#cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST)))))) mermet_deployment := maintenance mermet_disk := /dev/disk/by-id/ata-Samsung_SSD_840_EVO_250GB_S1DBNSAF340110R #mermet_cipher := mermet_cipher := aes-128-gcm mermet_autotrim := mermet_reservation := 1G #mermet_channel := $$(nix-env -p /nix/var/nix/profiles/per-user/$$USER/channels -q nixpkgs --no-name --out-path) #mermet_unicode_normalization := formD echo: echo $(MAKEFILES) wipeout: umount #sudo zpool labelclear -f $(mermet_disk)-part3 || true sudo zpool labelclear -f $(mermet_disk)-part5 || true sudo $$(which sgdisk) --zap-all $(mermet_disk) partition: sudo modprobe zfs set -x; if test -e sfdisk; then \ sudo $$(which sfdisk) $(losurdo_disk) sfdisk.txt; \ fi format: # DOC: https://github.com/zfsonlinux/zfs/wiki/Debian-Buster-Root-on-ZFS sudo mkdir -p /mnt/mermet blkid -t TYPE=ext2 $(mermet_disk)-part3; test $$? != 2 || \ mkfs.ext2 $(mermet_disk)-part3 # bpool ## NOTE: enable only ZFS features supported by GRUB #sudo zpool list bpool 2>/dev/null || \ #sudo zpool create -o ashift=12 -d \ # -o feature@allocation_classes=enabled \ # -o feature@async_destroy=enabled \ # -o feature@bookmarks=enabled \ # -o feature@embedded_data=enabled \ # -o feature@empty_bpobj=enabled \ # -o feature@enabled_txg=enabled \ # -o feature@extensible_dataset=enabled \ # -o feature@filesystem_limits=enabled \ # -o feature@hole_birth=enabled \ # -o feature@large_blocks=enabled \ # -o feature@lz4_compress=enabled \ # -o feature@project_quota=enabled \ # -o feature@resilver_defer=enabled \ # -o feature@spacemap_histogram=enabled \ # -o feature@spacemap_v2=enabled \ # -o feature@userobj_accounting=enabled \ # -o feature@zpool_checkpoint=enabled \ # -o feature@multi_vdev_crash_dump=disabled \ # -o feature@large_dnode=disabled \ # -o feature@sha512=disabled \ # -o feature@skein=disabled \ # -o feature@edonr=disabled \ # -O normalization=formD \ # -R /mnt/mermet bpool $(mermet_disk)-part3 #sudo zfs set \ # acltype=posixacl \ # canmount=off \ # compression=lz4 \ # devices=off \ # relatime=on \ # xattr=sa \ # mountpoint=/ \ # bpool # swap # Note: configured with a volatile key in configuration.nix #blkid -t TYPE=crypto_LUKS $(mermet_disk)-part4; test $$? != 2 || \ #sudo cryptsetup luksFormat --cipher aes-xts-plain64 --key-size 256 --hash sha256 $(mermet_disk)-part4 #sudo cryptsetup luksOpen $(mermet_disk)-part4 swap #blkid -t TYPE=swap /dev/mapper/-swap; test $$? != 2 || \ #sudo mkswap --check --label swap #sudo cryptsetup luksClose $(mermet_disk)-part4 swap # rpool sudo zpool list rpool 2>/dev/null || \ sudo zpool create -o ashift=12 \ $(if $(mermet_cipher),-O encryption=$(mermet_cipher) \ -O keyformat=passphrase \ -O keylocation=prompt) \ $(if $(mermet_unicode_normalization),-O normalization=$(mermet_unicode_normalization) \ -R /mnt/mermet rpool $(mermet_disk)-part5 sudo zfs set \ acltype=posixacl \ atime=off \ $(if $(mermet_autotrim),autotrim=on) \ canmount=off \ compression=lz4 \ dnodesize=auto \ relatime=on \ xattr=sa \ mountpoint=/ \ rpool # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations sudo zfs list rpool/reserved 2>/dev/null || \ sudo zfs create -o canmount=off -o mountpoint=none rpool/reserved sudo zfs set refreservation=$(mermet_reservation) rpool/reserved # / # NOTE: mountpoint=legacy is required to let NixOS mount the ZFS filesystems. sudo zfs list rpool/root 2>/dev/null || \ sudo zfs create \ -o canmount=on \ -o mountpoint=legacy \ rpool/root # /boot #sudo zfs list bpool/boot 2>/dev/null || \ #sudo zfs create \ # -o canmount=on \ # -o