]> Git — Sourcephile - julm/julm-nix.git/blob - hosts/patate/Makefile
wireguard: setup wg-intra
[julm/julm-nix.git] / hosts / patate / Makefile
1 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
2 #disk := /dev/disk/by-id/usb-Generic-_Multi-Card_20071114173400000-0:0
3 #disk := /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_Plus_250GB_S4EUNJ0N211426T
4 hostName := patate
5 disk_ssd := /dev/disk/by-id/ata-CT250MX500SSD1_2004E2849DD1
6 zpool := $(hostName)
7 cipher := aes-128-gcm
8 autotrim := on
9 reservation := 1G
10
11 wipe:
12 sudo modprobe zfs
13 sudo zpool labelclear -f /dev/disk/by-partlabel/$(hostName)_ssd_zpool || true
14 sudo $$(which sgdisk) --zap-all $(disk_ssd)
15
16 part: wipe
17 # https://wiki.archlinux.org/index.php/BIOS_boot_partition
18 sudo $$(which sgdisk) -a1 -n0:34:2047 -t0:EF02 -c0:"$(hostName)_ssd_bios" $(disk_ssd)
19 sudo $$(which sgdisk) -n0:1M:+32M -t0:EF00 -c0:"$(hostName)_ssd_efi" $(disk_ssd)
20 sudo $$(which sgdisk) -n0:0:+256M -t0:8300 -c0:"$(hostName)_ssd_boot" $(disk_ssd)
21 sudo $$(which sgdisk) -n0:0:+4G -t0:8200 -c0:"$(hostName)_ssd_swap" $(disk_ssd)
22 sudo $$(which sgdisk) -n0:0:0 -t0:BF01 -c0:"$(hostName)_ssd_zpool" $(disk_ssd)
23 # https://wiki.archlinux.org/index.php/Partitioning#Tricking_old_BIOS_into_booting_from_GPT
24 printf '\200\0\0\0\0\0\0\0\0\0\0\0\001\0\0\0' | sudo dd of=$(disk_ssd) bs=1 seek=462
25 sudo $$(which sgdisk) --randomize-guids $(disk_ssd)
26 sudo $$(which sgdisk) --backup=$(hostName)_ssd.sgdisk $(disk_ssd)
27
28 format: umount format-efi format-boot format-zpool
29 format-efi:
30 sudo blkid /dev/disk/by-partlabel/$(hostName)_ssd_efi -t TYPE=vfat || \
31 sudo mkfs.vfat -F 16 -s 1 -n EFI /dev/disk/by-partlabel/$(hostName)_ssd_efi
32 format-boot:
33 sudo mkdir -p /mnt/$(hostName)
34 sudo blkid -t TYPE=ext2 /dev/disk/by-partlabel/$(hostName)_ssd_boot; test $$? != 2 || \
35 sudo mkfs.ext2 /dev/disk/by-partlabel/$(hostName)_ssd_boot
36 format-zpool:
37 sudo zpool list $(zpool) 2>/dev/null || \
38 sudo zpool create -o ashift=12 \
39 $(if $(cipher),-O encryption=$(cipher) \
40 -O keyformat=passphrase \
41 -O keylocation=prompt) \
42 -R /mnt/$(hostName) $(zpool) /dev/disk/by-partlabel/$(hostName)_ssd_zpool
43 sudo zpool set \
44 autotrim=$(autotrim) \
45 $(zpool)
46 sudo zfs set \
47 acltype=off \
48 atime=off \
49 canmount=off \
50 compression=lz4 \
51 dnodesize=auto \
52 relatime=on \
53 xattr=off \
54 mountpoint=/ \
55 $(zpool)
56 # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
57 sudo zfs list $(zpool)/reserved 2>/dev/null || \
58 sudo zfs create -o canmount=off -o mountpoint=none $(zpool)/reserved
59 sudo zfs set refreservation=$(reservation) $(zpool)/reserved
60 # /
61 # mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
62 sudo zfs list $(zpool)/root 2>/dev/null || \
63 sudo zfs create \
64 -o canmount=on \
65 -o mountpoint=legacy \
66 $(zpool)/root
