]> Git — Sourcephile - sourcephile-nix.git/blob - servers/losurdo/Makefile
initrd: fix SSH host key location
[sourcephile-nix.git] / servers / losurdo / Makefile
1 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
2 #disk := /dev/disk/by-id/usb-Generic-_Multi-Card_20071114173400000-0:0
3 #disk := /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_Plus_250GB_S4EUNJ0N211426T
4 server := losurdo
5 disk_sd := $(shell sourcephile-nix-get nodes.$(server).config.boot.loader.grub.devices.0)
6 disk_nvme := /dev/disk/by-id/nvme-Samsung_SSD_970_EVO_Plus_250GB_S4EUNJ0N211426T
7 rpool := $(server)_nvme
8 cipher := aes-128-gcm
9 autotrim := on
10 reservation := 1G
11 #unicode_normalization := formD
12
13 wipe-sd:
14 sudo modprobe zfs
15 sudo zpool labelclear -f /dev/disk/by-partlabel/$(server)_nvme_rpool || true
16 sudo $$(which sgdisk) --zap-all $(disk_sd)
17
18 part: wipe-sd wipe-nvme
19 part-sd: wipe-sd
20 sudo $$(which sgdisk) -a1 -n0:34:2047 -t0:EF02 -c0:"$(server)_sd_bios" $(disk_sd)
21 sudo $$(which sgdisk) -n0:1M:+100M -t0:EF00 -c0:"$(server)_sd_efi" $(disk_sd)
22 sudo $$(which sgdisk) -n0:0:+256M -t0:8300 -c0:"$(server)_sd_boot" $(disk_sd)
23 sudo $$(which sgdisk) --randomize-guids $(disk_sd)
24 sudo $$(which sgdisk) --backup=$(server)_sd.sgdisk $(disk_sd)
25 part-nvme:
26 sudo $$(which sgdisk) -n0:0:+8G -t0:8200 -c0:"$(server)_nvme_swap" $(disk_nvme)
27 sudo $$(which sgdisk) -n0:0:0 -t0:BF01 -c0:"$(server)_nvme_rpool" $(disk_nvme)
28 sudo $$(which sgdisk) --randomize-guids $(disk_nvme)
29 sudo $$(which sgdisk) --backup=$(server)_nvme.sgdisk $(disk_nvme)
30
31 format: umount format-efi format-boot format-rpool
32 format-efi:
33 sudo blkid /dev/disk/by-partlabel/$(server)_sd_efi -t TYPE=vfat || \
34 sudo mkfs.vfat -F 16 -s 1 -n EFI /dev/disk/by-partlabel/$(server)_sd_efi
35 format-boot:
36 sudo mkdir -p /mnt/$(server)
37 sudo blkid -t TYPE=ext2 /dev/disk/by-partlabel/$(server)_sd_boot; test $$? != 2 || \
38 sudo mkfs.ext2 /dev/disk/by-partlabel/$(server)_sd_boot
39 format-rpool:
40 sudo zpool list $(rpool) 2>/dev/null || \
41 sudo zpool create -o ashift=12 \
42 $(if $(cipher),-O encryption=$(cipher) \
43 -O keyformat=passphrase \
44 -O keylocation=prompt) \
45 -O normalization=formD \
46 $(if $(unicode_normalization),-O normalization=$(unicode_normalization) \
47 -R /mnt/$(server) $(rpool) /dev/disk/by-partlabel/$(server)_nvme_root
48 sudo zpool set \
49 autotrim=$(autotrim) \
50 $(rpool)
51 sudo zfs set \
52 acltype=posixacl \
53 atime=off \
54 canmount=off \
55 compression=lz4 \
56 dnodesize=auto \
57 relatime=on \
58 xattr=sa \
59 mountpoint=/ \
60 $(rpool)
61 # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
62 sudo zfs list $(rpool)/reserved 2>/dev/null || \
63 sudo zfs create -o canmount=off -o mountpoint=none $(rpool)/reserved
64 sudo zfs set refreservation=$(reservation) $(rpool)/reserved
65 # /
66 # mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
67 sudo zfs list $(rpool)/root 2>/dev/null || \
68 sudo zfs create \
69 -o canmount=on \
70 -o mountpoint=legacy \
71 $(rpool)/root
72 # /boot
73 #sudo zfs list bpool/boot 2>/dev/null || \
74 #sudo zfs create \