mountpoint=legacy \ # bpool/boot # /boot/efi sudo blkid $(mermet_disk)-part2 -t TYPE=vfat || \ sudo mkfs.vfat -F 32 -s 1 -n EFI $(mermet_disk)-part2 # /* for p in \ home \ nix \ var \ var/cache \ var/log \ var/mail \ var/redis \ var/tmp \ var/www \ ; do \ sudo zfs list rpool/"$$p" 2>/dev/null || \ sudo zfs create \ -o canmount=on \ -o mountpoint=legacy \ rpool/"$$p" ; \ done sudo zfs set \ com.sun:auto-snapshot=false \ rpool/nix sudo zfs set \ com.sun:auto-snapshot=false \ rpool/var/cache sudo zfs set \ com.sun:auto-snapshot=false \ sync=disabled \ rpool/var/tmp mount: # scan needed zpools #sudo zpool list bpool || \ #sudo zpool import -f bpool sudo zpool list rpool || \ sudo zpool import -f rpool # load encryption key zfs get -H encryption rpool | \ grep -q '^rpool\s*encryption\s*off' || \ zfs get -H keystatus rpool | \ grep -q '^rpool\s*keystatus\s*available' || \ sudo zfs load-key rpool # / sudo mkdir -p /mnt/mermet sudo mountpoint /mnt/mermet || \ sudo mount -v -t zfs rpool/root /mnt/mermet # /boot sudo mkdir -p /mnt/mermet/boot sudo mountpoint /mnt/mermet/boot || \ sudo mount -v $(mermet_disk)-part3 /mnt/mermet/boot #sudo mount -v -t zfs bpool/boot /mnt/mermet/boot # /boot/efi sudo mkdir -p /mnt/mermet/boot/efi sudo mountpoint /mnt/mermet/boot/efi || \ sudo mount -v $(mermet_disk)-part2 /mnt/mermet/boot/efi # /* for p in \ home \ nix \ var \ var/cache \ var/log \ var/mail \ var/redis \ var/tmp \ var/www \ ; do \ sudo mkdir -p /mnt/mermet/"$$p"; \ sudo mountpoint /mnt/mermet/"$$p" || \ sudo mount -v -t zfs rpool/"$$p" /mnt/mermet/"$$p" ; \ done sudo chmod 1777 /mnt/mermet/var/tmp bootstrap: mount #test "$$(sudo grub-probe /mnt/mermet/boot)" = zfs # NOTE: nixos-install will install GRUB following configuration.nix # BIOS #sudo grub-install $(mermet_disk) # UEFI #sudo grub-install \ # --target=x86_64-efi \ # --efi-directory=/mnt/mermet/boot/efi \ # --bootloader-id=nixos \ # --recheck \ # --no-floppy pass machines/mermet/dropbear/host.key | \ sudo install -D -o root -g root -m 400 /dev/stdin \ /mnt/mermet/etc/dropbear/host.key && \ test -s /mnt/mermet/etc/dropbear/host.key #trap "test ! -e SHRED-ME || sudo find SHRED-ME -type f -exec shred -u {} + && sudo rm -rf SHRED-ME" EXIT ; sudo \ GNUPGHOME="$$GNUPGHOME" \ GPG_TTY="$$GPG_TTY" \ DBUS_SESSION_BUS_ADDRESS="$$DBUS_SESSION_BUS_ADDRESS" \ LANG="$$LANG" \ LC_CTYPE="$$LC_CTYPE" \ MERMET_DEPLOYMENT="$$MERMET_DEPLOYMENT" \ NIXOS_CONFIG="$$(readlink -e ../install.nix)" \ NIX_CONF_DIR="$$NIX_CONF_DIR" \ NIX_PATH="$$NIX_PATH" \ PASSWORD_STORE_DIR="$$PASSWORD_STORE_DIR" \ PATH="$$PATH" \ SSL_CERT_FILE="$$SSL_CERT_FILE" \ $$(which nixos-install) \ --root /mnt/mermet \ $(if $(mermet_channel),--channel "$(mermet_channel)") \ --option -Inixops=$$(nix-instantiate --eval -E '(import {}).nixops + ""') \ --no-root-passwd \ --show-trace umount: for p in \ boot/efi \ boot \ home \ nix \ var/cache \ var/log \ var/mail \ var/redis \ var/tmp \ var/www \ var \ "" \ ; do \ ! sudo mountpoint /mnt/mermet/"$$p" || \ sudo umount -v /mnt/mermet/"$$p" ; \ done ! sudo zpool list rpool 2>/dev/null || \ zfs get -H encryption rpool | \ grep -q '^rpool\s*encryption\s*off' || \ zfs get -H keystatus rpool | \ grep -q '^rpool\s*keystatus\s*unavailable' || \ sudo zfs unload-key rpool #! sudo zpool list bpool 2>/dev/null || \ #sudo zpool export bpool ! sudo zpool list rpool 2>/dev/null || \ sudo zpool export rpool unlock: pass machines/mermet/zfs/rpool | \ NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(MERMET_DEPLOYMENT)}" \ nixops ssh mermet -p 2222 'zfs load-key rpool && pkill zfs'