67 # /*
68 for p in \
69 home \
70 home/Documents \
71 home/Images \
72 home/Videos \
73 nix \
74 var \
75 var/cache \
76 var/log \
77 var/tmp \
78 ; do \
79 sudo zfs list $(zpool)/"$$p" 2>/dev/null || \
80 sudo zfs create \
81 -o canmount=on \
82 -o mountpoint=legacy \
83 $(zpool)/"$$p" ; \
84 done
85 sudo zfs set sync=disabled $(zpool)/var/tmp
86 sudo zfs set copies=2 $(zpool)/home/Documents
87 sudo zfs set compression=off $(zpool)/home/Images
88 sudo zfs set compression=off $(zpool)/home/Videos
89
90 mount: mount-zpool mount-boot mount-efi
91 mount-zpool:
92 # scan needed zpools
93 sudo zpool list $(zpool) || \
94 sudo zpool import -f $(zpool)
95 # load encryption key
96 sudo zfs get -H encryption $(zpool) | \
97 grep -q '^$(zpool)\s*encryption\s*off' || \
98 sudo zfs get -H keystatus $(zpool) | \
99 grep -q '^$(zpool)\s*keystatus\s*available' || \
100 sudo zfs load-key $(zpool)
101 # /
102 sudo mkdir -p /mnt/$(hostName)
103 sudo mountpoint /mnt/$(hostName) || \
104 sudo mount -v -t zfs $(zpool)/root /mnt/$(hostName)
105 # /*
106 for p in \
107 home \
108 nix \
109 var \
110 var/cache \
111 var/log \
112 var/tmp \
113 ; do \
114 sudo mkdir -p /mnt/$(hostName)/"$$p"; \
115 sudo mountpoint /mnt/$(hostName)/"$$p" || \
116 sudo mount -v -t zfs $(zpool)/"$$p" /mnt/$(hostName)/"$$p" ; \
117 done
118 sudo chmod 1777 /mnt/$(hostName)/var/tmp
119 mount-boot:
120 sudo mkdir -p /mnt/$(hostName)/boot
121 sudo mountpoint /mnt/$(hostName)/boot || \
122 sudo mount -v /dev/disk/by-partlabel/$(hostName)_ssd_boot /mnt/$(hostName)/boot
123 #sudo mount -v -t zfs bpool/boot /mnt/$(hostName)/boot
124 mount-efi: | mount-boot
125 sudo mkdir -p /mnt/$(hostName)/boot/efi
126 sudo mountpoint /mnt/$(hostName)/boot/efi || \
127 sudo mount -v /dev/disk/by-partlabel/$(hostName)_ssd_efi /mnt/$(hostName)/boot/efi
128
129 bootstrap: mount
130 # Workaround https://dev.gnupg.org/T3908
131 chmod o+rw $$GPG_TTY $$XAUTHORITY
132
133 sudo --preserve-env \
134 $$(which nixos-install) \
135 --root /mnt/$(hostName) \
136 --flake '../..#$(hostName)' \
137 --no-root-passwd \
138 --no-channel-copy \
139 --show-trace
140
141 # End workaround https://dev.gnupg.org/T3908
142 chmod o-rw $$GPG_TTY $$XAUTHORITY
143
144 umount:
145 for p in \
146 boot/efi \
147 boot \
148 home \
149 nix \
150 var/cache \
151 var/log \
152 var/tmp \
153 var \
154 "" \
155 ; do \
156 ! sudo mountpoint /mnt/$(hostName)/"$$p" || \
157 sudo umount -v /mnt/$(hostName)/"$$p" ; \
158 done
159 ! sudo zpool list $(zpool) 2>/dev/null || \
160 zfs get -H encryption $(zpool) | \
161 grep -q '^$(zpool)\s*encryption\s*off' || \
162 zfs get -H keystatus $(zpool) | \
163 grep -q '^$(zpool)\s*keystatus\s*unavailable' || \
164 sudo zfs unload-key $(zpool)
165 #! sudo zpool list bpool 2>/dev/null || \
166 #sudo zpool export bpool
167 ! sudo zpool list $(zpool) 2>/dev/null || \
168 sudo zpool export $(zpool)