75 # -o canmount=on \
76 # -o mountpoint=legacy \
77 # bpool/boot
78 # /*
79 for p in \
80 home \
81 nix \
82 var \
83 var/cache \
84 var/log \
85 var/tmp \
86 ; do \
87 sudo zfs list $(rpool)/"$$p" 2>/dev/null || \
88 sudo zfs create \
89 -o canmount=on \
90 -o mountpoint=legacy \
91 $(rpool)/"$$p" ; \
92 done
93 sudo zfs set \
94 com.sun:auto-snapshot=false \
95 $(rpool)/nix
96 sudo zfs set \
97 com.sun:auto-snapshot=false \
98 $(rpool)/var/cache
99 sudo zfs set \
100 com.sun:auto-snapshot=false \
101 sync=disabled \
102 $(rpool)/var/tmp
103
104 mount: mount-rpool mount-boot mount-efi
105 mount-rpool:
106 # scan needed zpools
107 sudo zpool list $(rpool) || \
108 sudo zpool import -f $(rpool)
109 # load encryption key
110 sudo zfs get -H encryption $(rpool) | \
111 grep -q '^$(rpool)\s*encryption\s*off' || \
112 sudo zfs get -H keystatus $(rpool) | \
113 grep -q '^$(rpool)\s*keystatus\s*available' || \
114 sudo zfs load-key $(rpool)
115 # /
116 sudo mkdir -p /mnt/$(server)
117 sudo mountpoint /mnt/$(server) || \
118 sudo mount -v -t zfs $(rpool)/root /mnt/$(server)
119 # /*
120 for p in \
121 home \
122 nix \
123 var \
124 var/cache \
125 var/log \
126 var/tmp \
127 ; do \
128 sudo mkdir -p /mnt/$(server)/"$$p"; \
129 sudo mountpoint /mnt/$(server)/"$$p" || \
130 sudo mount -v -t zfs $(rpool)/"$$p" /mnt/$(server)/"$$p" ; \
131 done
132 sudo chmod 1777 /mnt/$(server)/var/tmp
133 mount-boot:
134 sudo mkdir -p /mnt/$(server)/boot
135 sudo mountpoint /mnt/$(server)/boot || \
136 sudo mount -v /dev/disk/by-partlabel/$(server)_sd_boot /mnt/$(server)/boot
137 #sudo mount -v -t zfs bpool/boot /mnt/$(server)/boot
138 mount-efi: | mount-boot
139 sudo mkdir -p /mnt/$(server)/boot/efi
140 sudo mountpoint /mnt/$(server)/boot/efi || \
141 sudo mount -v /dev/disk/by-partlabel/$(server)_sd_efi /mnt/$(server)/boot/efi
142
143 bootstrap: mount
144 # Workaround https://dev.gnupg.org/T3908
145 chmod o+rw $$GPG_TTY $$XAUTHORITY
146
147 sudo --preserve-env \
148 NIXOS_CONFIG="$$PWD/install.nix" \
149 $$(which nixos-install) \
150 --root /mnt/$(server) \
151 --no-root-passwd \
152 --no-channel-copy \
153 --show-trace
154
155 # End workaround https://dev.gnupg.org/T3908
156 chmod o-rw $$GPG_TTY $$XAUTHORITY
157
158 sudo sourcephile-shred-tmp
159
160 umount:
161 for p in \
162 boot/efi \
163 boot \
164 home \
165 nix \
166 var/cache \
167 var/log \
168 var/tmp \
169 var \
170 "" \
171 ; do \
172 ! sudo mountpoint /mnt/$(server)/"$$p" || \
173 sudo umount -v /mnt/$(server)/"$$p" ; \
174 done
175 ! sudo zpool list $(rpool) 2>/dev/null || \
176 zfs get -H encryption $(rpool) | \
177 grep -q '^$(rpool)\s*encryption\s*off' || \
178 zfs get -H keystatus $(rpool) | \
179 grep -q '^$(rpool)\s*keystatus\s*unavailable' || \
180 sudo zfs unload-key $(rpool)
181 #! sudo zpool list bpool 2>/dev/null || \
182 #sudo zpool export bpool
183 ! sudo zpool list $(rpool) 2>/dev/null || \
184 sudo zpool export $(rpool)
185
186 unlock:
187 pass servers/$(server)/zfs/rpool | \
188 NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(LOSURDO_DEPLOYMENT)}" \
189 nixops ssh $(server) -p 2222 'zfs load-key $(rpool) && pkill zfs'