]> Git — Sourcephile - sourcephile-nix.git/blob - servers/losurdo/Makefile
losurdo: running configuration
[sourcephile-nix.git] / servers / losurdo / Makefile
1 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
2 losurdo_disk := /dev/disk/by-id/usb-Generic-_Multi-Card_20071114173400000-0:0
3 #losurdo_disk := /dev/disk/by-id/usb-_USB_DISK_2.0_07009A834986F483-0:0
4 #losurdo_cipher :=
5 losurdo_cipher := aes-128-gcm
6 losurdo_autotrim :=
7 losurdo_reservation := 1G
8 #losurdo_channel := $$(nix-env -p /nix/var/nix/profiles/per-user/$$USER/channels -q nixpkgs --no-name --out-path)
9
10 wipeout: umount
11 sudo zpool labelclear -f $(losurdo_disk)-part3 || true
12 sudo zpool labelclear -f $(losurdo_disk)-part5 || true
13 sudo $$(which sgdisk) --zap-all $(losurdo_disk)
14
15 partition:
16 sudo modprobe zfs
17 set -x; if test -e sfdisk; then \
18 sudo $$(which sfdisk) $(losurdo_disk) <sfdisk.txt; \
19 else \
20 sudo $$(which sgdisk) --zap-all $(losurdo_disk) && \
21 sudo partprobe && \
22 sudo $$(which sgdisk) -a1 -n1:34:2047 -t1:EF02 $(losurdo_disk) && \
23 sudo $$(which sgdisk) -n2:1M:+512M -t2:EF00 $(losurdo_disk) && \
24 sudo $$(which sgdisk) -n3:0:+512M -t3:8300 $(losurdo_disk) && \
25 sudo $$(which sgdisk) -n4:0:+4G -t4:8200 $(losurdo_disk) && \
26 sudo $$(which sgdisk) -n5:0:0 -t5:BF01 $(losurdo_disk) && \
27 sudo $$(which sgdisk) --randomize-guids $(losurdo_disk) && \
28 sudo $$(which sfdisk) -d $(losurdo_disk) | \
29 sed -e 's&/dev/sd.&$(losurdo_disk)&' >sfdisk.txt; \
30 fi
31
32 format:
33 # DOC: https://github.com/zfsonlinux/zfs/wiki/Debian-Buster-Root-on-ZFS
34 sudo mkdir -p /mnt/losurdo
35 blkid -t TYPE=ext2 $(losurdo_disk)-part3; test $$? != 2 || \
36 mkfs.ext2 $(losurdo_disk)-part3
37 # swap
38 # Note: configured with a volatile key in losurdo.nix
39 #blkid -t TYPE=crypto_LUKS $(losurdo_disk)-part4; test $$? != 2 || \
40 #sudo cryptsetup luksFormat --cipher aes-xts-plain64 --key-size 256 --hash sha256 $(losurdo_disk)-part4
41 #sudo cryptsetup luksOpen $(losurdo_disk)-part4 swap
42 #blkid -t TYPE=swap /dev/mapper/-swap; test $$? != 2 || \
43 #sudo mkswap --check --label swap
44 #sudo cryptsetup luksClose $(losurdo_disk)-part4 swap
45 # rpool
46 sudo zpool list rpool 2>/dev/null || \
47 sudo zpool create -o ashift=12 \
48 $(if $(losurdo_cipher),-O encryption=$(losurdo_cipher) \
49 -O keyformat=passphrase \
50 -O keylocation=prompt) \
51 -O normalization=formD \
52 -R /mnt/losurdo rpool $(losurdo_disk)-part5
53 sudo zfs set \
54 acltype=posixacl \
55 atime=off \
56 $(if $(losurdo_autotrim),autotrim=on) \
57 canmount=off \
58 compression=lz4 \
59 dnodesize=auto \
60 relatime=on \
61 xattr=sa \
62 mountpoint=/ \
63 rpool
64 # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
65 sudo zfs list rpool/reserved 2>/dev/null || \
66 sudo zfs create -o canmount=off -o mountpoint=none rpool/reserved
67 sudo zfs set refreservation=$(losurdo_reservation) rpool/reserved
68 # /
69 # NOTE: mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
70 sudo zfs list rpool/root 2>/dev/null || \
71 sudo zfs create \
72 -o canmount=on \
73 -o mountpoint=legacy \
74 rpool/root
75 # /boot
76 #sudo zfs list bpool/boot 2>/dev/null || \
77 #sudo zfs create \
78 # -o canmount=on \
79 # -o mountpoint=legacy \
80 # bpool/boot
81 # /boot/efi
82 sudo blkid $(losurdo_disk)-part2 -t TYPE=vfat || \
83 sudo mkfs.vfat -F 32 -s 1 -n EFI $(losurdo_disk)-part2
84 # /*
85 for p in \
86 home \
87 nix \
88 var \
89 var/cache \
90 var/log \
91 var/tmp \
92 ; do \
93 sudo zfs list rpool/"$$p" 2>/dev/null || \
94 sudo zfs create \
95 -o canmount=on \
96 -o mountpoint=legacy \
97 rpool/"$$p" ; \
98 done
99 sudo zfs set \
100 com.sun:auto-snapshot=false \
101 rpool/nix
102 sudo zfs set \
103 com.sun:auto-snapshot=false \
104 rpool/var/cache
