main
 1#!/usr/bin/env bash
 2
 3# Sakhalin (Fedora Workstation) bootstrap script.
 4# Installs Determinate Nix, deploys minimal host files, and activates Home Manager.
 5
 6if [[ "${BASH_SOURCE[0]:-}" == "${0}" ]]; then
 7	set -euo pipefail
 8fi
 9
10readonly GREEN='\033[0;32m'
11readonly YELLOW='\033[0;33m'
12readonly RED='\033[0;31m'
13readonly NC='\033[0m'
14
15REPO_URL="${REPO_URL:-https://git.sbr.pm/home.git}"
16REPO_PATH="${REPO_PATH:-$HOME/src/home}"
17SYSTEM_CONFIG="${SYSTEM_CONFIG:-sakhalin}"
18
19log_info() { echo -e "${GREEN}[INFO]${NC} $*"; }
20log_warn() { echo -e "${YELLOW}[WARN]${NC} $*"; }
21log_error() { echo -e "${RED}[ERROR]${NC} $*" >&2; }
22
23check_root() {
24	if [[ $EUID -eq 0 ]]; then
25		log_error "Run as your regular user, not root (sudo is used when needed)"
26		exit 1
27	fi
28}
29
30source_nix() {
31	if ! command -v nix &>/dev/null && [[ -f /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh ]]; then
32		# shellcheck disable=SC1091
33		. /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh
34	fi
35}
36
37install_nix() {
38	if command -v nix &>/dev/null; then
39		log_info "Nix already installed: $(nix --version)"
40		return 0
41	fi
42
43	log_info "Installing Nix (Determinate Systems installer)..."
44	curl --proto '=https' --tlsv1.2 -sSf -L https://install.determinate.systems/nix | sh -s -- install
45	source_nix
46}
47
48clone_repo() {
49	if [[ -d "$REPO_PATH/.git" ]]; then
50		log_info "Repository exists at $REPO_PATH, pulling..."
51		git -C "$REPO_PATH" pull --ff-only || log_warn "Pull failed, continuing with existing checkout"
52		return 0
53	fi
54
55	log_info "Cloning $REPO_URL → $REPO_PATH"
56	mkdir -p "$(dirname "$REPO_PATH")"
57	git clone "$REPO_URL" "$REPO_PATH"
58}
59
60setup_host_configs() {
61	local config_path
62
63	cd "$REPO_PATH"
64	config_path=$(nix build ".#fedoraConfigs.${SYSTEM_CONFIG}" --no-link --print-out-paths)
65	sudo "${config_path}/deploy"
66}
67
68enable_wireguard() {
69	log_info "Enabling WireGuard for a future boot after private-key restoration..."
70	sudo systemctl enable wg-quick@wg0.service
71}
72
73setup_home_manager() {
74	cd "$REPO_PATH"
75	nix run home-manager -- switch --flake ".#vincent@${SYSTEM_CONFIG}" -b backup
76}
77
78main() {
79	log_info "Bootstrapping Sakhalin..."
80	check_root
81	install_nix
82	clone_repo
83	setup_host_configs
84	enable_wireguard
85	setup_home_manager
86	log_info "Sakhalin bootstrap completed. Restore /etc/wireguard/private.key before starting WireGuard."
87}
88
89if [[ "${BASH_SOURCE[0]:-}" == "${0}" ]]; then
90	main "$@"
91fi