Commit d96fd9c0aa93

Vincent Demeester <vincent@sbr.pm>
2026-09-10 14:16:25
feat(nix): add Nagoya as an ARM builder
Register Nagoya as Aomi's native ARM build machine with pinned host verification so aarch64 derivations use available capacity rather than the Fedora workstation. Signed-off-by: Vincent Demeester <vincent@sbr.pm>
1 parent 1ae1857
Changed files (2)
systems
systems/common/fedora-work/gen-configs.nix
@@ -10,6 +10,8 @@
 }:
 let
   machine = globals.machines.${hostname};
+  isAomi = hostname == "aomi";
+  nagoya = globals.machines.nagoya;
   hostsEntries = libx.hostConfigs globals.machines;
   hostsFile = lib.concatStringsSep "\n" (
     lib.mapAttrsToList (ip: names: "${ip} ${lib.concatStringsSep " " names}") hostsEntries
@@ -37,6 +39,15 @@ let
     trusted-users = root @wheel
     connect-timeout = 5
     download-attempts = 2
+    builders-use-substitutes = true
+  '';
+
+  nixMachines = pkgs.writeText "nix-machines" ''
+    ssh-ng://vincent@nagoya.vpn aarch64-linux /home/vdemeest/.ssh/id_homelab_sk 4 1
+  '';
+
+  sshKnownHosts = pkgs.writeText "ssh-known-hosts" ''
+    nagoya.home,nagoya.vpn,nagoya.sbr.pm,192.168.1.80,10.100.0.80 ${nagoya.ssh.hostKey}
   '';
 
   nmDispatcher = pkgs.writeScript "99-wireguard-route" ''
@@ -57,13 +68,29 @@ let
     install -m 0644 ${hosts} /etc/hosts
     mkdir -p /etc/wireguard
     install -m 0600 ${wgConf} /etc/wireguard/wg0.conf
-    if [ -f /etc/nix/nix.custom.conf ]; then
-      if ! grep -q 'trusted-users' /etc/nix/nix.custom.conf 2>/dev/null; then
-        cat ${nixCustomConf} >> /etc/nix/nix.custom.conf
-      fi
+    mkdir -p /etc/nix
+    touch /etc/nix/nix.custom.conf
+    if ! grep -q '^trusted-users[[:space:]]*=' /etc/nix/nix.custom.conf; then
+      echo 'trusted-users = root @wheel' >> /etc/nix/nix.custom.conf
     fi
+    if ! grep -q '^connect-timeout[[:space:]]*=' /etc/nix/nix.custom.conf; then
+      echo 'connect-timeout = 5' >> /etc/nix/nix.custom.conf
+    fi
+    if ! grep -q '^download-attempts[[:space:]]*=' /etc/nix/nix.custom.conf; then
+      echo 'download-attempts = 2' >> /etc/nix/nix.custom.conf
+    fi
+    ${lib.optionalString isAomi ''
+      if ! grep -q '^builders-use-substitutes[[:space:]]*=' /etc/nix/nix.custom.conf; then
+        echo 'builders-use-substitutes = true' >> /etc/nix/nix.custom.conf
+      fi
+    ''}
     mkdir -p /etc/NetworkManager/dispatcher.d
     install -m 0755 ${nmDispatcher} /etc/NetworkManager/dispatcher.d/99-wireguard-route
+    ${lib.optionalString isAomi ''
+      install -m 0644 ${nixMachines} /etc/nix/machines
+      install -d -m 0755 /etc/ssh
+      install -m 0644 ${sshKnownHosts} /etc/ssh/ssh_known_hosts
+    ''}
     echo "Done!"
   '';
 in
@@ -73,5 +100,10 @@ pkgs.runCommand "fedora-configs-${hostname}" { } ''
   cp ${wgConf} $out/etc/wireguard/wg0.conf
   cp ${nixCustomConf} $out/etc/nix/nix.custom.conf
   cp ${nmDispatcher} $out/etc/NetworkManager/dispatcher.d/99-wireguard-route
+  ${lib.optionalString isAomi ''
+    mkdir -p $out/etc/ssh
+    cp ${nixMachines} $out/etc/nix/machines
+    cp ${sshKnownHosts} $out/etc/ssh/ssh_known_hosts
+  ''}
   cp ${deployScript} $out/deploy
 ''
systems/common/fedora-work/test-gen-configs.sh
@@ -0,0 +1,15 @@
+#!/usr/bin/env bash
+
+set -euo pipefail
+
+repo_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/../../.." && pwd)
+generator="$repo_root/systems/common/fedora-work/gen-configs.nix"
+
+# Aomi delegates native ARM builds to Nagoya through its Nix daemon.
+grep -q 'ssh-ng://vincent@nagoya.vpn aarch64-linux /home/vdemeest/.ssh/id_homelab_sk 4 1' "$generator"
+grep -q 'builders-use-substitutes = true' "$generator"
+grep -q '/etc/nix/machines' "$generator"
+grep -q '/etc/ssh/ssh_known_hosts' "$generator"
+
+cd "$repo_root"
+nix build .#fedoraConfigs.aomi --dry-run >/dev/null