mirror of https://gitlab.crans.org/nounous/nixos
Lib crans
parent
bf2cd34569
commit
6a11260c62
78
flake.nix
78
flake.nix
|
|
@ -27,14 +27,20 @@
|
|||
...
|
||||
}:
|
||||
let
|
||||
lib = nixpkgs.lib;
|
||||
lib = nixpkgs.lib.extend (
|
||||
final: prev:
|
||||
import ./lib {
|
||||
inherit inputs;
|
||||
lib = final;
|
||||
}
|
||||
);
|
||||
in
|
||||
flake-parts.lib.mkFlake { inherit inputs; } {
|
||||
imports = [ inputs.treefmt-nix.flakeModule ];
|
||||
|
||||
systems = [ "x86_64-linux" ];
|
||||
|
||||
flake = with lib; {
|
||||
flake = with lib.crans.info; {
|
||||
nixosConfigurations =
|
||||
let
|
||||
baseModules = [
|
||||
|
|
@ -42,76 +48,14 @@
|
|||
agenix.nixosModules.default
|
||||
];
|
||||
|
||||
infoRequired = {
|
||||
name = lib.isString;
|
||||
description = lib.isString;
|
||||
id = lib.isInt;
|
||||
};
|
||||
verifyAttrs =
|
||||
info:
|
||||
let
|
||||
missing = lib.filter (n: !(info ? ${n})) (map (i: i.name) (lib.attrsToList infoRequired));
|
||||
wrongType = lib.filter (n: info ? ${n.name} && !(n.value info.${n.name})) (
|
||||
lib.attrsToList infoRequired
|
||||
);
|
||||
in
|
||||
(lib.warnIf (
|
||||
lib.length missing > 0
|
||||
) "${info.name}/info.nix : les attributs « ${lib.join ", " missing} » sont manquants")
|
||||
(lib.warnIf (lib.length wrongType > 0)
|
||||
"${info.name}/info.nix : les attributs « ${
|
||||
lib.join ", " (map (i: i.name) wrongType)
|
||||
} » sont mal typés"
|
||||
)
|
||||
(lib.warnIfNot (
|
||||
(info.isDebian or false) || info ? enable
|
||||
) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable")
|
||||
info;
|
||||
|
||||
get_hosts_names =
|
||||
path: attrNames (attrsets.filterAttrs (name: type: type == "directory") (readDir path));
|
||||
get_info =
|
||||
path:
|
||||
filter (x: x != null) (
|
||||
map (
|
||||
name:
|
||||
let
|
||||
filePath = path + "/${name}/info.nix";
|
||||
in
|
||||
if builtins.pathExists filePath then
|
||||
verifyAttrs (import filePath)
|
||||
else
|
||||
warn "${toString filePath} not found" null
|
||||
) (get_hosts_names path)
|
||||
);
|
||||
|
||||
listInfoToAttrs =
|
||||
infos: add: listToAttrs (map (info: lib.nameValuePair info.name (info // add)) infos);
|
||||
|
||||
attrsToNixosSystem =
|
||||
path: all_hosts: hosts:
|
||||
mapAttrs (
|
||||
name: info:
|
||||
nixosSystem {
|
||||
specialArgs = inputs // {
|
||||
hosts = all_hosts;
|
||||
};
|
||||
modules = [
|
||||
(path + "/${name}")
|
||||
({ ... }: { config.crans = info; })
|
||||
]
|
||||
++ baseModules;
|
||||
}
|
||||
) (attrsets.filterAttrs (name: info: !(info.isDebian or false)) hosts);
|
||||
|
||||
attrs_vm_info = listInfoToAttrs (get_info ./hosts/vm) { isVm = true; };
|
||||
attrs_physique_info = listInfoToAttrs (get_info ./hosts/physiques) { isVm = false; };
|
||||
attrs_all_info = attrs_physique_info // attrs_vm_info;
|
||||
in
|
||||
(attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info)
|
||||
// (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info)
|
||||
(attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info baseModules)
|
||||
// (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info baseModules)
|
||||
// {
|
||||
cransIso = nixosSystem {
|
||||
cransIso = lib.nixosSystem {
|
||||
system = "x86_64-linux";
|
||||
specialArgs = inputs;
|
||||
modules = [
|
||||
|
|
|
|||
|
|
@ -8,6 +8,8 @@ let
|
|||
formatJSON = pkgs.formats.json { };
|
||||
formatYAML = pkgs.formats.yaml { };
|
||||
|
||||
