]> Git — Sourcephile - julm/julm-nix.git/blob - Makefile
init
[julm/julm-nix.git] / Makefile
1 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
2 machine := oignon
3 disk_ssd := /dev/disk/by-id/ata-Samsung_SSD_850_PRO_128GB_S1SMNSAFC36436X
4 zpool := $(machine)
5 cipher := aes-128-gcm
6 autotrim := on
7 reservation := 1G
8
9 wipe:
10 sudo modprobe zfs
11 sudo zpool labelclear -f /dev/disk/by-partlabel/$(machine)_ssd_zpool || true
12 sudo $$(which sgdisk) --zap-all $(disk_ssd)
13
14 part: wipe
15 # https://wiki.archlinux.org/index.php/BIOS_boot_partition
16 sudo $$(which sgdisk) -a1 -n0:34:2047 -t0:EF02 -c0:"$(machine)_ssd_bios" $(disk_ssd)
17 sudo $$(which sgdisk) -n0:1M:+32M -t0:EF00 -c0:"$(machine)_ssd_efi" $(disk_ssd)
18 sudo $$(which sgdisk) -n0:0:+256M -t0:8300 -c0:"$(machine)_ssd_boot" $(disk_ssd)
19 sudo $$(which sgdisk) -n0:0:+4G -t0:8200 -c0:"$(machine)_ssd_swap" $(disk_ssd)
20 sudo $$(which sgdisk) -n0:0:0 -t0:BF01 -c0:"$(machine)_ssd_zpool" $(disk_ssd)
21 # https://wiki.archlinux.org/index.php/Partitioning#Tricking_old_BIOS_into_booting_from_GPT
22 printf '\200\0\0\0\0\0\0\0\0\0\0\0\001\0\0\0' | sudo dd of=$(disk_ssd) bs=1 seek=462
23 sudo $$(which sgdisk) --randomize-guids $(disk_ssd)
24 sudo $$(which sgdisk) --backup=$(machine)_ssd.sgdisk $(disk_ssd)
25
26 format: umount format-efi format-boot format-zpool
27 format-efi:
28 sudo blkid /dev/disk/by-partlabel/$(machine)_ssd_efi -t TYPE=vfat || \
29 sudo mkfs.vfat -F 16 -s 1 -n EFI /dev/disk/by-partlabel/$(machine)_ssd_efi
30 format-boot:
31 sudo mkdir -p /mnt/$(machine)
32 sudo blkid -t TYPE=ext2 /dev/disk/by-partlabel/$(machine)_ssd_boot; test $$? != 2 || \
33 sudo mkfs.ext2 /dev/disk/by-partlabel/$(machine)_ssd_boot
34 format-zpool:
35 sudo zpool list $(zpool) 2>/dev/null || \
36 sudo zpool create -o ashift=12 \
37 -O utf8only=yes \
38 $(if $(cipher),-O encryption=$(cipher) \
39 -O keyformat=passphrase \
40 -O keylocation=prompt) \
41 -R /mnt/$(machine) $(zpool) /dev/disk/by-partlabel/$(machine)_ssd_zpool
42 sudo zpool set \
43 autotrim=$(autotrim) \
44 $(zpool)
45 sudo zfs set \
46 acltype=off \
47 atime=off \
48 canmount=off \
49 compression=lz4 \
50 dnodesize=auto \
51 relatime=on \
52 xattr=off \
53 mountpoint=/ \
54 $(zpool)
55 # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
56 sudo zfs list $(zpool)/reserved 2>/dev/null || \
57 sudo zfs create -o canmount=off -o mountpoint=none $(zpool)/reserved
58 sudo zfs set reservation=$(reservation) $(zpool)/reserved
59 # /
60 # mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
61 sudo zfs list $(zpool)/root 2>/dev/null || \
62 sudo zfs create \
63 -o canmount=on \
64 -o mountpoint=legacy \
65 $(zpool)/root
66 # /*
67 for p in \
68 home \
69 home/documents \
70 nix \
71 var \
72 ; do \
