losurdo: boot on SD and root on NVMe
[sourcephile-nix.git] / servers / mermet / Makefile
index 98c522518f368c8ea64be46e16bd024f980184bb..49c03bea71e2424517208ceeaeaec7f0dcfa0c96 100644 (file)
@@ -1,27 +1,38 @@
 #cwd := $(notdir $(patsubst %/,%,$(dir $(abspath $(lastword $(MAKEFILE_LIST))))))
-NIXOPS_DEPLOYMENT  := maintenance
-mermet_disk        := $(shell sed -ne 's/^device: \(.*\)/\1/p' machine/sfdisk.txt)
-mermet_cipher      :=
-#mermet_cipher      := aes-128-gcm
+mermet_deployment  := maintenance
+mermet_disk        := /dev/disk/by-id/ata-Samsung_SSD_840_EVO_250GB_S1DBNSAF340110R
+#mermet_cipher      :=
+mermet_cipher      := aes-128-gcm
 mermet_autotrim    :=
-mermet_reservation := 40G
+mermet_reservation := 1G
 #mermet_channel     := $$(nix-env -p /nix/var/nix/profiles/per-user/$$USER/channels -q nixpkgs --no-name --out-path)
 
 echo:
        echo $(MAKEFILES)
 
-mermet-wipeout: mermet-umount
-       sudo zpool labelclear -f $(mermet_disk)-part3 || true
+wipeout: umount
+       #sudo zpool labelclear -f $(mermet_disk)-part3 || true
        sudo zpool labelclear -f $(mermet_disk)-part5 || true
        sudo $$(which sgdisk) --zap-all $(mermet_disk)
 
-mermet-partition:
+partition:
        sudo modprobe zfs
-       sudo $$(which sfdisk) $(mermet_disk) <machine/sfdisk.txt
-       sudo $$(which sgdisk) --randomize-guids $(mermet_disk)
-       sudo partprobe
+       set -x; if test -e sfdisk; then \
+               sudo $$(which sfdisk) $(losurdo_disk) <sfdisk.txt; \
+       else \
+               sudo $$(which sgdisk) --zap-all $(losurdo_disk) && \
+               sudo partprobe && \
+               sudo $$(which sgdisk) -a1 -n1:34:2047  -t1:EF02 $(losurdo_disk) && \
+               sudo $$(which sgdisk)     -n2:1M:+512M -t2:EF00 $(losurdo_disk) && \
+               sudo $$(which sgdisk)     -n3:0:+512M  -t3:8300 $(losurdo_disk) && \
+               sudo $$(which sgdisk)     -n4:0:+4G    -t4:8200 $(losurdo_disk) && \
+               sudo $$(which sgdisk)     -n5:0:0      -t5:BF01 $(losurdo_disk) && \
+               sudo $$(which sgdisk) --randomize-guids $(losurdo_disk) && \
+               sudo $$(which sfdisk) -d $(losurdo_disk) | \
+               sed -e 's&/dev/sd.&$(losurdo_disk)&' >sfdisk.txt; \
+       fi
 
-mermet-format:
+format:
        # DOC: https://github.com/zfsonlinux/zfs/wiki/Debian-Buster-Root-on-ZFS
        sudo mkdir -p /mnt/mermet
        blkid -t TYPE=ext2 $(mermet_disk)-part3; test $$? != 2 || \
@@ -65,13 +76,13 @@ mermet-format:
        # bpool
        
        # swap
-       # Note: configured with a volatile key in mermet.nix
+       # Note: configured with a volatile key in configuration.nix
        #blkid -t TYPE=crypto_LUKS $(mermet_disk)-part4; test $$? != 2 || \
        #sudo cryptsetup luksFormat --cipher aes-xts-plain64 --key-size 256 --hash sha256 $(mermet_disk)-part4
-       #sudo cryptsetup luksOpen $(mermet_disk)-part4 mermet-swap
-       #blkid -t TYPE=swap /dev/mapper/mermet--swap; test $$? != 2 || \
+       #sudo cryptsetup luksOpen $(mermet_disk)-part4 swap
+       #blkid -t TYPE=swap /dev/mapper/-swap; test $$? != 2 || \
        #sudo mkswap --check --label swap
-       #sudo cryptsetup luksClose $(mermet_disk)-part4 mermet-swap
+       #sudo cryptsetup luksClose $(mermet_disk)-part4 swap
        # rpool
        sudo zpool list rpool 2>/dev/null || \
        sudo zpool create -o ashift=12 \
@@ -88,10 +99,13 @@ mermet-format:
         compression=lz4 \
         dnodesize=auto \
         relatime=on \
-        $(if $(mermet_reservation),reservation=$(mermet_reservation)) \
         xattr=sa \
         mountpoint=/ \
         rpool
+       # https://nixos.wiki/wiki/NixOS_on_ZFS#Reservations
+       sudo zfs list rpool/reserved 2>/dev/null || \
+       sudo zfs create -o canmount=off -o mountpoint=none rpool/reserved
+       sudo zfs set refreservation=$(mermet_reservation) rpool/reserved
        # /
        # NOTE: mountpoint=legacy is required to let NixOS mount the ZFS filesystems.
        sudo zfs list rpool/root 2>/dev/null || \
@@ -112,11 +126,11 @@ mermet-format:
        for p in \
         home \
         nix \
-        nix/var \
         var \
         var/cache \
         var/log \
         var/mail \
+        var/redis \
         var/tmp \
         var/www \
         ; do \
@@ -129,9 +143,6 @@ mermet-format:
        sudo zfs set \
         com.sun:auto-snapshot=false \
         rpool/nix
-       sudo zfs set \
-        sync=always \
-        rpool/nix/var
        sudo zfs set \
         com.sun:auto-snapshot=false \
         rpool/var/cache
@@ -140,7 +151,7 @@ mermet-format:
         sync=disabled \
         rpool/var/tmp
 
