644f79ad1
cli.rs: Indicate support for flakes
2021-06-29 01:19:13 -07:00
Zhaofeng Li
67db0e73d1
Add check for Flakes support
2021-06-29 01:02:43 -07:00
Zhaofeng Li
e50ba82bf2
Add basic Flakes support
...
Co-authored-by: Alex Zero <joseph@marsden.space>
2021-06-29 01:02:43 -07:00
Zhaofeng Li
22ae18f5e7
Exit with non-zero code if any node fails to deploy
...
The exit codes are in flux and should not be relied upon.
Fixes #28 .
2021-05-24 00:15:38 -07:00
Zhaofeng Li
960af8f793
Add deployment.privilegeEscalationCommand
...
This adds a NixOps-equivalent option for non-root deployment
on remote hosts.
Fixes #27 .
2021-05-24 00:15:38 -07:00
Zhaofeng Li
39d612a5e7
ssh: Remove dead code
2021-05-24 00:15:38 -07:00
Zhaofeng Li
99ba8db335
Merge pull request #21 from jasonrm/machines-file
...
eval.nix: Adds meta.machinesFile option that is passed to Nix as builder option
2021-05-07 16:25:36 -07:00
Zhaofeng Li
16ccdbc700
Better handling of killed processes
2021-04-28 15:09:40 -07:00
Zhaofeng Li
44b421c2c7
key.rs: Fix typo (user -> group)
...
Fixes #22 .
2021-04-19 15:40:19 -07:00
Jason R. McNeil
3ee97c2a76
apply: Add deployment.replaceUnknownProfiles
option and --force-replace-unknown-profiles
switch
...
If `deployment.replaceUnknownProfiles` is set to false, a diverged hive
config (in a shared git repo for example) won't result in accidentally
undoing another applied configuration profile.
The deployment option is set to true so that fiction is minimized from
aggressive garbage collection, first time profile application and low
contention hives.
2021-04-10 13:42:38 -07:00
Jason R. McNeil
e0465567b2
eval.nix: Adds meta.machinesFile option that is passed to Nix as builders argument
2021-04-09 23:54:13 -07:00
Zhaofeng Li
0927fe9dc1
cli: Add hidden command to generate shell autocompletion
2021-03-23 14:14:04 -07:00
Zhaofeng Li
53b55a102e
cli: Set bin_name to be lower case
2021-03-23 14:14:04 -07:00
Zhaofeng Li
ba2574755a
Separate global CLI setup into module
2021-03-23 14:14:04 -07:00
Zhaofeng Li
8abcd5d53b
"Successfully built" -> "Build successful" for consistency
2021-03-18 15:13:34 -07:00
Zhaofeng Li
b44dd1f877
apply_local: Don't bother evaluating other hosts
2021-03-18 15:05:05 -07:00
Zhaofeng Li
e9487ced9e
host: Use the key uploader script for both SSH and local
2021-03-17 22:39:05 -07:00
Zhaofeng Li
29cfd45141
Miscellaneous doc fixes
2021-03-17 19:07:26 -07:00
Zhaofeng Li
610a725ba2
Add --keep-result to create GC roots for profiles
...
This resembles the behavior of morph.
Reference: #18
2021-03-17 14:59:57 -07:00
Zhaofeng Li
81375e71b2
deployment: Display the resulting paths if the goal is to build only
...
Reference: #18
2021-03-17 14:59:43 -07:00
Zhaofeng Li
180d2f2435
Merge pull request #17 from jasonrm/nix-copy-ssh-options
...
Makes SSH options available to nix-copy-closure
2021-03-14 23:06:04 -07:00
Jason R. McNeil
4098bf73bc
Makes SSH options available to nix-copy-closure
2021-03-14 22:20:47 -07:00
Zhaofeng Li
fb5ff6f9c9
Allow specifying alternative commands for privilege escalation
...
Fixes #16 .
2021-03-10 08:42:51 -08:00
Zhaofeng Li
082a033443
eval.nix: Exclude internal Nixpkgs config options from node override warning
2021-02-17 23:06:22 -08:00
Zhaofeng Li
3b005b0949
src/progress.rs: Oops, forgot to add
2021-02-17 22:56:34 -08:00
Zhaofeng Li
e32e130621
Always print the entire log for failures in eval and build
...
