main
1#!/usr/bin/env bash
2
3# Sakhalin (Fedora Workstation) bootstrap script.
4# Installs Determinate Nix, deploys minimal host files, and activates Home Manager.
5
6if [[ "${BASH_SOURCE[0]:-}" == "${0}" ]]; then
7 set -euo pipefail
8fi
9
10readonly GREEN='\033[0;32m'
11readonly YELLOW='\033[0;33m'
12readonly RED='\033[0;31m'
13readonly NC='\033[0m'
14
15REPO_URL="${REPO_URL:-https://git.sbr.pm/home.git}"
16REPO_PATH="${REPO_PATH:-$HOME/src/home}"
17SYSTEM_CONFIG="${SYSTEM_CONFIG:-sakhalin}"
18
19log_info() { echo -e "${GREEN}[INFO]${NC} $*"; }
20log_warn() { echo -e "${YELLOW}[WARN]${NC} $*"; }
21log_error() { echo -e "${RED}[ERROR]${NC} $*" >&2; }
22
23check_root() {
24 if [[ $EUID -eq 0 ]]; then
25 log_error "Run as your regular user, not root (sudo is used when needed)"
26 exit 1
27 fi
28}
29
30source_nix() {
31 if ! command -v nix &>/dev/null && [[ -f /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh ]]; then
32 # shellcheck disable=SC1091
33 . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh
34 fi
35}
36
37install_nix() {
38 if command -v nix &>/dev/null; then
39 log_info "Nix already installed: $(nix --version)"
40 return 0
41 fi
42
43 log_info "Installing Nix (Determinate Systems installer)..."
44 curl --proto '=https' --tlsv1.2 -sSf -L https://install.determinate.systems/nix | sh -s -- install
45 source_nix
46}
47
48clone_repo() {
49 if [[ -d "$REPO_PATH/.git" ]]; then
50 log_info "Repository exists at $REPO_PATH, pulling..."
51 git -C "$REPO_PATH" pull --ff-only || log_warn "Pull failed, continuing with existing checkout"
52 return 0
53 fi
54
55 log_info "Cloning $REPO_URL → $REPO_PATH"
56 mkdir -p "$(dirname "$REPO_PATH")"
57 git clone "$REPO_URL" "$REPO_PATH"
58}
59
60setup_host_configs() {
61 local config_path
62
63 cd "$REPO_PATH"
64 config_path=$(nix build ".#fedoraConfigs.${SYSTEM_CONFIG}" --no-link --print-out-paths)
65 sudo "${config_path}/deploy"
66}
67
68enable_wireguard() {
69 log_info "Enabling WireGuard for a future boot after private-key restoration..."
70 sudo systemctl enable wg-quick@wg0.service
71}
72
73setup_home_manager() {
74 cd "$REPO_PATH"
75 nix run home-manager -- switch --flake ".#vincent@${SYSTEM_CONFIG}" -b backup
76}
77
78main() {
79 log_info "Bootstrapping Sakhalin..."
80 check_root
81 install_nix
82 clone_repo
83 setup_host_configs
84 enable_wireguard
85 setup_home_manager
86 log_info "Sakhalin bootstrap completed. Restore /etc/wireguard/private.key before starting WireGuard."
87}
88
89if [[ "${BASH_SOURCE[0]:-}" == "${0}" ]]; then
90 main "$@"
91fi