mermet_mnt := mermet mermet_rpool := rpool mermet_bpool := bpool mermet_disk := $(shell sed -ne 's/^device: \(.*\)/\1/p' bootstrap/$(mermet_mnt)/etc/sfdisk.txt) mermet_cipher := aes-128-gcm mermet-partition: sudo modprobe zfs sudo $$(which sfdisk) $(mermet_disk) /dev/null || \ # NOTE: enable only ZFS features supported by GRUB sudo zpool create -o ashift=12 -d \ -o feature@allocation_classes=enabled \ -o feature@async_destroy=enabled \ -o feature@bookmarks=enabled \ -o feature@embedded_data=enabled \ -o feature@empty_bpobj=enabled \ -o feature@enabled_txg=enabled \ -o feature@extensible_dataset=enabled \ -o feature@filesystem_limits=enabled \ -o feature@hole_birth=enabled \ -o feature@large_blocks=enabled \ -o feature@lz4_compress=enabled \ -o feature@project_quota=enabled \ -o feature@resilver_defer=enabled \ -o feature@spacemap_histogram=enabled \ -o feature@spacemap_v2=enabled \ -o feature@userobj_accounting=enabled \ -o feature@zpool_checkpoint=enabled \ -O normalization=formD \ -R /mnt/$(mermet_mnt) $(mermet_bpool) $(mermet_disk)-part3 sudo zfs set \ acltype=posixacl \ canmount=off \ compression=lz4 \ devices=off \ relatime=on \ xattr=sa \ mountpoint=/ \ $(mermet_bpool) # swap # FIXME: configure with a volatile key in configuration.nix #blkid -t TYPE=crypto_LUKS $(mermet_disk)-part4; test $$? != 2 || \ #sudo cryptsetup luksFormat --cipher aes-xts-plain64 --key-size 256 --hash sha256 $(mermet_disk)-part4 # rpool sudo zpool list $(mermet_rpool) 2>/dev/null || \ sudo zpool create -o ashift=12 \ $(if $(mermet_cipher),-O encryption=$(mermet_cipher) \ -O keyformat=passphrase \ -O keylocation=prompt) \ -O normalization=formD \ -R /mnt/$(mermet_mnt) $(mermet_rpool) $(mermet_disk)-part5 sudo zfs set \ acltype=posixacl \ atime=off \ $(if $(autotrim),autotrim=on) \ canmount=off \ compression=lz4 \ dnodesize=auto \ relatime=on \ xattr=sa \ mountpoint=/ \ $(mermet_rpool) # / # NOTE: mountpoint=legacy is required to let NixOS mount the ZFS filesystems. sudo zfs list $(mermet_rpool)/root 2>/dev/null || \ sudo zfs create \ -o canmount=on \ -o mountpoint=legacy \ $(mermet_rpool)/root #sudo zpool set bootfs="$(mermet_rpool)/boot" $(mermet_rpool) # /boot sudo zfs list $(mermet_bpool)/boot 2>/dev/null || \ sudo zfs create \ -o canmount=on \ -o mountpoint=legacy \ $(mermet_bpool)/boot # /boot/efi sudo blkid $(mermet_disk)-part2 -t TYPE=vfat || \ sudo mkfs.vfat -F 32 -s 1 -n EFI $(mermet_disk)-part2 # /* for p in \ home \ nix \ var \ var/cache \ var/log \ var/mail \ var/tmp \ var/www \ ; do \ sudo zfs list $(mermet_rpool)/"$$p" 2>/dev/null || \ sudo zfs create \ -o canmount=on \ -o mountpoint=legacy \ $(mermet_rpool)/"$$p" ; \ done sudo zfs set \ com.sun:auto-snapshot=false \ $(mermet_rpool)/var/cache sudo zfs set \ com.sun:auto-snapshot=false \ sync=disabled \ $(mermet_rpool)/var/tmp mermet-mount: # / sudo mkdir -p /mnt/$(mermet_mnt) sudo mountpoint /mnt/$(mermet_mnt) || \ sudo mount -v -t zfs $(mermet_rpool)/root /mnt/$(mermet_mnt) # /boot sudo mkdir -p /mnt/$(mermet_mnt)/boot sudo mountpoint /mnt/$(mermet_mnt)/boot || \ sudo mount -v -t zfs $(mermet_bpool)/boot /mnt/$(mermet_mnt)/boot # /boot/efi sudo mkdir -p /mnt/$(mermet_mnt)/boot/efi sudo mountpoint /mnt/$(mermet_mnt)/boot/efi || \ sudo mount -v $(mermet_disk)-part2 /mnt/$(mermet_mnt)/boot/efi # /* for p in \ home \ nix \ var \ var/cache \ var/log \ var/mail \ var/tmp \ var/www \ ; do \ sudo mkdir -p /mnt/$(mermet_mnt)/"$$p"; \ sudo mountpoint /mnt/$(mermet_mnt)/"$$p" || \ sudo mount -v -t zfs $(mermet_rpool)/"$$p" /mnt/$(mermet_mnt)/"$$p" ; \ done sudo chmod 1777 /mnt/$(mermet_mnt)/var/tmp mermet-bootstrap: mermet-mount sudo mkdir -p bootstrap/$(mermet_mnt)/etc/nixos sudo rm -rf "/mnt/$(mermet_mnt)/etc/nixos" sudo cp -r \ bootstrap/$(mermet_mnt)/etc/nixos \ /mnt/$(mermet_mnt)/etc/ test "$$(sudo grub-probe /mnt/$(mermet_mnt)/boot)" = zfs # NOTE: nixos-install will install GRUB following configuration.nix # BIOS #sudo grub-install $(mermet_disk) # UEFI #sudo grub-install \ # --target=x86_64-efi \ # --efi-directory=/mnt/$(mermet_mnt)/boot/efi \ # --bootloader-id=nixos \ # --recheck \ # --no-floppy sudo NIX_PATH="$$NIX_PATH" PATH="$$PATH" $$(which nixos-install) \ --root /mnt/$(mermet_mnt) \ --no-root-passwd mermet-umount: for p in \ boot/efi \ boot \ home \ nix \ var/cache \ var/log \ var/mail \ var/tmp \ var/www \ var \ "" \ ; do \ ! sudo mountpoint /mnt/$(mermet_mnt)/"$$p" || \ sudo umount -v /mnt/$(mermet_mnt)/"$$p" ; \ done