This makes it easier to debug configuration issues without -v.
Fixes #14 .
2021-02-17 22:48:26 -08:00
Zhaofeng Li
d16a13654c
Merge nixpkgs.config
and nixpkgs.overlays
...
This replaces #12 , and allows for Nixpkgs overlays and config to be overridden
in machine configs. With #12 , overlays set in machine configurations
(`nixpkgs.overlays`) get silently ignored.
2021-02-17 22:46:01 -08:00
Zhaofeng Li
9eae937b42
apply: Disable configuration of build process limit
2021-02-17 08:09:15 -08:00
Justinas Stankevicius
10f98d715f
Propagate same 'pkgs' to all modules
2021-02-16 20:53:43 +02:00
Zhaofeng Li
6a9282e121
exec: Remove outdated doc
2021-02-12 16:21:38 -08:00
Zhaofeng Li
30dc352eb9
eval.nix: Add type checking to meta/network
...
Primarily to make the evaluation error out if the configuration
tries to use non-existent options (e.g., pinning Nixpkgs with
morph-specific options).
2021-02-12 14:52:09 -08:00
Zhaofeng Li
d0bba90d04
ssh: Fix shell escaping
...
The previous `sh -c` invocation was incorrect and just happened
to work on hosts with a Bourne-compatible shell set as the login
shell. Commands in the deploy script were being executed in the
login shell.
2021-02-12 13:55:44 -08:00
Zhaofeng Li
95ddbcbfd6
ssh/deploy-key: Skip chown if the user/group doesn't exist
...
This matches the behavior of NixOps.
Potential solution to #10 .
2021-02-12 13:54:17 -08:00
Zhaofeng Li
dbd66d7c7c
Add initial set of tests
2021-02-11 13:27:21 -08:00
Justinas Stankevicius
4c7f8eb838
keyCommand: on error, do not upload key, report
2021-02-11 21:16:56 +02:00
Zhaofeng Li
e49e9367c0
key: Serialize KeySource through an intermediate struct
...
Well, still better than `if/else`-ing all the way. Also we
definitely need unit tests.
See #8 .
2021-02-11 00:51:11 -08:00
Zhaofeng Li
2886662e18
nix: Key names can contain one path component only
...
Well, I changed my mind and this should be cleaner.
2021-02-10 18:17:55 -08:00
Zhaofeng Li
52622ecd27
Add 'deployment.keys.<key>.keyCommand' support
...
Fixes #3 .
2021-02-10 18:08:47 -08:00
Zhaofeng Li
ce9f639a53
key: Make the key source better typed
2021-02-10 17:34:52 -08:00
Zhaofeng Li
62753ea138
progress: Let's just call them "tasks" instead of "processes"...
2021-02-10 17:20:49 -08:00
Zhaofeng Li
9d59a6a288
Merge pull request #5 from justinas/keys-keyfile
...
Add 'deployment.keys.<key>.keyFile' option
2021-02-10 17:20:28 -08:00
Justinas Stankevicius
d90fc56bc3
Implement key upload from local file
2021-02-10 20:37:54 +02:00
Justinas Stankevicius
f521f19629
Add deployment.keys.<key>.keyFile option
2021-02-10 20:37:54 +02:00
Zhaofeng Li
afabd8c6f9
Minor tokio cleanup
2021-02-10 10:29:17 -08:00
Zhaofeng Li
9f4d5a2221
Target stable toolchain
2021-02-10 00:41:02 -08:00
Zhaofeng Li
9a588815c8
exec.rs: Wording
2021-02-10 00:22:17 -08:00
Zhaofeng Li
d9d9bf48f6
apply.rs: Remove unused build limit flag
2021-02-09 22:33:45 -08:00
Zhaofeng Li
78a6825be6
Add exec command
2021-02-09 22:07:10 -08:00
Zhaofeng Li
1c9e7cdb83
Allow customization of SSH configurations
2021-02-09 21:02:00 -08:00
Zhaofeng Li
a2fa8f1da7
Clean up logging / progress display
2021-02-09 19:28:45 -08:00
Zhaofeng Li
8934726664
More fixes to key deployment and logging
2021-02-09 14:57:11 -08:00
Zhaofeng Li
84aa165aef
Refactoring and deployment.keys implementation
...
