mirror of https://gitlab.crans.org/nounous/nixos
Lib crans
parent
bf2cd34569
commit
6a11260c62
78
flake.nix
78
flake.nix
|
|
@ -27,14 +27,20 @@
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
let
|
let
|
||||||
lib = nixpkgs.lib;
|
lib = nixpkgs.lib.extend (
|
||||||
|
final: prev:
|
||||||
|
import ./lib {
|
||||||
|
inherit inputs;
|
||||||
|
lib = final;
|
||||||
|
}
|
||||||
|
);
|
||||||
in
|
in
|
||||||
flake-parts.lib.mkFlake { inherit inputs; } {
|
flake-parts.lib.mkFlake { inherit inputs; } {
|
||||||
imports = [ inputs.treefmt-nix.flakeModule ];
|
imports = [ inputs.treefmt-nix.flakeModule ];
|
||||||
|
|
||||||
systems = [ "x86_64-linux" ];
|
systems = [ "x86_64-linux" ];
|
||||||
|
|
||||||
flake = with lib; {
|
flake = with lib.crans.info; {
|
||||||
nixosConfigurations =
|
nixosConfigurations =
|
||||||
let
|
let
|
||||||
baseModules = [
|
baseModules = [
|
||||||
|
|
@ -42,76 +48,14 @@
|
||||||
agenix.nixosModules.default
|
agenix.nixosModules.default
|
||||||
];
|
];
|
||||||
|
|
||||||
infoRequired = {
|
|
||||||
name = lib.isString;
|
|
||||||
description = lib.isString;
|
|
||||||
id = lib.isInt;
|
|
||||||
};
|
|
||||||
verifyAttrs =
|
|
||||||
info:
|
|
||||||
let
|
|
||||||
missing = lib.filter (n: !(info ? ${n})) (map (i: i.name) (lib.attrsToList infoRequired));
|
|
||||||
wrongType = lib.filter (n: info ? ${n.name} && !(n.value info.${n.name})) (
|
|
||||||
lib.attrsToList infoRequired
|
|
||||||
);
|
|
||||||
in
|
|
||||||
(lib.warnIf (
|
|
||||||
lib.length missing > 0
|
|
||||||
) "${info.name}/info.nix : les attributs « ${lib.join ", " missing} » sont manquants")
|
|
||||||
(lib.warnIf (lib.length wrongType > 0)
|
|
||||||
"${info.name}/info.nix : les attributs « ${
|
|
||||||
lib.join ", " (map (i: i.name) wrongType)
|
|
||||||
} » sont mal typés"
|
|
||||||
)
|
|
||||||
(lib.warnIfNot (
|
|
||||||
(info.isDebian or false) || info ? enable
|
|
||||||
) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable")
|
|
||||||
info;
|
|
||||||
|
|
||||||
get_hosts_names =
|
|
||||||
path: attrNames (attrsets.filterAttrs (name: type: type == "directory") (readDir path));
|
|
||||||
get_info =
|
|
||||||
path:
|
|
||||||
filter (x: x != null) (
|
|
||||||
map (
|
|
||||||
name:
|
|
||||||
let
|
|
||||||
filePath = path + "/${name}/info.nix";
|
|
||||||
in
|
|
||||||
if builtins.pathExists filePath then
|
|
||||||
verifyAttrs (import filePath)
|
|
||||||
else
|
|
||||||
warn "${toString filePath} not found" null
|
|
||||||
) (get_hosts_names path)
|
|
||||||
);
|
|
||||||
|
|
||||||
listInfoToAttrs =
|
|
||||||
infos: add: listToAttrs (map (info: lib.nameValuePair info.name (info // add)) infos);
|
|
||||||
|
|
||||||
attrsToNixosSystem =
|
|
||||||
path: all_hosts: hosts:
|
|
||||||
mapAttrs (
|
|
||||||
name: info:
|
|
||||||
nixosSystem {
|
|
||||||
specialArgs = inputs // {
|
|
||||||
hosts = all_hosts;
|
|
||||||
};
|
|
||||||
modules = [
|
|
||||||
(path + "/${name}")
|
|
||||||
({ ... }: { config.crans = info; })
|
|
||||||
]
|
|
||||||
++ baseModules;
|
|
||||||
}
|
|
||||||
) (attrsets.filterAttrs (name: info: !(info.isDebian or false)) hosts);
|
|
||||||
|
|
||||||
attrs_vm_info = listInfoToAttrs (get_info ./hosts/vm) { isVm = true; };
|
attrs_vm_info = listInfoToAttrs (get_info ./hosts/vm) { isVm = true; };
|
||||||
attrs_physique_info = listInfoToAttrs (get_info ./hosts/physiques) { isVm = false; };
|
attrs_physique_info = listInfoToAttrs (get_info ./hosts/physiques) { isVm = false; };
|
||||||
attrs_all_info = attrs_physique_info // attrs_vm_info;
|
attrs_all_info = attrs_physique_info // attrs_vm_info;
|
||||||
in
|
in
|
||||||
(attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info)
|
(attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info baseModules)
|
||||||
// (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info)
|
// (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info baseModules)
|
||||||
// {
|
// {
|
||||||
cransIso = nixosSystem {
|
cransIso = lib.nixosSystem {
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
specialArgs = inputs;
|
specialArgs = inputs;
|
||||||
modules = [
|
modules = [
|
||||||
|
|
|
||||||
|
|
@ -8,6 +8,8 @@ let
|
||||||
formatJSON = pkgs.formats.json { };
|
formatJSON = pkgs.formats.json { };
|
||||||
formatYAML = pkgs.formats.yaml { };
|
formatYAML = pkgs.formats.yaml { };
|
||||||
|
|
||||||
|