-mermet-mount:
+mount:
        # scan needed zpools
        #sudo zpool list bpool || \
        #sudo zpool import -f bpool
@@ -169,11 +180,11 @@ mermet-mount:
        for p in \
         home \
         nix \
-        nix/var \
         var \
         var/cache \
         var/log \
         var/mail \
+        var/redis \
         var/tmp \
         var/www \
         ; do \
@@ -183,10 +194,9 @@ mermet-mount:
         done
        sudo chmod 1777 /mnt/mermet/var/tmp
 
-mermet-bootstrap: mermet-mount
-       sudo rm -rf /mnt/mermet/etc/nixos
+bootstrap: mount
        #test "$$(sudo grub-probe /mnt/mermet/boot)" = zfs
-       # NOTE: nixos-install will install GRUB following mermet.nix
+       # NOTE: nixos-install will install GRUB following configuration.nix
        # BIOS
        #sudo grub-install $(mermet_disk)
        # UEFI
@@ -197,19 +207,20 @@ mermet-bootstrap: mermet-mount
        # --recheck \
        # --no-floppy
        
-       pass sourcephile/mermet/dropbear/host-ecdsa.key | \
+       pass servers/mermet/dropbear/host.key | \
        sudo install -D -o root -g root -m 400 /dev/stdin \
-        /mnt/mermet/etc/dropbear/host-ecdsa.key && \
-       test -s /mnt/mermet/etc/dropbear/host-ecdsa.key
+        /mnt/mermet/etc/dropbear/host.key && \
+       test -s /mnt/mermet/etc/dropbear/host.key
        
        #trap "test ! -e SHRED-ME || sudo find SHRED-ME -type f -exec shred -u {} + && sudo rm -rf SHRED-ME" EXIT ;
        sudo \
         GNUPGHOME="$$GNUPGHOME" \
         GPG_TTY="$$GPG_TTY" \
+        DBUS_SESSION_BUS_ADDRESS="$$DBUS_SESSION_BUS_ADDRESS" \
         LANG="$$LANG" \
         LC_CTYPE="$$LC_CTYPE" \
-        NIXOPS_DEPLOYMENT="$(NIXOPS_DEPLOYMENT)" \
-        NIXOS_CONFIG="$$(readlink -e ../mermet.nix)" \
+        MERMET_DEPLOYMENT="$$MERMET_DEPLOYMENT" \
+        NIXOS_CONFIG="$$(readlink -e ../configuration.nix)" \
         NIX_CONF_DIR="$$NIX_CONF_DIR" \
         NIX_PATH="$$NIX_PATH" \
         PASSWORD_STORE_DIR="$$PASSWORD_STORE_DIR" \
@@ -218,19 +229,20 @@ mermet-bootstrap: mermet-mount
         $$(which nixos-install) \
         --root /mnt/mermet \
         $(if $(mermet_channel),--channel "$(mermet_channel)") \
+        --option -Inixops=$$(nix-instantiate --eval -E '(import <nixpkgs> {}).nixops + ""') \
         --no-root-passwd \
         --show-trace
 
-mermet-umount:
+umount:
        for p in \
         boot/efi \
         boot \
         home \
-        nix/var \
         nix \
         var/cache \
         var/log \
         var/mail \
+        var/redis \
         var/tmp \
         var/www \
         var \
@@ -249,3 +261,8 @@ mermet-umount:
        #sudo zpool export bpool
        ! sudo zpool list rpool 2>/dev/null || \
        sudo zpool export rpool
+
+unlock:
+       pass servers/mermet/zfs/rpool | \
+       NIXOPS_DEPLOYMENT="$${NIXOPS_DEPLOYMENT:-$(MERMET_DEPLOYMENT)}" \
+       nixops ssh mermet -p 2222 'zfs load-key rpool && pkill zfs'