73 sudo zfs list $(zpool)/"$$p" 2>/dev/null || \
74 sudo zfs create \
75 -o canmount=on \
76 -o mountpoint=legacy \
77 $(zpool)/"$$p" ; \
78 done
79 #sudo zfs set sync=disabled $(zpool)/var/tmp
80 sudo zfs set copies=2 $(zpool)/home/documents
81
82 mount: mount-zpool mount-boot mount-efi
83 mount-zpool:
84 # scan needed zpools
85 sudo zpool list $(zpool) || \
86 sudo zpool import -f $(zpool)
87 # load encryption key
88 sudo zfs get -H encryption $(zpool) | \
89 grep -q '^$(zpool)\s*encryption\s*off' || \
90 sudo zfs get -H keystatus $(zpool) | \
91 grep -q '^$(zpool)\s*keystatus\s*available' || \
92 sudo zfs load-key $(zpool)
93 # /
94 sudo mkdir -p /mnt/$(machine)
95 sudo mountpoint /mnt/$(machine) || \
96 sudo mount -v -t zfs $(zpool)/root /mnt/$(machine)
97 # /*
98 for p in \
99 home \
100 nix \
101 var \
102 ; do \
103 sudo mkdir -p /mnt/$(machine)/"$$p"; \
104 sudo mountpoint /mnt/$(machine)/"$$p" || \
105 sudo mount -v -t zfs $(zpool)/"$$p" /mnt/$(machine)/"$$p" ; \
106 done
107 #sudo chmod 1777 /mnt/$(machine)/var/tmp
108 mount-boot:
109 sudo mkdir -p /mnt/$(machine)/boot
110 sudo mountpoint /mnt/$(machine)/boot || \
111 sudo mount -v /dev/disk/by-partlabel/$(machine)_ssd_boot /mnt/$(machine)/boot
112 #sudo mount -v -t zfs bpool/boot /mnt/$(machine)/boot
113 mount-efi: | mount-boot
114 sudo mkdir -p /mnt/$(machine)/boot/efi
115 sudo mountpoint /mnt/$(machine)/boot/efi || \
116 sudo mount -v /dev/disk/by-partlabel/$(machine)_ssd_efi /mnt/$(machine)/boot/efi
117
118 bootstrap: mount
119 # Workaround https://dev.gnupg.org/T3908
120 chmod o+rw $$GPG_TTY $$XAUTHORITY
121
122 sudo --preserve-env \
123 $$(which nixos-install) \
124 --root /mnt/$(machine) \
125 --flake '.#$(machine)' \
126 --no-root-passwd \
127 --no-channel-copy \
128 --option allow-import-from-derivation true \
129 --show-trace
130
131 # End workaround https://dev.gnupg.org/T3908
132 chmod o-rw $$GPG_TTY $$XAUTHORITY
133
134 umount:
135 for p in \
136 boot/efi \
137 boot \
138 home \
139 home/documents \
140 nix \
141 var \
142 "" \
143 ; do \
144 ! sudo mountpoint /mnt/$(machine)/"$$p" || \
145 sudo umount -v /mnt/$(machine)/"$$p" ; \
146 done
147 ! sudo zpool list $(zpool) 2>/dev/null || \
148 zfs get -H encryption $(zpool) | \
149 grep -q '^$(zpool)\s*encryption\s*off' || \
150 zfs get -H keystatus $(zpool) | \
151 grep -q '^$(zpool)\s*keystatus\s*unavailable' || \
152 sudo zfs unload-key $(zpool)
153 #! sudo zpool list bpool 2>/dev/null || \
154 #sudo zpool export bpool
155 ! sudo zpool list $(zpool) 2>/dev/null || \
156 sudo zpool export $(zpool)
157
158 unlock:
159 pass machines/$(machine)/zfs/zpool | \
160 NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(LOSURDO_DEPLOYMENT)}" \
161 nixops ssh $(machine) -p 2222 'zfs load-key $(zpool) && pkill zfs'