inherit (lib.crans) fetchFromCrans;
|
||||||
|
|
||||||
antiBot = formatYAML.generate "antibot.yaml" [
|
antiBot = formatYAML.generate "antibot.yaml" [
|
||||||
{
|
{
|
||||||
name = "whitelist-crans";
|
name = "whitelist-crans";
|
||||||
|
|
@ -160,16 +162,6 @@ let
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
fetchFromCrans =
|
|
||||||
opts:
|
|
||||||
pkgs.fetchFromGitLab (
|
|
||||||
{
|
|
||||||
domain = "gitlab.adm.crans.org";
|
|
||||||
owner = "nounous";
|
|
||||||
}
|
|
||||||
// opts
|
|
||||||
);
|
|
||||||
|
|
||||||
installPartySite = pkgs.python3Packages.buildPythonApplication {
|
installPartySite = pkgs.python3Packages.buildPythonApplication {
|
||||||
name = "site-install-party";
|
name = "site-install-party";
|
||||||
pyproject = false;
|
pyproject = false;
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,19 @@
|
||||||
|
args@{ inputs, ... }:
|
||||||
|
let
|
||||||
|
pkgs = inputs.nixpkgs.legacyPackages.x86_64-linux;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
crans = {
|
||||||
|
info = import ./info.nix args;
|
||||||
|
|
||||||
|
fetchFromCrans =
|
||||||
|
opts:
|
||||||
|
pkgs.fetchFromGitLab (
|
||||||
|
{
|
||||||
|
domain = "gitlab.adm.crans.org";
|
||||||
|
owner = "nounous";
|
||||||
|
}
|
||||||
|
// opts
|
||||||
|
);
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
@ -0,0 +1,81 @@
|
||||||
|
{ lib, inputs, ... }:
|
||||||
|
|
||||||
|
let
|
||||||
|
inherit (lib)
|
||||||
|
attrNames
|
||||||
|
attrsToList
|
||||||
|
isInt
|
||||||
|
isString
|
||||||
|
join
|
||||||
|
length
|
||||||
|
listToAttrs
|
||||||
|
filter
|
||||||
|
filterAttrs
|
||||||
|
mapAttrs
|
||||||
|
nameValuePair
|
||||||
|
nixosSystem
|
||||||
|
readDir
|
||||||
|
warn
|
||||||
|
warnIf
|
||||||
|
warnIfNot
|
||||||
|
;
|
||||||
|
in
|
||||||
|
rec {
|
||||||
|
|
||||||
|
infoRequired = {
|
||||||
|
name = isString;
|
||||||
|
description = isString;
|
||||||
|
id = isInt;
|
||||||
|
};
|
||||||
|
verifyAttrs =
|
||||||
|
info:
|
||||||
|
let
|
||||||
|
missing = filter (n: !(info ? ${n})) (attrNames infoRequired);
|
||||||
|
wrongType = filter (n: info ? ${n.name} && !(n.value info.${n.name})) (attrsToList infoRequired);
|
||||||
|
in
|
||||||
|
(warnIf (
|
||||||
|
length missing > 0
|
||||||
|
) "${info.name}/info.nix : les attributs « ${join ", " missing} » sont manquants")
|
||||||
|
(warnIf (length wrongType > 0)
|
||||||
|
"${info.name}/info.nix : les attributs « ${join ", " (map (i: i.name) wrongType)} » sont mal typés"
|
||||||
|
)
|
||||||
|
(warnIfNot (
|
||||||
|
(info.isDebian or false) || info ? enable
|
||||||
|
) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable")
|
||||||
|
info;
|
||||||
|
|
||||||
|
get_hosts_names = path: attrNames (filterAttrs (name: type: type == "directory") (readDir path));
|
||||||
|
get_info =
|
||||||
|
path:
|
||||||
|
filter (x: x != null) (
|
||||||
|
map (
|
||||||
|
name:
|
||||||
|
let
|
||||||
|
filePath = path + "/${name}/info.nix";
|
||||||
|
in
|
||||||
|
if builtins.pathExists filePath then
|
||||||
|
verifyAttrs (import filePath)
|
||||||
|
else
|
||||||
|
warn "${toString filePath} not found" null
|
||||||
|
) (get_hosts_names path)
|
||||||
|
);
|
||||||
|
|
||||||
|
listInfoToAttrs = infos: add: listToAttrs (map (info: nameValuePair info.name (info // add)) infos);
|
||||||
|
|
||||||
|
attrsToNixosSystem =
|
||||||
|
path: all_hosts: hosts: baseModules:
|
||||||
|
mapAttrs (
|
||||||
|
name: info:
|
||||||
|
nixosSystem {
|
||||||
|
specialArgs = inputs // {
|
||||||
|
hosts = all_hosts;
|
||||||
|
};
|
||||||
|
modules = [
|
||||||
|
(path + "/${name}")
|
||||||
|
({ ... }: { config.crans = info; })
|
||||||
|
]
|
||||||
|
++ baseModules;
|
||||||
|
}
|
||||||
|
) (filterAttrs (name: info: !(info.isDebian or false)) hosts);
|
||||||
|
|
||||||
|
}
|
||||||
|
|
@ -23,7 +23,7 @@ in
|
||||||
|
|
||||||
root = {
|
root = {
|
||||||
passwordFile = mkOption {
|
passwordFile = mkOption {
|
||||||
type = types.externalPath;
|
type = types.path;
|
||||||
default = ../../secrets/common/root.age;
|
default = ../../secrets/common/root.age;
|
||||||
example = ../../secrets/apprentix/root.age;
|
example = ../../secrets/apprentix/root.age;
|
||||||
description = "Fichier chiffré par age contenant le mot de passe root.";
|
description = "Fichier chiffré par age contenant le mot de passe root.";
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue