1 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
 
   2 losurdo_disk        := /dev/disk/by-id/usb-Generic-_Multi-Card_20071114173400000-0:0
 
   3 #losurdo_disk        := /dev/disk/by-id/usb-_USB_DISK_2.0_07009A834986F483-0:0
 
   5 losurdo_cipher      := aes-128-gcm
 
   7 losurdo_reservation := 1G
 
   8 #losurdo_channel     := $$(nix-env -p /nix/var/nix/profiles/per-user/$$USER/channels -q nixpkgs --no-name --out-path)
 
  11         sudo zpool labelclear -f $(losurdo_disk)-part3 || true
 
  12         sudo zpool labelclear -f $(losurdo_disk)-part5 || true
 
  13         sudo $$(which sgdisk) --zap-all $(losurdo_disk)
 
  17         set -x; if test -e sfdisk; then \
 
  18                 sudo $$(which sfdisk) $(losurdo_disk) <sfdisk.txt; \
 
  20                 sudo $$(which sgdisk) --zap-all $(losurdo_disk) && \
 
  22                 sudo $$(which sgdisk) -a1 -n1:34:2047  -t1:EF02 $(losurdo_disk) && \
 
  23                 sudo $$(which sgdisk)     -n2:1M:+512M -t2:EF00 $(losurdo_disk) && \
 
  24                 sudo $$(which sgdisk)     -n3:0:+512M  -t3:8300 $(losurdo_disk) && \
 
  25                 sudo $$(which sgdisk)     -n4:0:+4G    -t4:8200 $(losurdo_disk) && \
 
  26                 sudo $$(which sgdisk)     -n5:0:0      -t5:BF01 $(losurdo_disk) && \
 
  27                 sudo $$(which sgdisk) --randomize-guids $(losurdo_disk) && \
 
  28                 sudo $$(which sfdisk) -d $(losurdo_disk) | \
 
  29                 sed -e 's&/dev/sd.&$(losurdo_disk)&' >sfdisk.txt; \
 
  33         # DOC: https://github.com/zfsonlinux/zfs/wiki/Debian-Buster-Root-on-ZFS
 
  34         sudo mkdir -p /mnt/losurdo
 
  35         blkid -t TYPE=ext2 $(losurdo_disk)-part3; test $$? != 2 || \
 
  36         mkfs.ext2 $(losurdo_disk)-part3
 
  38         # Note: configured with a volatile key in losurdo.nix
 
  39         #blkid -t TYPE=crypto_LUKS $(losurdo_disk)-part4; test $$? != 2 || \
 
  40         #sudo cryptsetup luksFormat --cipher aes-xts-plain64 --key-size 256 --hash sha256 $(losurdo_disk)-part4
 
