public-inbox: rename inboxes
[sourcephile-nix.git] / servers / mermet / Makefile
index d59d6964394af7ecd04706d844836cc1ed00ff09..c2cc2d377b79a97ddfd32846fa7b3f286d44b54b 100644 (file)
@@ -1,25 +1,37 @@
 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
-NIXOPS_DEPLOYMENT  := maintenance
-mermet_disk        := $(shell sed -ne 's/^device: \(.*\)/\1/p' machine/sfdisk.txt)
+mermet_deployment  := maintenance
+mermet_disk        := /dev/disk/by-id/ata-Samsung_SSD_840_EVO_250GB_S1DBNSAF340110R
 #mermet_cipher      :=
 mermet_cipher      := aes-128-gcm
 mermet_autotrim    :=
-mermet_reservation := 40G
+mermet_reservation := 1G
 #mermet_channel     := $$(nix-env -p /nix/var/nix/profiles/per-user/$$USER/channels -q nixpkgs --no-name --out-path)
+#mermet_unicode_normalization := formD
 
 echo:
        echo $(MAKEFILES)
 
 wipeout: umount
-       sudo zpool labelclear -f $(mermet_disk)-part3 || true
+       #sudo zpool labelclear -f $(mermet_disk)-part3 || true
        sudo zpool labelclear -f $(mermet_disk)-part5 || true
        sudo $$(which sgdisk) --zap-all $(mermet_disk)
 
 partition:
        sudo modprobe zfs
-       sudo $$(which sfdisk) $(mermet_disk) <machine/sfdisk.txt
-       sudo $$(which sgdisk) --randomize-guids $(mermet_disk)
-       sudo partprobe
+       set -x; if test -e sfdisk; then \
+               sudo $$(which sfdisk) $(losurdo_disk) <sfdisk.txt; \
+       else \
+               sudo $$(which sgdisk) --zap-all $(losurdo_disk) && \
+               sudo partprobe && \
+               sudo $$(which sgdisk) -a1 -n1:34:2047  -t1:EF02 $(losurdo_disk) && \
+               sudo $$(which sgdisk)     -n2:1M:+512M -t2:EF00 $(losurdo_disk) && \
+               sudo $$(which sgdisk)     -n3:0:+512M  -t3:8300 $(losurdo_disk) && \
+               sudo $$(which sgdisk)     -n4:0:+4G    -t4:8200 $(losurdo_disk) && \
+               sudo $$(which sgdisk)     -n5:0:0      -t5:BF01 $(losurdo_disk) && \
+               sudo $$(which sgdisk) --randomize-guids $(losurdo_disk) && \
+               sudo $$(which sfdisk) -d $(losurdo_disk) | \
+               sed -e 's&/dev/sd.&$(losurdo_disk)&' >sfdisk.txt; \
+       fi
 
 format:
        # DOC: https://github.com/zfsonlinux/zfs/wiki/Debian-Buster-Root-on-ZFS
@@ -65,7 +77,7 @@ format:
        # bpool
        
        # swap
-       # Note: configured with a volatile key in mermet.nix
+       # Note: configured with a volatile key in configuration.nix
        #blkid -t TYPE=crypto_LUKS $(mermet_disk)-part4; test $$? != 2 || \
        #sudo cryptsetup luksFormat --cipher aes-xts-plain64 --key-size 256 --hash sha256 $(mermet_disk)-part4
        #sudo cryptsetup luksOpen $(mermet_disk)-part4 swap
@@ -78,7 +90,7 @@ format:
         $(if $(mermet_cipher),-O encryption=$(mermet_cipher) \
         -O keyformat=passphrase \
         -O keylocation=prompt) \
-        -O normalization=formD \
+        $(if $(mermet_unicode_normalization),-O normalization=$(mermet_unicode_normalization) \
         -R /mnt/mermet rpool $(mermet_disk)-part5
        sudo zfs set \
         acltype=posixacl \
@@ -88,10 +100,13 @@ format:
         compression=lz4 \
         dnodesize=auto \
         relatime=on \
-        $(if $(mermet_reservation),reservation=$(mermet_reservation)) \
         xattr=sa \
         mountpoint=/ \
         rpool
+       # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
+       sudo zfs list rpool/reserved 2>/dev/null || \
+       sudo zfs create -o canmount=off -o mountpoint=none rpool/reserved
+       sudo zfs set refreservation=$(mermet_reservation) rpool/reserved
        # /
        # NOTE: mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
        sudo zfs list rpool/root 2>/dev/null || \
@@ -112,11 +127,11 @@ format:
        for p in \
         home \
         nix \
-        nix/var \
         var \
         var/cache \
         var/log \
         var/mail \
+        var/redis \
         var/tmp \
         var/www \
         ; do \
@@ -129,9 +144,6 @@ format:
        sudo zfs set \
         com.sun:auto-snapshot=false \
         rpool/nix
-       sudo zfs set \
-        sync=always \
-        rpool/nix/var
        sudo zfs set \
         com.sun:auto-snapshot=false \
         rpool/var/cache
@@ -169,11 +181,11 @@ mount:
        for p in \
         home \
         nix \
-        nix/var \
         var \
         var/cache \
         var/log \
         var/mail \
+        var/redis \
         var/tmp \
         var/www \
         ; do \
@@ -185,7 +197,7 @@ mount:
 
 bootstrap: mount
        #test "$$(sudo grub-probe /mnt/mermet/boot)" = zfs
-       # NOTE: nixos-install will install GRUB following mermet.nix
+       # NOTE: nixos-install will install GRUB following configuration.nix
        # BIOS
        #sudo grub-install $(mermet_disk)
        # UEFI
@@ -205,10 +217,11 @@ bootstrap: mount
        sudo \
         GNUPGHOME="$$GNUPGHOME" \
         GPG_TTY="$$GPG_TTY" \
+        DBUS_SESSION_BUS_ADDRESS="$$DBUS_SESSION_BUS_ADDRESS" \
         LANG="$$LANG" \
         LC_CTYPE="$$LC_CTYPE" \
-        NIXOPS_DEPLOYMENT="$(NIXOPS_DEPLOYMENT)" \
-        NIXOS_CONFIG="$$(readlink -e ../mermet.nix)" \
+        MERMET_DEPLOYMENT="$$MERMET_DEPLOYMENT" \
+        NIXOS_CONFIG="$$(readlink -e ../install.nix)" \
         NIX_CONF_DIR="$$NIX_CONF_DIR" \
         NIX_PATH="$$NIX_PATH" \
         PASSWORD_STORE_DIR="$$PASSWORD_STORE_DIR" \
@@ -217,6 +230,7 @@ bootstrap: mount
         $$(which nixos-install) \
         --root /mnt/mermet \
         $(if $(mermet_channel),--channel "$(mermet_channel)") \
+        --option -Inixops=$$(nix-instantiate --eval -E '(import <nixpkgs> {}).nixops + ""') \
         --no-root-passwd \
         --show-trace
 
@@ -225,11 +239,11 @@ umount:
         boot/efi \
         boot \
         home \
-        nix/var \
         nix \
         var/cache \
         var/log \
         var/mail \
+        var/redis \
         var/tmp \
         var/www \
         var \
@@ -251,4 +265,5 @@ umount:
 
 unlock:
        pass servers/mermet/zfs/rpool | \
+       NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(MERMET_DEPLOYMENT)}" \
        nixops ssh mermet -p 2222 'zfs load-key rpool && pkill zfs'