main
  1# Generate system config files for Fedora work hosts without system-manager.
  2# Usage: nix build .#fedoraConfigs.<hostname>
  3# Then: sudo ./result/deploy
  4{
  5  lib,
  6  pkgs,
  7  globals,
  8  libx,
  9  hostname,
 10}:
 11let
 12  machine = globals.machines.${hostname};
 13  isNagoyaBuilderClient = builtins.elem hostname [
 14    "aomi"
 15    "kyushu"
 16  ];
 17  nagoya = globals.machines.nagoya;
 18  hostsEntries = libx.hostConfigs globals.machines;
 19  hostsFile = lib.concatStringsSep "\n" (
 20    lib.mapAttrsToList (ip: names: "${ip} ${lib.concatStringsSep " " names}") hostsEntries
 21  );
 22
 23  hosts = pkgs.writeText "hosts" ''
 24    127.0.0.1 localhost
 25    ::1 localhost
 26    ${hostsFile}
 27  '';
 28
 29  wgConf = pkgs.writeText "wg0.conf" ''
 30    [Interface]
 31    PostUp = wg set %i private-key /etc/wireguard/private.key
 32    Address = ${builtins.head machine.net.vpn.ips}/24
 33
 34    [Peer]
 35    PublicKey = ${globals.machines.carthage.net.vpn.pubkey}
 36    AllowedIPs = 10.100.0.0/24
 37    Endpoint = ${globals.net.vpn.endpoint}:51820
 38    PersistentKeepalive = 25
 39  '';
 40
 41  nixCustomConf = pkgs.writeText "nix.custom.conf" ''
 42    trusted-users = root @wheel
 43    connect-timeout = 5
 44    download-attempts = 2
 45    ${lib.optionalString isNagoyaBuilderClient "builders-use-substitutes = true"}
 46  '';
 47
 48  nixMachines = pkgs.writeText "nix-machines" ''
 49    ssh-ng://vincent@nagoya.vpn aarch64-linux /etc/nix/keys/nagoya-builder 4 1
 50  '';
 51
 52  sshKnownHosts = pkgs.writeText "ssh-known-hosts" ''
 53    nagoya.home,nagoya.vpn,nagoya.sbr.pm,192.168.1.80,10.100.0.80 ${nagoya.ssh.hostKey}
 54  '';
 55
 56  nmDispatcher = pkgs.writeScript "99-wireguard-route" ''
 57    #!/bin/bash
 58    INTERFACE="$1"
 59    ACTION="$2"
 60    if [[ "$INTERFACE" == "tun0" && "$ACTION" == "vpn-up" ]]; then
 61      TABLE=$(ip rule show | grep -oP 'lookup \K[0-9]+' | head -1)
 62      if [[ -n "$TABLE" && "$TABLE" != "local" ]]; then
 63        ip route add 10.100.0.0/24 dev wg0 table "$TABLE" 2>/dev/null || true
 64      fi
 65    fi
 66  '';
 67
 68  deployScript = pkgs.writeShellScript "deploy-configs" ''
 69    set -euo pipefail
 70    echo "Deploying system configs for ${hostname}..."
 71    install -m 0644 ${hosts} /etc/hosts
 72    mkdir -p /etc/wireguard
 73    install -m 0600 ${wgConf} /etc/wireguard/wg0.conf
 74    mkdir -p /etc/nix
 75    touch /etc/nix/nix.custom.conf
 76    if ! grep -q '^trusted-users[[:space:]]*=' /etc/nix/nix.custom.conf; then
 77      echo 'trusted-users = root @wheel' >> /etc/nix/nix.custom.conf
 78    fi
 79    if ! grep -q '^connect-timeout[[:space:]]*=' /etc/nix/nix.custom.conf; then
 80      echo 'connect-timeout = 5' >> /etc/nix/nix.custom.conf
 81    fi
 82    if ! grep -q '^download-attempts[[:space:]]*=' /etc/nix/nix.custom.conf; then
 83      echo 'download-attempts = 2' >> /etc/nix/nix.custom.conf
 84    fi
 85    ${lib.optionalString isNagoyaBuilderClient ''
 86      if ! grep -q '^builders-use-substitutes[[:space:]]*=' /etc/nix/nix.custom.conf; then
 87        echo 'builders-use-substitutes = true' >> /etc/nix/nix.custom.conf
 88      fi
 89    ''}
 90    mkdir -p /etc/NetworkManager/dispatcher.d
 91    install -m 0755 ${nmDispatcher} /etc/NetworkManager/dispatcher.d/99-wireguard-route
 92    ${lib.optionalString isNagoyaBuilderClient ''
 93      install -m 0644 ${nixMachines} /etc/nix/machines
 94      install -d -m 0755 /etc/ssh
 95      install -m 0644 ${sshKnownHosts} /etc/ssh/ssh_known_hosts
 96    ''}
 97    echo "Done!"
 98  '';
 99in
100pkgs.runCommand "fedora-configs-${hostname}" { } ''
101  mkdir -p $out/etc/wireguard $out/etc/NetworkManager/dispatcher.d $out/etc/nix
102  cp ${hosts} $out/etc/hosts
103  cp ${wgConf} $out/etc/wireguard/wg0.conf
104  cp ${nixCustomConf} $out/etc/nix/nix.custom.conf
105  cp ${nmDispatcher} $out/etc/NetworkManager/dispatcher.d/99-wireguard-route
106  ${lib.optionalString isNagoyaBuilderClient ''
107    mkdir -p $out/etc/ssh
108    cp ${nixMachines} $out/etc/nix/machines
109    cp ${sshKnownHosts} $out/etc/ssh/ssh_known_hosts
110  ''}
111  cp ${deployScript} $out/deploy
112''