Commit 76cdc7695e0d

Vincent Demeester <vincent@sbr.pm>
2026-10-01 17:02:08
feat(nix): added Kyushu Nagoya builder
Enabled Kyushu to delegate native ARM builds to Nagoya with a distinct restricted key, matching the existing Aomi builder workflow. Signed-off-by: Vincent Demeester <vincent@sbr.pm>
1 parent 59882e5
imperative/nagoya/authorize-aomi-builder.sh → imperative/nagoya/authorize-builder.sh
@@ -1,7 +1,7 @@
 #!/usr/bin/env bash
 
-# Authorize Aomi's dedicated Nix builder key on Nagoya.
-# Run from Aomi after installing /etc/nix/keys/nagoya-builder.pub.
+# Authorize a supplied dedicated Nix builder public key on Nagoya.
+# Run after installing /etc/nix/keys/nagoya-builder.pub.
 
 set -euo pipefail
 
imperative/nagoya/test-builder-key.sh
@@ -3,9 +3,10 @@
 set -euo pipefail
 
 repo_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)
-helper="$repo_root/imperative/nagoya/authorize-aomi-builder.sh"
+helper="$repo_root/imperative/nagoya/authorize-builder.sh"
 
 [[ -x "$helper" ]]
 grep -qF 'restrict,command=\"/nix/var/nix/profiles/default/bin/nix-daemon --stdio\"' "$helper"
 grep -q 'aomi-nagoya-builder' "$repo_root/globals.nix"
+grep -q 'kyushu-nagoya-builder' "$repo_root/globals.nix"
 grep -q 'access.vincent.nagoya = "trusted"' "$repo_root/globals.nix"
systems/common/fedora-work/gen-configs.nix
@@ -10,7 +10,7 @@
 }:
 let
   machine = globals.machines.${hostname};
-  isAomi = hostname == "aomi";
+  isNagoyaBuilderClient = builtins.elem hostname [ "aomi" "kyushu" ];
   nagoya = globals.machines.nagoya;
   hostsEntries = libx.hostConfigs globals.machines;
   hostsFile = lib.concatStringsSep "\n" (
@@ -39,7 +39,7 @@ let
     trusted-users = root @wheel
     connect-timeout = 5
     download-attempts = 2
-    builders-use-substitutes = true
+    ${lib.optionalString isNagoyaBuilderClient "builders-use-substitutes = true"}
   '';
 
   nixMachines = pkgs.writeText "nix-machines" ''
@@ -79,14 +79,14 @@ let
     if ! grep -q '^download-attempts[[:space:]]*=' /etc/nix/nix.custom.conf; then
       echo 'download-attempts = 2' >> /etc/nix/nix.custom.conf
     fi
-    ${lib.optionalString isAomi ''
+    ${lib.optionalString isNagoyaBuilderClient ''
       if ! grep -q '^builders-use-substitutes[[:space:]]*=' /etc/nix/nix.custom.conf; then
         echo 'builders-use-substitutes = true' >> /etc/nix/nix.custom.conf
       fi
     ''}
     mkdir -p /etc/NetworkManager/dispatcher.d
     install -m 0755 ${nmDispatcher} /etc/NetworkManager/dispatcher.d/99-wireguard-route
-    ${lib.optionalString isAomi ''
+    ${lib.optionalString isNagoyaBuilderClient ''
       install -m 0644 ${nixMachines} /etc/nix/machines
       install -d -m 0755 /etc/ssh
       install -m 0644 ${sshKnownHosts} /etc/ssh/ssh_known_hosts
@@ -100,7 +100,7 @@ pkgs.runCommand "fedora-configs-${hostname}" { } ''
   cp ${wgConf} $out/etc/wireguard/wg0.conf
   cp ${nixCustomConf} $out/etc/nix/nix.custom.conf
   cp ${nmDispatcher} $out/etc/NetworkManager/dispatcher.d/99-wireguard-route
-  ${lib.optionalString isAomi ''
+  ${lib.optionalString isNagoyaBuilderClient ''
     mkdir -p $out/etc/ssh
     cp ${nixMachines} $out/etc/nix/machines
     cp ${sshKnownHosts} $out/etc/ssh/ssh_known_hosts
systems/common/fedora-work/test-gen-configs.sh
@@ -5,11 +5,15 @@ set -euo pipefail
 repo_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/../../.." && pwd)
 generator="$repo_root/systems/common/fedora-work/gen-configs.nix"
 
-# Aomi delegates native ARM builds to Nagoya through its Nix daemon.
+# Aomi and Kyushu delegate native ARM builds to Nagoya through their Nix daemons.
 grep -q 'ssh-ng://vincent@nagoya.vpn aarch64-linux /etc/nix/keys/nagoya-builder 4 1' "$generator"
 grep -q 'builders-use-substitutes = true' "$generator"
 grep -q '/etc/nix/machines' "$generator"
 grep -q '/etc/ssh/ssh_known_hosts' "$generator"
 
 cd "$repo_root"
-nix build .#fedoraConfigs.aomi --dry-run >/dev/null
+for host in aomi kyushu; do
+  out=$(nix build --no-link --print-out-paths ".#fedoraConfigs.$host")
+  test -f "$out/etc/nix/machines"
+  test -f "$out/etc/ssh/ssh_known_hosts"
+done
globals.nix
@@ -80,6 +80,10 @@ _: {
         key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIuiAFmNPzh+hpnLfjCauNQWIuQ4JRBT7cD/y/5zjmZK aomi-nagoya-builder";
         access.vincent.nagoya = "trusted";
       };
+      kyushu-nagoya-builder = {
+        key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINkw0Oc5ZQWIOSAykMb37B1xqViH1Nt8Ol+bMhE/qzK8 kyushu-nagoya-builder";
+        access.vincent.nagoya = "trusted";
+      };
       boox-moshi = {
         key = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICuaKzLeP5TasvkLucaqM/SDxP07B3zqVetuFz5+ZXQS moshi";
         access.vincent.aomi = "trusted";