#cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
NIXOPS_DEPLOYMENT := maintenance
-mermet_disk := $(shell sed -ne 's/^device: \(.*\)/\1/p' machine/sfdisk.txt)
-mermet_cipher :=
-#mermet_cipher := aes-128-gcm
+mermet_disk := $(shell sed -ne 's/^device: \(.*\)/\1/p' sfdisk.txt)
+#mermet_cipher :=
+mermet_cipher := aes-128-gcm
mermet_autotrim :=
mermet_reservation := 40G
#mermet_channel := $$(nix-env -p /nix/var/nix/profiles/per-user/$$USER/channels -q nixpkgs --no-name --out-path)
echo:
echo $(MAKEFILES)
-mermet-wipeout: mermet-umount
+wipeout: umount
sudo zpool labelclear -f $(mermet_disk)-part3 || true
sudo zpool labelclear -f $(mermet_disk)-part5 || true
sudo $$(which sgdisk) --zap-all $(mermet_disk)
-mermet-partition:
+partition:
sudo modprobe zfs
- sudo $$(which sfdisk) $(mermet_disk) <machine/sfdisk.txt
+ sudo $$(which sfdisk) $(mermet_disk) <sfdisk.txt
sudo $$(which sgdisk) --randomize-guids $(mermet_disk)
sudo partprobe
-mermet-format:
+format:
# DOC: https://github.com/zfsonlinux/zfs/wiki/Debian-Buster-Root-on-ZFS
sudo mkdir -p /mnt/mermet
blkid -t TYPE=ext2 $(mermet_disk)-part3; test $$? != 2 || \
# Note: configured with a volatile key in mermet.nix
#blkid -t TYPE=crypto_LUKS $(mermet_disk)-part4; test $$? != 2 || \
#sudo cryptsetup luksFormat --cipher aes-xts-plain64 --key-size 256 --hash sha256 $(mermet_disk)-part4
- #sudo cryptsetup luksOpen $(mermet_disk)-part4 mermet-swap
- #blkid -t TYPE=swap /dev/mapper/mermet--swap; test $$? != 2 || \
+ #sudo cryptsetup luksOpen $(mermet_disk)-part4 swap
+ #blkid -t TYPE=swap /dev/mapper/-swap; test $$? != 2 || \
#sudo mkswap --check --label swap
- #sudo cryptsetup luksClose $(mermet_disk)-part4 mermet-swap
+ #sudo cryptsetup luksClose $(mermet_disk)-part4 swap
# rpool
sudo zpool list rpool 2>/dev/null || \
sudo zpool create -o ashift=12 \
for p in \
home \
nix \
- nix/var \
var \
var/cache \
var/log \
var/mail \
+ var/redis \
var/tmp \
var/www \
; do \
sudo zfs set \
com.sun:auto-snapshot=false \
rpool/nix
- sudo zfs set \
- sync=always \
- rpool/nix/var
sudo zfs set \
com.sun:auto-snapshot=false \
rpool/var/cache
sync=disabled \
rpool/var/tmp
-mermet-mount:
+mount:
# scan needed zpools
#sudo zpool list bpool || \
#sudo zpool import -f bpool
for p in \
home \
nix \
- nix/var \
var \
var/cache \
var/log \
var/mail \
+ var/redis \
var/tmp \
var/www \
; do \
done
sudo chmod 1777 /mnt/mermet/var/tmp
-mermet-bootstrap: mermet-mount
- sudo rm -rf /mnt/mermet/etc/nixos
+bootstrap: mount
#test "$$(sudo grub-probe /mnt/mermet/boot)" = zfs
# NOTE: nixos-install will install GRUB following mermet.nix
# BIOS
# --recheck \
# --no-floppy
- pass sourcephile/mermet/dropbear/host-ecdsa.key | \
+ pass servers/mermet/dropbear/host.key | \
sudo install -D -o root -g root -m 400 /dev/stdin \
- /mnt/mermet/etc/dropbear/host-ecdsa.key && \
- test -s /mnt/mermet/etc/dropbear/host-ecdsa.key
+ /mnt/mermet/etc/dropbear/host.key && \
+ test -s /mnt/mermet/etc/dropbear/host.key
#trap "test ! -e SHRED-ME || sudo find SHRED-ME -type f -exec shred -u {} + && sudo rm -rf SHRED-ME" EXIT ;
sudo \
--no-root-passwd \
--show-trace
-mermet-umount:
+umount:
for p in \
boot/efi \
boot \
home \
- nix/var \
nix \
var/cache \
var/log \
var/mail \
+ var/redis \
var/tmp \
var/www \
var \
#sudo zpool export bpool
! sudo zpool list rpool 2>/dev/null || \
sudo zpool export rpool
+
+unlock:
+ pass servers/mermet/zfs/rpool | \
+ NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(NIXOPS_DEPLOYMENT)}" \
+ nixops ssh mermet -p 2222 'zfs load-key rpool && pkill zfs'