More refactoring of the deployment process, as well as an initial
implementation of `deployment.keys`.
Fixes #2 .
2021-02-08 19:00:29 -08:00
Zhaofeng Li
21c2bef3ad
Small fixes to eval logging
2021-02-05 02:20:57 -08:00
Zhaofeng Li
406e5a6443
apply-local: Allow overriding the node name
2021-02-05 02:20:08 -08:00
Zhaofeng Li
6e909477ae
nix/deployment: Well, that's an embarrassing typo...
2021-01-29 21:24:05 -08:00
Zhaofeng Li
68ecb095b8
nix: Small fixes to logging
2021-01-28 23:58:54 -08:00
Zhaofeng Li
ade2095919
Remove unused --no-build-substitutes
...
Ended up not implementing this.
2021-01-24 17:26:50 -08:00
Zhaofeng Li
506b894be6
Redesign deployment process
...
Now evaluation can be automatically split into chunks based on available
RAM. All three stages of the deployment process (evaluate, build,
apply) can happen concurrently.
Fixes #1 .
2021-01-24 14:08:48 -08:00
Zhaofeng Li
f53ebef41c
nix/eval.nix: Disallow setting network and meta at the same time
2021-01-17 00:06:45 -08:00
Zhaofeng Li
2050e84bb8
nix/eval.nix: Support setting meta.nixpkgs to a .nix that returns an initialized Nixpkgs attrset
2021-01-17 00:06:20 -08:00
Zhaofeng Li
f3bf3dc492
Allow disabling --use-substitutes and --gzip during copying
2021-01-13 12:20:34 -08:00
Zhaofeng Li
2cb429ed8d
Minor fixes to CLI help messages
2021-01-01 20:45:41 -08:00
Zhaofeng Li
be8e30cebf
deployment.rs: Strip line endings for error logs
2020-12-30 16:54:07 -08:00
Zhaofeng Li
1125eb6d1b
nix: Suppress GC warnings
...
The derivations and built closures are intentionally not added as GC
roots. Maybe we can provide an option for those who want GC roots
to be created.
2020-12-29 12:10:00 -08:00
Zhaofeng Li
4c1ce95c15
apply_local.rs: s/Coult/Could
2020-12-29 12:05:06 -08:00
Zhaofeng Li
60d6475897
Traverse up to find hive.nix by default, and other CLI ergonomics fixes
2020-12-29 12:02:50 -08:00
Zhaofeng Li
9c8e3034f7
deployment.rs: Clippy
2020-12-28 21:35:57 -08:00
Zhaofeng Li
ed52e259aa
Add support for --show-trace
2020-12-28 21:35:43 -08:00
Zhaofeng Li
ab6515d935
eval.nix: Do not specify system in evalConfig
2020-12-28 17:17:13 -08:00
Zhaofeng Li
c60d63e053
deployment.rs: There is nothing "internal" now about the error after the refactor
2020-12-20 00:58:51 -08:00
Zhaofeng Li
d99089ad6b
nix: Set profile only with certain goals
2020-12-19 16:34:24 -08:00
Zhaofeng Li
480d7ea5a1
apply_local: Refactoring oops
2020-12-19 16:28:55 -08:00
Zhaofeng Li
2ad5027cee
nix: Also set the system profile...
2020-12-19 16:28:34 -08:00
Zhaofeng Li
45b6568164
Support per-node Nixpkgs overrides and local deployment
...
Also renamed the `network` key to `meta`.
2020-12-19 15:10:22 -08:00
Zhaofeng Li
d0ed138ef0
Refactoring and other stuff
2020-12-18 01:28:02 -08:00
Zhaofeng Li
e092ba5bb1
Initial commit
2020-12-15 20:23:02 -08:00