]> Git — Sourcephile - sourcephile-nix.git/blob - servers/losurdo/Makefile
losurdo: initial config
[sourcephile-nix.git] / servers / losurdo / Makefile
1 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
2 losurdo_disk := /dev/disk/by-id/FIXME
3 #losurdo_cipher :=
4 losurdo_cipher := aes-128-gcm
5 losurdo_autotrim :=
6 losurdo_reservation := 1G
7 #losurdo_channel := $$(nix-env -p /nix/var/nix/profiles/per-user/$$USER/channels -q nixpkgs --no-name --out-path)
8
9 wipeout: umount
10 sudo zpool labelclear -f $(losurdo_disk)-part3 || true
11 sudo zpool labelclear -f $(losurdo_disk)-part5 || true
12 sudo $$(which sgdisk) --zap-all $(losurdo_disk)
13
14 partition:
15 sudo modprobe zfs
16 if test -e sfdisk; then \
17 sudo $$(which sfdisk) $(losurdo_disk) <sfdisk.txt; \
18 else \
19 sudo $$(which sgdisk) --zap-all $(losurdo_disk); \
20 sudo $(which sgdisk) -a1 -n1:34:2047 -t1:EF02 $(losurdo_disk); \
21 sudo $(which sgdisk) -n2:1M:+512M -t2:EF00 $(losurdo_disk); \
22 sudo $(which sgdisk) -n3:0:+512M -t3:8300 $(losurdo_disk); \
23 sudo $(which sgdisk) -n4:0:+4G -t4:8200 $(losurdo_disk); \
24 sudo $(which sgdisk) -n5:0:0 -t5:BF01 $(losurdo_disk); \
25 sudo $$(which sfdisk) -d $(losurdo_disk) | \
26 sed -e 's:/dev/sd.:$(losurdo_disk):' >sfdisk.txt; \
27 fi
28 sudo $$(which sgdisk) --randomize-guids $(losurdo_disk)
29 sudo partprobe
30
31 format:
32 # DOC: https://github.com/zfsonlinux/zfs/wiki/Debian-Buster-Root-on-ZFS
33 sudo mkdir -p /mnt/losurdo
34 blkid -t TYPE=ext2 $(losurdo_disk)-part3; test $$? != 2 || \
35 mkfs.ext2 $(losurdo_disk)-part3
36 # swap
37 # Note: configured with a volatile key in losurdo.nix
38 #blkid -t TYPE=crypto_LUKS $(losurdo_disk)-part4; test $$? != 2 || \
39 #sudo cryptsetup luksFormat --cipher aes-xts-plain64 --key-size 256 --hash sha256 $(losurdo_disk)-part4
40 #sudo cryptsetup luksOpen $(losurdo_disk)-part4 swap
41 #blkid -t TYPE=swap /dev/mapper/-swap; test $$? != 2 || \
42 #sudo mkswap --check --label swap
43 #sudo cryptsetup luksClose $(losurdo_disk)-part4 swap
44 # rpool
45 sudo zpool list rpool 2>/dev/null || \
46 sudo zpool create -o ashift=12 \
47 $(if $(losurdo_cipher),-O encryption=$(losurdo_cipher) \
48 -O keyformat=passphrase \
49 -O keylocation=prompt) \
50 -O normalization=formD \
51 -R /mnt/losurdo rpool $(losurdo_disk)-part5
52 sudo zfs set \
53 acltype=posixacl \
54 atime=off \
55 $(if $(losurdo_autotrim),autotrim=on) \
56 canmount=off \
57 compression=lz4 \
58 dnodesize=auto \
59 relatime=on \
60 xattr=sa \
61 mountpoint=/ \
62 rpool
63 # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
64 sudo zfs list rpool/reserved 2>/dev/null || \
65 sudo zfs create -o canmount=off -o mountpoint=none rpool/reserved
66 sudo zfs set refreservation=$(losurdo_reservation) rpool/reserved
67 # /
68 # NOTE: mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
69 sudo zfs list rpool/root 2>/dev/null || \
70 sudo zfs create \
71 -o canmount=on \
72 -o mountpoint=legacy \
73 rpool/root
74 # /boot
75 #sudo zfs list bpool/boot 2>/dev/null || \
76 #sudo zfs create \
77 # -o canmount=on \
78 # -o mountpoint=legacy \
79 # bpool/boot
80 # /boot/efi
81 sudo blkid $(losurdo_disk)-part2 -t TYPE=vfat || \
82 sudo mkfs.vfat -F 32 -s 1 -n EFI $(losurdo_disk)-part2
83 # /*
84 for p in \
85 home \
86 nix \
87 var \
88 var/cache \
89 var/log \
90 var/mail \
91 var/redis \
92 var/tmp \
93 var/www \
94 ; do \
95 sudo zfs list rpool/"$$p" 2>/dev/null || \
96 sudo zfs create \
97 -o canmount=on \
98 -o mountpoint=legacy \
99 rpool/"$$p" ; \
100 done