  41         #sudo cryptsetup luksOpen $(losurdo_disk)-part4 swap
 
  42         #blkid -t TYPE=swap /dev/mapper/-swap; test $$? != 2 || \
 
  43         #sudo mkswap --check --label swap
 
  44         #sudo cryptsetup luksClose $(losurdo_disk)-part4 swap
 
  46         sudo zpool list rpool 2>/dev/null || \
 
  47         sudo zpool create -o ashift=12 \
 
  48          $(if $(losurdo_cipher),-O encryption=$(losurdo_cipher) \
 
  49          -O keyformat=passphrase \
 
  50          -O keylocation=prompt) \
 
  51          -O normalization=formD \
 
  52          -R /mnt/losurdo rpool $(losurdo_disk)-part5
 
  56          $(if $(losurdo_autotrim),autotrim=on) \
 
  64         # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
 
  65         sudo zfs list rpool/reserved 2>/dev/null || \
 
  66         sudo zfs create -o canmount=off -o mountpoint=none rpool/reserved
 
  67         sudo zfs set refreservation=$(losurdo_reservation) rpool/reserved
 
  69         # NOTE: mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
 
  70         sudo zfs list rpool/root 2>/dev/null || \
 
  73          -o mountpoint=legacy \
 
  76         #sudo zfs list bpool/boot 2>/dev/null || \
 
  79         # -o mountpoint=legacy \
 
  82         sudo blkid $(losurdo_disk)-part2 -t TYPE=vfat || \
 
  83         sudo mkfs.vfat -F 32 -s 1 -n EFI $(losurdo_disk)-part2
 
  93                 sudo zfs list rpool/"$$p" 2>/dev/null || \
 
  96                  -o mountpoint=legacy \
 
 100          com.sun:auto-snapshot=false \
 
 103          com.sun:auto-snapshot=false \
 
 106          com.sun:auto-snapshot=false \
 
 112         #sudo zpool list bpool || \
 
 113         #sudo zpool import -f bpool
 
 114         sudo zpool list rpool || \
 
 115         sudo zpool import -f rpool
 
 116         # load encryption key
 
 117         sudo zfs get -H encryption rpool | \
 
 118         grep -q '^rpool\s*encryption\s*off' || \
 
 119         sudo zfs get -H keystatus rpool | \
 
 120         grep -q '^rpool\s*keystatus\s*available' || \
 
 121         sudo zfs load-key rpool
 
 123         sudo mkdir -p /mnt/losurdo
 
 124         sudo mountpoint /mnt/losurdo || \
 
 125         sudo mount -v -t zfs rpool/root /mnt/losurdo
 
 127         sudo mkdir -p /mnt/losurdo/boot
 
 128         sudo mountpoint /mnt/losurdo/boot || \
 
 129         sudo mount -v $(losurdo_disk)-part3 /mnt/losurdo/boot
 
 130         #sudo mount -v -t zfs bpool/boot /mnt/losurdo/boot
 
 132         sudo mkdir -p /mnt/losurdo/boot/efi
 
 133         sudo mountpoint /mnt/losurdo/boot/efi || \
 
 134         sudo mount -v $(losurdo_disk)-part2 /mnt/losurdo/boot/efi
 
 144                 sudo mkdir -p /mnt/losurdo/"$$p"; \
 
 145                 sudo mountpoint /mnt/losurdo/"$$p" || \
 
 146                 sudo mount -v -t zfs rpool/"$$p" /mnt/losurdo/"$$p" ; \
 
 148         sudo chmod 1777 /mnt/losurdo/var/tmp
 
 151         #test "$$(sudo grub-probe /mnt/losurdo/boot)" = zfs
 
 152         # NOTE: nixos-install will install GRUB following losurdo.nix
 
 154         #sudo grub-install $(losurdo_disk)
 
 157         # --target=x86_64-efi \
 
 158         # --efi-directory=/mnt/losurdo/boot/efi \
 
 159         # --bootloader-id=nixos \
 
 163         # Run pass as root to start gpg-agent as root not as $USER
 
 164         # otherwise the yubikey has to be unplugged/replugged…
 
 166          GNUPGHOME="$$GNUPGHOME" \
 
 167          GPG_TTY="$$GPG_TTY" \
 
 168          PASSWORD_STORE_DIR="$$PASSWORD_STORE_DIR" \
 
 169          PINENTRY_USER_DATA="$$PINENTRY_USER_DATA" \
 
 170          XAUTHORITY="$$XAUTHORITY" \
 
 171          pass servers/losurdo/dropbear/ecdsa.key | \
 
 172         sudo install -D -o root -g root -m 400 /dev/stdin \
 
 173          /mnt/losurdo/etc/dropbear/ecdsa.key && \
 
 174         test -s /mnt/losurdo/etc/dropbear/ecdsa.key
 
 176         #trap "test ! -e SHRED-ME || sudo find SHRED-ME -type f -exec shred -u {} + && sudo rm -rf SHRED-ME" EXIT ;
 
 178          GNUPGHOME="$$GNUPGHOME" \
 
 179          GPG_TTY="$$GPG_TTY" \
 
 181          LC_CTYPE="$$LC_CTYPE" \
 
 182          LOSURDO_DEPLOYMENT="$$LOSURDO_DEPLOYMENT" \
 
 183          NIXOS_CONFIG="$$(readlink -e configuration.nix)" \
 
 184          NIX_CONF_DIR="$$NIX_CONF_DIR" \
 
 185          NIX_PATH="$$NIX_PATH" \
 
 186          PASSWORD_STORE_DIR="$$PASSWORD_STORE_DIR" \
 
 188          PINENTRY_USER_DATA="$$PINENTRY_USER_DATA" \
 
 189          SSL_CERT_FILE="$$SSL_CERT_FILE" \
 
 190          XAUTHORITY="$$XAUTHORITY" \
 
 191          $$(which nixos-install) \
 
 192          --root /mnt/losurdo \
 
 193          $(if $(losurdo_channel),--channel "$(losurdo_channel)") \
 
 209                 ! sudo mountpoint /mnt/losurdo/"$$p" || \
 
 210                 sudo umount -v /mnt/losurdo/"$$p" ; \
 
 212         ! sudo zpool list rpool 2>/dev/null || \
 
 213         zfs get -H encryption rpool | \
 
 214         grep -q '^rpool\s*encryption\s*off' || \
 
 215         zfs get -H keystatus rpool | \
 
 216         grep -q '^rpool\s*keystatus\s*unavailable' || \
 
 217         sudo zfs unload-key rpool
 
 218         #! sudo zpool list bpool 2>/dev/null || \
 
 219         #sudo zpool export bpool
 
 220         ! sudo zpool list rpool 2>/dev/null || \
 
 221         sudo zpool export rpool
 
 224         pass servers/losurdo/zfs/rpool | \
 
 225         NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(LOSURDO_DEPLOYMENT)}" \
 
 226         nixops ssh losurdo -p 2222 'zfs load-key rpool && pkill zfs'