105 sudo zfs set \
106 com.sun:auto-snapshot=false \
107 sync=disabled \
108 rpool/var/tmp
109
110 mount:
111 # scan needed zpools
112 #sudo zpool list bpool || \
113 #sudo zpool import -f bpool
114 sudo zpool list rpool || \
115 sudo zpool import -f rpool
116 # load encryption key
117 sudo zfs get -H encryption rpool | \
118 grep -q '^rpool\s*encryption\s*off' || \
119 sudo zfs get -H keystatus rpool | \
120 grep -q '^rpool\s*keystatus\s*available' || \
121 sudo zfs load-key rpool
122 # /
123 sudo mkdir -p /mnt/losurdo
124 sudo mountpoint /mnt/losurdo || \
125 sudo mount -v -t zfs rpool/root /mnt/losurdo
126 # /boot
127 sudo mkdir -p /mnt/losurdo/boot
128 sudo mountpoint /mnt/losurdo/boot || \
129 sudo mount -v $(losurdo_disk)-part3 /mnt/losurdo/boot
130 #sudo mount -v -t zfs bpool/boot /mnt/losurdo/boot
131 # /boot/efi
132 sudo mkdir -p /mnt/losurdo/boot/efi
133 sudo mountpoint /mnt/losurdo/boot/efi || \
134 sudo mount -v $(losurdo_disk)-part2 /mnt/losurdo/boot/efi
135 # /*
136 for p in \
137 home \
138 nix \
139 var \
140 var/cache \
141 var/log \
142 var/tmp \
143 ; do \
144 sudo mkdir -p /mnt/losurdo/"$$p"; \
145 sudo mountpoint /mnt/losurdo/"$$p" || \
146 sudo mount -v -t zfs rpool/"$$p" /mnt/losurdo/"$$p" ; \
147 done
148 sudo chmod 1777 /mnt/losurdo/var/tmp
149
150 bootstrap: mount
151 #test "$$(sudo grub-probe /mnt/losurdo/boot)" = zfs
152 # NOTE: nixos-install will install GRUB following losurdo.nix
153 # BIOS
154 #sudo grub-install $(losurdo_disk)
155 # UEFI
156 #sudo grub-install \
157 # --target=x86_64-efi \
158 # --efi-directory=/mnt/losurdo/boot/efi \
159 # --bootloader-id=nixos \
160 # --recheck \
161 # --no-floppy
162
163 # Run pass as root to start gpg-agent as root not as $USER
164 # otherwise the yubikey has to be unplugged/replugged…
165 sudo \
166 GNUPGHOME="$$GNUPGHOME" \
167 GPG_TTY="$$GPG_TTY" \
168 PASSWORD_STORE_DIR="$$PASSWORD_STORE_DIR" \
169 PINENTRY_USER_DATA="$$PINENTRY_USER_DATA" \
170 XAUTHORITY="$$XAUTHORITY" \
171 pass servers/losurdo/dropbear/ecdsa.key | \
172 sudo install -D -o root -g root -m 400 /dev/stdin \
173 /mnt/losurdo/etc/dropbear/ecdsa.key && \
174 test -s /mnt/losurdo/etc/dropbear/ecdsa.key
175
176 #trap "test ! -e SHRED-ME || sudo find SHRED-ME -type f -exec shred -u {} + && sudo rm -rf SHRED-ME" EXIT ;
177 sudo \
178 GNUPGHOME="$$GNUPGHOME" \
179 GPG_TTY="$$GPG_TTY" \
180 LANG="$$LANG" \
181 LC_CTYPE="$$LC_CTYPE" \
182 LOSURDO_DEPLOYMENT="$$LOSURDO_DEPLOYMENT" \
183 NIXOS_CONFIG="$$(readlink -e configuration.nix)" \
184 NIX_CONF_DIR="$$NIX_CONF_DIR" \
185 NIX_PATH="$$NIX_PATH" \
186 PASSWORD_STORE_DIR="$$PASSWORD_STORE_DIR" \
187 PATH="$$PATH" \
188 PINENTRY_USER_DATA="$$PINENTRY_USER_DATA" \
189 SSL_CERT_FILE="$$SSL_CERT_FILE" \
190 XAUTHORITY="$$XAUTHORITY" \
191 $$(which nixos-install) \
192 --root /mnt/losurdo \
193 $(if $(losurdo_channel),--channel "$(losurdo_channel)") \
194 --no-root-passwd \
195 --show-trace
196
197 umount:
198 for p in \
199 boot/efi \
200 boot \
201 home \
202 nix \
203 var/cache \
204 var/log \
205 var/tmp \
206 var \
207 "" \
208 ; do \
209 ! sudo mountpoint /mnt/losurdo/"$$p" || \
210 sudo umount -v /mnt/losurdo/"$$p" ; \
211 done
212 ! sudo zpool list rpool 2>/dev/null || \
213 zfs get -H encryption rpool | \
214 grep -q '^rpool\s*encryption\s*off' || \
215 zfs get -H keystatus rpool | \
216 grep -q '^rpool\s*keystatus\s*unavailable' || \
217 sudo zfs unload-key rpool
218 #! sudo zpool list bpool 2>/dev/null || \
219 #sudo zpool export bpool
220 ! sudo zpool list rpool 2>/dev/null || \
221 sudo zpool export rpool
222
223 unlock:
224 pass servers/losurdo/zfs/rpool | \
225 NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(LOSURDO_DEPLOYMENT)}" \
226 nixops ssh losurdo -p 2222 'zfs load-key rpool && pkill zfs'