inherit (lib.crans) fetchFromCrans;
|
||||
|
||||
antiBot = formatYAML.generate "antibot.yaml" [
|
||||
{
|
||||
name = "whitelist-crans";
|
||||
|
|
@ -160,16 +162,6 @@ let
|
|||
];
|
||||
};
|
||||
|
||||
fetchFromCrans =
|
||||
opts:
|
||||
pkgs.fetchFromGitLab (
|
||||
{
|
||||
domain = "gitlab.adm.crans.org";
|
||||
owner = "nounous";
|
||||
}
|
||||
// opts
|
||||
);
|
||||
|
||||
installPartySite = pkgs.python3Packages.buildPythonApplication {
|
||||
name = "site-install-party";
|
||||
pyproject = false;
|
||||
|
|
|
|||
|
|
@ -0,0 +1,19 @@
|
|||
args@{ inputs, ... }:
|
||||
let
|
||||
pkgs = inputs.nixpkgs.legacyPackages.x86_64-linux;
|
||||
in
|
||||
{
|
||||
crans = {
|
||||
info = import ./info.nix args;
|
||||
|
||||
fetchFromCrans =
|
||||
opts:
|
||||
pkgs.fetchFromGitLab (
|
||||
{
|
||||
domain = "gitlab.adm.crans.org";
|
||||
owner = "nounous";
|
||||
}
|
||||
// opts
|
||||
);
|
||||
};
|
||||
}
|
||||
|
|
@ -0,0 +1,81 @@
|
|||
{ lib, inputs, ... }:
|
||||
|
||||
let
|
||||
inherit (lib)
|
||||
attrNames
|
||||
attrsToList
|
||||
isInt
|
||||
isString
|
||||
join
|
||||
length
|
||||
listToAttrs
|
||||
filter
|
||||
filterAttrs
|
||||
mapAttrs
|
||||
nameValuePair
|
||||
nixosSystem
|
||||
readDir
|
||||
warn
|
||||
warnIf
|
||||
warnIfNot
|
||||
;
|
||||
in
|
||||
rec {
|
||||
|
||||
infoRequired = {
|
||||
name = isString;
|
||||
description = isString;
|
||||
id = isInt;
|
||||
};
|
||||
verifyAttrs =
|
||||
info:
|
||||
let
|
||||
missing = filter (n: !(info ? ${n})) (attrNames infoRequired);
|
||||
wrongType = filter (n: info ? ${n.name} && !(n.value info.${n.name})) (attrsToList infoRequired);
|
||||
in
|
||||
(warnIf (
|
||||
length missing > 0
|
||||
) "${info.name}/info.nix : les attributs « ${join ", " missing} » sont manquants")
|
||||
(warnIf (length wrongType > 0)
|
||||
"${info.name}/info.nix : les attributs « ${join ", " (map (i: i.name) wrongType)} » sont mal typés"
|
||||
)
|
||||
(warnIfNot (
|
||||
(info.isDebian or false) || info ? enable
|
||||
) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable")
|
||||
info;
|
||||
|
||||
get_hosts_names = path: attrNames (filterAttrs (name: type: type == "directory") (readDir path));
|
||||
get_info =
|
||||
path:
|
||||
filter (x: x != null) (
|
||||
map (
|
||||
name:
|
||||
let
|
||||
filePath = path + "/${name}/info.nix";
|
||||
in
|
||||
if builtins.pathExists filePath then
|
||||
verifyAttrs (import filePath)
|
||||
else
|
||||
warn "${toString filePath} not found" null
|
||||
) (get_hosts_names path)
|
||||
);
|
||||
|
||||
listInfoToAttrs = infos: add: listToAttrs (map (info: nameValuePair info.name (info // add)) infos);
|
||||
|
||||
attrsToNixosSystem =
|
||||
path: all_hosts: hosts: baseModules:
|
||||
mapAttrs (
|
||||
name: info:
|
||||
nixosSystem {
|
||||
specialArgs = inputs // {
|
||||
hosts = all_hosts;
|
||||
};
|
||||
modules = [
|
||||
(path + "/${name}")
|
||||
({ ... }: { config.crans = info; })
|
||||
]
|
||||
++ baseModules;
|
||||
}
|
||||
) (filterAttrs (name: info: !(info.isDebian or false)) hosts);
|
||||
|
||||
}
|
||||
|
|
@ -23,7 +23,7 @@ in
|
|||
|
||||
root = {
|
||||
passwordFile = mkOption {
|
||||
type = types.externalPath;
|
||||
type = types.path;
|
||||
default = ../../secrets/common/root.age;
|
||||
example = ../../secrets/apprentix/root.age;
|
||||
description = "Fichier chiffré par age contenant le mot de passe root.";
|
||||
|
|
|
|||
Loading…
Reference in New Issue