101 sudo zfs set \
102 com.sun:auto-snapshot=false \
103 rpool/nix
104 sudo zfs set \
105 com.sun:auto-snapshot=false \
106 rpool/var/cache
107 sudo zfs set \
108 com.sun:auto-snapshot=false \
109 sync=disabled \
110 rpool/var/tmp
111
112 mount:
113 # scan needed zpools
114 #sudo zpool list bpool || \
115 #sudo zpool import -f bpool
116 sudo zpool list rpool || \
117 sudo zpool import -f rpool
118 # load encryption key
119 zfs get -H encryption rpool | \
120 grep -q '^rpool\s*encryption\s*off' || \
121 zfs get -H keystatus rpool | \
122 grep -q '^rpool\s*keystatus\s*available' || \
123 sudo zfs load-key rpool
124 # /
125 sudo mkdir -p /mnt/losurdo
126 sudo mountpoint /mnt/losurdo || \
127 sudo mount -v -t zfs rpool/root /mnt/losurdo
128 # /boot
129 sudo mkdir -p /mnt/losurdo/boot
130 sudo mountpoint /mnt/losurdo/boot || \
131 sudo mount -v $(losurdo_disk)-part3 /mnt/losurdo/boot
132 #sudo mount -v -t zfs bpool/boot /mnt/losurdo/boot
133 # /boot/efi
134 sudo mkdir -p /mnt/losurdo/boot/efi
135 sudo mountpoint /mnt/losurdo/boot/efi || \
136 sudo mount -v $(losurdo_disk)-part2 /mnt/losurdo/boot/efi
137 # /*
138 for p in \
139 home \
140 nix \
141 var \
142 var/cache \
143 var/log \
144 var/mail \
145 var/redis \
146 var/tmp \
147 var/www \
148 ; do \
149 sudo mkdir -p /mnt/losurdo/"$$p"; \
150 sudo mountpoint /mnt/losurdo/"$$p" || \
151 sudo mount -v -t zfs rpool/"$$p" /mnt/losurdo/"$$p" ; \
152 done
153 sudo chmod 1777 /mnt/losurdo/var/tmp
154
155 bootstrap: mount
156 #test "$$(sudo grub-probe /mnt/losurdo/boot)" = zfs
157 # NOTE: nixos-install will install GRUB following losurdo.nix
158 # BIOS
159 #sudo grub-install $(losurdo_disk)
160 # UEFI
161 #sudo grub-install \
162 # --target=x86_64-efi \
163 # --efi-directory=/mnt/losurdo/boot/efi \
164 # --bootloader-id=nixos \
165 # --recheck \
166 # --no-floppy
167
168 pass servers/losurdo/dropbear/host.key | \
169 sudo install -D -o root -g root -m 400 /dev/stdin \
170 /mnt/losurdo/etc/dropbear/host.key && \
171 test -s /mnt/losurdo/etc/dropbear/host.key
172
173 #trap "test ! -e SHRED-ME || sudo find SHRED-ME -type f -exec shred -u {} + && sudo rm -rf SHRED-ME" EXIT ;
174 sudo \
175 GNUPGHOME="$$GNUPGHOME" \
176 GPG_TTY="$$GPG_TTY" \
177 LANG="$$LANG" \
178 LC_CTYPE="$$LC_CTYPE" \
179 NIXOS_CONFIG="$$(readlink -e configuration.nix)" \
180 NIX_CONF_DIR="$$NIX_CONF_DIR" \
181 NIX_PATH="$$NIX_PATH" \
182 PASSWORD_STORE_DIR="$$PASSWORD_STORE_DIR" \
183 PATH="$$PATH" \
184 SSL_CERT_FILE="$$SSL_CERT_FILE" \
185 $$(which nixos-install) \
186 --root /mnt/losurdo \
187 $(if $(losurdo_channel),--channel "$(losurdo_channel)") \
188 --no-root-passwd \
189 --show-trace
190
191 umount:
192 for p in \
193 boot/efi \
194 boot \
195 home \
196 nix \
197 var/cache \
198 var/log \
199 var/mail \
200 var/redis \
201 var/tmp \
202 var/www \
203 var \
204 "" \
205 ; do \
206 ! sudo mountpoint /mnt/losurdo/"$$p" || \
207 sudo umount -v /mnt/losurdo/"$$p" ; \
208 done
209 ! sudo zpool list rpool 2>/dev/null || \
210 zfs get -H encryption rpool | \
211 grep -q '^rpool\s*encryption\s*off' || \
212 zfs get -H keystatus rpool | \
213 grep -q '^rpool\s*keystatus\s*unavailable' || \
214 sudo zfs unload-key rpool
215 #! sudo zpool list bpool 2>/dev/null || \
216 #sudo zpool export bpool
217 ! sudo zpool list rpool 2>/dev/null || \
218 sudo zpool export rpool
219
220 unlock:
221 pass servers/losurdo/zfs/rpool | \
222 NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(LOSURDO_DEPLOYMENT)}" \
223 nixops ssh losurdo -p 2222 'zfs load-key rpool && pkill zfs'