]> Git — Sourcephile - sourcephile-nix.git/blob - shell.nix
nix: improve bootstrap/mermet/ upto ssh root@
[sourcephile-nix.git] / shell.nix
1 let
2 nixpkgs = import .lib/nix/nixpkgs.nix;
3 pkgs = import nixpkgs {
4 config = {}; # Make the config pure, ignoring user's config.
5 overlays = import .lib/nixpkgs-sourcephile/build/overlays.nix;
6 };
7 sourcephile-nix-build-modules =
8 (import .lib/nixpkgs-sourcephile/build/modules.nix {
9 inherit pkgs;
10 inherit (pkgs) lib;
11 modules = [ ( import build/modules.nix ) ];
12 }).config;
13 /*
14 sourcephile-nix-build =
15 pkgs.stdenv.mkDerivation {
16 name = "sourcephile-nix-build";
17 preferLocalBuild = true;
18 allowSubstitutes = false;
19 inherit (pkgs) coreutils;
20 builder = pkgs.writeText "builder.sh" sourcephile-nix-build-modules.init.builder;
21 };
22 */
23 sourcephile-nix-build =
24 pkgs.buildEnv {
25 name = "sourcephile-nix-build";
26 pathsToLink = [ "/bin" ];
27 paths = with sourcephile-nix-build-modules; [
28 gnupg.init
29 #gnupg.gpg-fingerprint
30 #nix-plugins.nix-with-extra-builtins
31 ];
32 };
33 nixos-generate-config =
34 (pkgs.nixos {}).nixos-generate-config;
35 nixos-install =
36 (pkgs.nixos {}).nixos-install;
37 in
38 pkgs.stdenv.mkDerivation {
39 name = "sourcephile-nix";
40 src = null;
41 #preferLocalBuild = true;
42 #allowSubstitutes = false;
43 buildInputs = [
44 sourcephile-nix-build
45 nixpkgs
46 nixos-generate-config
47 nixos-install
48 #pkgs.binutils
49 pkgs.coreutils
50 pkgs.cryptsetup
51 pkgs.curl
52 pkgs.direnv
53 #pkgs.dnsutils
54 #pkgs.dropbear
55 pkgs.e2fsprogs
56 pkgs.git
57 pkgs.glibcLocales
58 pkgs.gnumake
59 pkgs.gnupg
60 pkgs.htop
61 #pkgs.inetutils
62 pkgs.less
63 pkgs.libfaketime
64 #pkgs.mailutils
65 pkgs.man
66 pkgs.mdadm
67 pkgs.gptfdisk
68 pkgs.ncdu
69 pkgs.ncurses
70 pkgs.nixops
71 #pkgs.openssl
72 pkgs.pass
73 pkgs.procps
74 #pkgs.rxvt_unicode.terminfo
75 #pkgs.sqlite
76 pkgs.sqlite
77 pkgs.sudo
78 pkgs.tig
79 pkgs.time
80 #pkgs.tmux
81 pkgs.tree
82 pkgs.utillinux
83 pkgs.vim
84 #pkgs.virtualbox
85 pkgs.which
86 pkgs.xdg_utils
87 pkgs.zfs
88 pkgs.fio
89 #pkgs.zfstools
90 ];
91 #enableParallelBuilding = true;
92 shellHook = ''
93 # nix
94 export NIX_PATH="nixpkgs=${nixpkgs}:nixpkgs-sourcephile=$PWD/.lib/nixpkgs-sourcephile"
95 #NIX_PATH+=":nixpkgs-overlays="$PWD"/install/overlays.nix"
96 #NIX_PATH+=""
97
98 # executables
99 PATH_NIX=$(dirname $(readlink -e ~/.nix-profile/bin/nix))
100 PATH_NIXOS=/run/wrappers/bin
101 PATH_FHS="$PWD"/.lib/nix/fhs-bin
102 PATH_FHS_VBOX="$PWD"/.lib/fhs-vbox-bin
103 export PATH="$PATH_NIXOS:$PATH_FHS_VBOX:$PATH_FHS:$PATH:$PATH_NIX"
104 ln -sfn ${sourcephile-nix-build}/bin "$PWD"/.bin
105
106 # NOTE: sudo needs to be own by root with the setuid bit,
107 # but this won't be the case for the sudo provided by Nix outside NixOS,
108 # hence the addition of $PATH_FHS in shellHook
109 # to provide the host system's sudo.
110 # WARNING: beware that sudo may reset the environment,
111 # and especially PATH, to some system's default.
112
113 # locales
114 export LANG=fr_FR.UTF-8
115 export LC_CTYPE=fr_FR.UTF-8
116
117 # gnupg
118 export GNUPGHOME="$PWD"/../sec/gnupg
119 install -dm700 "$GNUPGHOME"
120 export GPG_TTY=$(tty)
121 gpgconf --launch gpg-agent
122 export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)
123
124 # password-store
125 export PASSWORD_STORE_DIR="$PWD"/../sec/pass
126
127 # openssl
128 export SSL_CERT_FILE="${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
129
130 # git
131 gitdir="$PWD"/.git
132 test ! -f "$gitdir" || while IFS=" :" read -r hdr gitdir; do [ "$hdr" != gitdir ] || break; done <"$gitdir"
133 ln -fnsr \
134 "$PWD"/.lib/git/hooks/prepare-commit-msg--longuest-common-prefix \
135 "$gitdir"/hooks/prepare-commit-msg
136
137 # nixops
138 export NIXOPS_DEPLOYMENT="virtualbox"
139 export NIXOPS_STATE="$PWD"/.sec/nixops/state.nixops
140 # Extend the Nix interpreter
141 # to enable builtins.extraBuiltins,
142 # which provides an unsafe exec useful to get secrets
143 # from the local password-store.
144 NIXOPS_OPTS+=" --show-trace"
145 NIXOPS_OPTS+=" --option plugin-files ${pkgs.nix-plugins}/lib/nix/plugins/libnix-extra-builtins.so"
146 NIXOPS_OPTS+=" --option extra-builtins-file ${sourcephile-nix-build-modules.nix-plugins.extra-builtins}"
147 export NIXOPS_OPTS
148
149 # disnix
150 #export DISNIXOS_USE_NIXOPS=1
151 #export DISNIX_CLIENT_INTERFACE=disnix-nixops-client
152 #export DISNIX_PROFILE=default
153 #export DISNIX_TARGET_PROPERTY=hostname
154 #export DYSNOMIA_STATEDIR="$PWD"/.sec/dysnomia
155 '';
156 }