nixos/flake.nix

134 lines
4.1 KiB
Nix
Raw Blame History

This file contains invisible Unicode characters!

This file contains invisible Unicode characters that may be processed differently from what appears below. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to reveal hidden characters.

This file contains ambiguous Unicode characters that may be confused with others in your current locale. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to highlight these characters.

{
description = "Configuration NixOS du Crans";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
flake-parts.url = "github:hercules-ci/flake-parts";
# Formatter
treefmt-nix = {
url = "github:numtide/treefmt-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
# Secret management
agenix = {
url = "github:ryantm/agenix";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs =
inputs@{
self,
nixpkgs,
flake-parts,
agenix,
...
}:
let
lib = nixpkgs.lib;
in
flake-parts.lib.mkFlake { inherit inputs; } {
imports = [ inputs.treefmt-nix.flakeModule ];
systems = [ "x86_64-linux" ];
flake = with lib; {
nixosConfigurations =
let
baseModules = [
./modules
agenix.nixosModules.default
];
infoRequired = {
name = lib.isString;
description = lib.isString;
id = lib.isInt;
};
verifyAttrs =
info:
let
missing = lib.filter (n: !(info ? ${n})) (map (i: i.name) (lib.attrsToList infoRequired));
wrongType = lib.filter (n: info ? ${n.name} && !(n.value info.${n.name})) (
lib.attrsToList infoRequired
);
in
(lib.warnIf (
lib.length missing > 0
) "${info.name}/info.nix : les attributs « ${lib.join ", " missing} » sont manquants")
(lib.warnIf (lib.length wrongType > 0)
"${info.name}/info.nix : les attributs « ${
lib.join ", " (map (i: i.name) wrongType)
} » sont mal typés"
)
(lib.warnIfNot (
(info.isDebian or false) || info ? enable
) "${info.name}/info.nix : cette machine nix ne définit pas l’attribut enable")
info;
get_hosts_names =
path: attrNames (attrsets.filterAttrs (name: type: type == "directory") (readDir path));
get_info =
path:
filter (x: x != null) (
map (
name:
let
filePath = path + "/${name}/info.nix";
in
if builtins.pathExists filePath then
verifyAttrs (import filePath)
else
warn "${toString filePath} not found" null
) (get_hosts_names path)
);
listInfoToAttrs =
infos: add: listToAttrs (map (info: lib.nameValuePair info.name (info // add)) infos);
attrsToNixosSystem =
path: all_hosts: hosts:
mapAttrs (
name: info:
nixosSystem {
specialArgs = inputs // {
hosts = all_hosts;
};
modules = [
(path + "/${name}")
({ ... }: { config.crans = info; })
]
++ baseModules;
}
) (attrsets.filterAttrs (name: info: !(info.isDebian or false)) hosts);
attrs_vm_info = listInfoToAttrs (get_info ./hosts/vm) { isVm = true; };
attrs_physique_info = listInfoToAttrs (get_info ./hosts/physiques) { isVm = false; };
attrs_all_info = attrs_physique_info // attrs_vm_info;
in
(attrsToNixosSystem ./hosts/vm attrs_all_info attrs_vm_info)
// (attrsToNixosSystem ./hosts/physiques attrs_all_info attrs_physique_info)
// {
cransIso = nixosSystem {
system = "x86_64-linux";
specialArgs = inputs;
modules = [
./hosts/iso
./modules/crans/locale.nix
];
};
};
};
perSystem =
{ config, pkgs, ... }:
{
devShells = {
default = pkgs.callPackage ./devshells/default.nix { inherit (inputs) agenix; };
};
};
};
}