Lib crans

hosts-v2
Pyjacpp 2026-09-16 10:43:53 +02:00
parent bf2cd34569
commit 6a11260c62
No known key found for this signature in database
GPG Key ID: ED479A5A26930939
5 changed files with 114 additions and 78 deletions

View File

@ -27,14 +27,20 @@
... ...
}: }:
let let
lib = nixpkgs.lib; lib = nixpkgs.lib.extend (
final: prev:
import ./lib {
inherit inputs;
lib = final;
}
);
in in
flake-parts.lib.mkFlake { inherit inputs; } { flake-parts.lib.mkFlake { inherit inputs; } {
imports = [ inputs.treefmt-nix.flakeModule ]; imports = [ inputs.treefmt-nix.flakeModule ];
systems = [ "x86_64-linux" ]; systems = [ "x86_64-linux" ];
flake = with lib; { flake = with lib.crans.info; {
nixosConfigurations = nixosConfigurations =
let let
baseModules = [ baseModules = [
@ -42,76 +48,14 @@
agenix.nixosModules.default agenix.nixosModules.default
]; ];
infoRequired = {
name = lib.isString;
description = lib.isString;
id = lib.isInt;
};
verifyAttrs =
info:
let
missing = lib.filter (n: !(info ? ${n})) (map (i: i.name) (lib.attrsToList infoRequired));
wrongType = lib.filter (n: info ? ${n.name} && !(n.value info.${n.name})) (
lib.attrsToList infoRequired
);
in
(lib.warnIf (
lib.length missing > 0
) "${info.name}/info.nix : les attributs « ${lib.join ", " missing} » sont manquants")
(lib.warnIf (lib.length wrongType > 0)
"${info.name}/info.nix : les attributs « ${
lib.join ", " (map (i: i.name) wrongType)
} » sont mal typés"
)
(lib.warnIfNot (
(info.isDebian or false) || info ? enable
) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable")
info;
get_hosts_names =
path: attrNames (attrsets.filterAttrs (name: type: type == "directory") (readDir path));
get_info =
path:
filter (x: x != null) (
map (
name:
let
filePath = path + "/${name}/info.nix";
in
if builtins.pathExists filePath then
verifyAttrs (import filePath)
else
warn "${toString filePath} not found" null
) (get_hosts_names path)
);
listInfoToAttrs =
infos: add: listToAttrs (map (info: lib.nameValuePair info.name (info // add)) infos);
attrsToNixosSystem =
path: all_hosts: hosts:
mapAttrs (
name: info:
nixosSystem {
specialArgs = inputs // {
hosts = all_hosts;
};
modules = [
(path + "/${name}")
({ ... }: { config.crans = info; })
]
++ baseModules;
}
) (attrsets.filterAttrs (name: info: !(info.isDebian or false)) hosts);
attrs_vm_info = listInfoToAttrs (get_info ./hosts/vm) { isVm = true; }; attrs_vm_info = listInfoToAttrs (get_info ./hosts/vm) { isVm = true; };
attrs_physique_info = listInfoToAttrs (get_info ./hosts/physiques) { isVm = false; }; attrs_physique_info = listInfoToAttrs (get_info ./hosts/physiques) { isVm = false; };
attrs_all_info = attrs_physique_info // attrs_vm_info; attrs_all_info = attrs_physique_info // attrs_vm_info;
in in
(attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info) (attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info baseModules)
// (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info) // (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info baseModules)
// { // {
cransIso = nixosSystem { cransIso = lib.nixosSystem {
system = "x86_64-linux"; system = "x86_64-linux";
specialArgs = inputs; specialArgs = inputs;
modules = [ modules = [

View File

@ -8,6 +8,8 @@ let
formatJSON = pkgs.formats.json { }; formatJSON = pkgs.formats.json { };
formatYAML = pkgs.formats.yaml { }; formatYAML = pkgs.formats.yaml { };
inherit (lib.crans) fetchFromCrans;
antiBot = formatYAML.generate "antibot.yaml" [ antiBot = formatYAML.generate "antibot.yaml" [
{ {
name = "whitelist-crans"; name = "whitelist-crans";
@ -160,16 +162,6 @@ let
]; ];
}; };
fetchFromCrans =
opts:
pkgs.fetchFromGitLab (
{
domain = "gitlab.adm.crans.org";
owner = "nounous";
}
// opts
);
installPartySite = pkgs.python3Packages.buildPythonApplication { installPartySite = pkgs.python3Packages.buildPythonApplication {
name = "site-install-party"; name = "site-install-party";
pyproject = false; pyproject = false;

19
lib/default.nix 100644
View File

@ -0,0 +1,19 @@
args@{ inputs, ... }:
let
pkgs = inputs.nixpkgs.legacyPackages.x86_64-linux;
in
{
crans = {
info = import ./info.nix args;
fetchFromCrans =
opts:
pkgs.fetchFromGitLab (
{
domain = "gitlab.adm.crans.org";
owner = "nounous";
}
// opts
);
};
}

81
lib/info.nix 100644
View File

@ -0,0 +1,81 @@
{ lib, inputs, ... }:
let
inherit (lib)
attrNames
attrsToList
isInt
isString
join
length
listToAttrs
filter
filterAttrs
mapAttrs
nameValuePair
nixosSystem
readDir
warn
warnIf
warnIfNot
;
in
rec {
infoRequired = {
name = isString;
description = isString;
id = isInt;
};
verifyAttrs =
info:
let
missing = filter (n: !(info ? ${n})) (attrNames infoRequired);
wrongType = filter (n: info ? ${n.name} && !(n.value info.${n.name})) (attrsToList infoRequired);
in
(warnIf (
length missing > 0
) "${info.name}/info.nix : les attributs « ${join ", " missing} » sont manquants")
(warnIf (length wrongType > 0)
"${info.name}/info.nix : les attributs « ${join ", " (map (i: i.name) wrongType)} » sont mal typés"
)
(warnIfNot (
(info.isDebian or false) || info ? enable
) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable")
info;
get_hosts_names = path: attrNames (filterAttrs (name: type: type == "directory") (readDir path));
get_info =
path:
filter (x: x != null) (
map (
name:
let
filePath = path + "/${name}/info.nix";
in
if builtins.pathExists filePath then
verifyAttrs (import filePath)
else
warn "${toString filePath} not found" null
) (get_hosts_names path)
);
listInfoToAttrs = infos: add: listToAttrs (map (info: nameValuePair info.name (info // add)) infos);
attrsToNixosSystem =
path: all_hosts: hosts: baseModules:
mapAttrs (
name: info:
nixosSystem {
specialArgs = inputs // {
hosts = all_hosts;
};
modules = [
(path + "/${name}")
({ ... }: { config.crans = info; })
]
++ baseModules;
}
) (filterAttrs (name: info: !(info.isDebian or false)) hosts);
}

View File

@ -23,7 +23,7 @@ in
root = { root = {
passwordFile = mkOption { passwordFile = mkOption {
type = types.externalPath; type = types.path;
default = ../../secrets/common/root.age; default = ../../secrets/common/root.age;
example = ../../secrets/apprentix/root.age; example = ../../secrets/apprentix/root.age;
description = "Fichier chiffré par age contenant le mot de passe root."; description = "Fichier chiffré par age contenant le mot de passe root.";