diff --git a/flake.nix b/flake.nix index 6a3a797..7b90db8 100644 --- a/flake.nix +++ b/flake.nix @@ -27,14 +27,20 @@ ... }: let - lib = nixpkgs.lib; + lib = nixpkgs.lib.extend ( + final: prev: + import ./lib { + inherit inputs; + lib = final; + } + ); in flake-parts.lib.mkFlake { inherit inputs; } { imports = [ inputs.treefmt-nix.flakeModule ]; systems = [ "x86_64-linux" ]; - flake = with lib; { + flake = with lib.crans.info; { nixosConfigurations = let baseModules = [ @@ -42,76 +48,14 @@ agenix.nixosModules.default ]; - infoRequired = { - name = lib.isString; - description = lib.isString; - id = lib.isInt; - }; - verifyAttrs = - info: - let - missing = lib.filter (n: !(info ? ${n})) (map (i: i.name) (lib.attrsToList infoRequired)); - wrongType = lib.filter (n: info ? ${n.name} && !(n.value info.${n.name})) ( - lib.attrsToList infoRequired - ); - in - (lib.warnIf ( - lib.length missing > 0 - ) "${info.name}/info.nix : les attributs « ${lib.join ", " missing} » sont manquants") - (lib.warnIf (lib.length wrongType > 0) - "${info.name}/info.nix : les attributs « ${ - lib.join ", " (map (i: i.name) wrongType) - } » sont mal typés" - ) - (lib.warnIfNot ( - (info.isDebian or false) || info ? enable - ) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable") - info; - - get_hosts_names = - path: attrNames (attrsets.filterAttrs (name: type: type == "directory") (readDir path)); - get_info = - path: - filter (x: x != null) ( - map ( - name: - let - filePath = path + "/${name}/info.nix"; - in - if builtins.pathExists filePath then - verifyAttrs (import filePath) - else - warn "${toString filePath} not found" null - ) (get_hosts_names path) - ); - - listInfoToAttrs = - infos: add: listToAttrs (map (info: lib.nameValuePair info.name (info // add)) infos); - - attrsToNixosSystem = - path: all_hosts: hosts: - mapAttrs ( - name: info: - nixosSystem { - specialArgs = inputs // { - hosts = all_hosts; - }; - modules = [ - (path + "/${name}") - ({ ... }: { config.crans = info; }) - ] - ++ baseModules; - } - ) (attrsets.filterAttrs (name: info: !(info.isDebian or false)) hosts); - attrs_vm_info = listInfoToAttrs (get_info ./hosts/vm) { isVm = true; }; attrs_physique_info = listInfoToAttrs (get_info ./hosts/physiques) { isVm = false; }; attrs_all_info = attrs_physique_info // attrs_vm_info; in - (attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info) - // (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info) + (attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info baseModules) + // (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info baseModules) // { - cransIso = nixosSystem { + cransIso = lib.nixosSystem { system = "x86_64-linux"; specialArgs = inputs; modules = [ diff --git a/hosts/vm/reverseproxy/reverseproxy.nix b/hosts/vm/reverseproxy/reverseproxy.nix index f0d5b78..8301373 100644 --- a/hosts/vm/reverseproxy/reverseproxy.nix +++ b/hosts/vm/reverseproxy/reverseproxy.nix @@ -8,6 +8,8 @@ let formatJSON = pkgs.formats.json { }; formatYAML = pkgs.formats.yaml { }; + inherit (lib.crans) fetchFromCrans; + antiBot = formatYAML.generate "antibot.yaml" [ { name = "whitelist-crans"; @@ -160,16 +162,6 @@ let ]; }; - fetchFromCrans = - opts: - pkgs.fetchFromGitLab ( - { - domain = "gitlab.adm.crans.org"; - owner = "nounous"; - } - // opts - ); - installPartySite = pkgs.python3Packages.buildPythonApplication { name = "site-install-party"; pyproject = false; diff --git a/lib/default.nix b/lib/default.nix new file mode 100644 index 0000000..e3ffe47 --- /dev/null +++ b/lib/default.nix @@ -0,0 +1,19 @@ +args@{ inputs, ... }: +let + pkgs = inputs.nixpkgs.legacyPackages.x86_64-linux; +in +{ + crans = { + info = import ./info.nix args; + + fetchFromCrans = + opts: + pkgs.fetchFromGitLab ( + { + domain = "gitlab.adm.crans.org"; + owner = "nounous"; + } + // opts + ); + }; +} diff --git a/lib/info.nix b/lib/info.nix new file mode 100644 index 0000000..b3cd64f --- /dev/null +++ b/lib/info.nix @@ -0,0 +1,81 @@ +{ lib, inputs, ... }: + +let + inherit (lib) + attrNames + attrsToList + isInt + isString + join + length + listToAttrs + filter + filterAttrs + mapAttrs + nameValuePair + nixosSystem + readDir + warn + warnIf + warnIfNot + ; +in +rec { + + infoRequired = { + name = isString; + description = isString; + id = isInt; + }; + verifyAttrs = + info: + let + missing = filter (n: !(info ? ${n})) (attrNames infoRequired); + wrongType = filter (n: info ? ${n.name} && !(n.value info.${n.name})) (attrsToList infoRequired); + in + (warnIf ( + length missing > 0 + ) "${info.name}/info.nix : les attributs « ${join ", " missing} » sont manquants") + (warnIf (length wrongType > 0) + "${info.name}/info.nix : les attributs « ${join ", " (map (i: i.name) wrongType)} » sont mal typés" + ) + (warnIfNot ( + (info.isDebian or false) || info ? enable + ) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable") + info; + + get_hosts_names = path: attrNames (filterAttrs (name: type: type == "directory") (readDir path)); + get_info = + path: + filter (x: x != null) ( + map ( + name: + let + filePath = path + "/${name}/info.nix"; + in + if builtins.pathExists filePath then + verifyAttrs (import filePath) + else + warn "${toString filePath} not found" null + ) (get_hosts_names path) + ); + + listInfoToAttrs = infos: add: listToAttrs (map (info: nameValuePair info.name (info // add)) infos); + + attrsToNixosSystem = + path: all_hosts: hosts: baseModules: + mapAttrs ( + name: info: + nixosSystem { + specialArgs = inputs // { + hosts = all_hosts; + }; + modules = [ + (path + "/${name}") + ({ ... }: { config.crans = info; }) + ] + ++ baseModules; + } + ) (filterAttrs (name: info: !(info.isDebian or false)) hosts); + +} diff --git a/modules/crans/users.nix b/modules/crans/users.nix index 892aede..9c14880 100644 --- a/modules/crans/users.nix +++ b/modules/crans/users.nix @@ -23,7 +23,7 @@ in root = { passwordFile = mkOption { - type = types.externalPath; + type = types.path; default = ../../secrets/common/root.age; example = ../../secrets/apprentix/root.age; description = "Fichier chiffré par age contenant le mot de passe root.";