5 Commits
Author SHA1 Message Date
jackos1998andClaude Opus 5 d1b9358069 nixos/netboot: Fix installer update failures
CI / Check, build and cache nixfiles (push) Has been cancelled
Update docs / update (push) Has been cancelled
Installer / Build installer (push) Successful in 4m56s
`netboot-update` failed with an opaque curl usage error whenever the
`installer` tag advanced past a build that had not published assets:
the `jq` select found no matching asset, and the empty result was
passed straight to `curl` as the URL. Report the missing asset (and
an unresolvable tag) instead.

The unit also had its network dependency inverted, being `wantedBy`
network-online.target rather than wanting and ordering after it. Fix
the idiom and keep it in the boot transaction via multi-user.target.

On river that is not enough on its own, because the WAN is a pppd
interface that networkd's wait-online knows nothing about, so
network-online.target is reached well before there is a route
off-site. Gate the service on wan-online.target there, following the
same wantedBy + partOf idiom as ipsec, which also re-runs the fetch
whenever the link returns.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 23:21:31 +01:00
jackos1998andClaude Opus 5 41ada3fa60 ci/installer: Switch to gitea-release-action
`release-action` is archived; its repository points at
`gitea-release-action` as the replacement. The inputs were renamed
(`api_key` -> `token`, `title` -> `name`).

The new action is a Node one rather than Go, so the Go setup step
kept in the previous commit is no longer needed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 23:17:25 +01:00
jackos1998andClaude Opus 5 dcf79577ca nixos/git: Buffer uploads on the state volume
Gitea writes uploaded release assets to a temp file before storing
them. That landed in `/tmp`, which is on the 2G tmpfs root, so
uploading the installer ISO failed with:

  ParseMultipartForm [E] ... write /tmp/multipart-...: no space
  left on device

Point the service's `TMPDIR` at the state volume, which has room.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 23:17:21 +01:00
jackos1998andClaude Opus 5 cea32c5f16 ci/installer: Refresh workflow infrastructure
CI / Check, build and cache nixfiles (push) Has been cancelled
Update docs / update (push) Has been cancelled
Installer / Build installer (push) Failing after 4m30s
The installer workflow had not been touched since 2024 and missed
both the Ubuntu 26.04 runner bump and the move to Determinate Nix as
the common Nix. Bring it in line with `ci.yaml`.

The Go setup step stays: it supports the Gitea release action rather
than the Nix build.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 22:52:35 +01:00
jackos1998andClaude Opus 5 cbc48e456d nixos/build: Fix netboot initrd systemd config
`boot.initrd.systemd.extraConfig` was removed upstream and now fails
an assertion, which broke the `netbootArchive` target and with it the
second build step of the installer release workflow. Move the two
timeout settings to `settings.Manager`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 22:52:30 +01:00
5 changed files with 48 additions and 18 deletions
+14 -12
View File
@@ -7,20 +7,22 @@ on:
jobs:
installer:
name: Build installer
runs-on: ubuntu-22.04
runs-on: ubuntu-26.04
steps:
- uses: actions/checkout@v4
- name: Set up Go
uses: https://github.com/actions/setup-go@v4
- uses: actions/checkout@v6
- uses: DeterminateSystems/determinate-nix-action@v3
with:
go-version: '>=1.20.1'
- uses: cachix/install-nix-action@v27
with:
github_access_token: ${{ secrets.GH_PULL_TOKEN }}
extra_nix_config: |
# Gitea will supply a token in GITHUB_TOKEN, which this action passes to
# Nix (as access-tokens) when downloading from GitHub
github-token: ${{ secrets.GH_PULL_TOKEN }}
extra-conf: |
# Make sure we're using sandbox
sandbox-fallback = false
# Determinate performance features
lazy-trees = true
eval-cores = 0
extra-substituters = https://nix-cache.nul.ie
extra-trusted-public-keys = nix-cache.nul.ie-1:BzH5yMfF4HbzY1C977XzOxoPhEc9Zbu39ftPkUbH+m4=
@@ -40,10 +42,10 @@ jobs:
jackos-installer-netboot-${{ steps.setup.outputs.short_rev }}.tar.zst
- name: Create release
uses: https://gitea.com/actions/release-action@main
uses: https://gitea.com/actions/gitea-release-action@main
with:
title: Latest installer
api_key: '${{ secrets.RELEASE_TOKEN }}'
name: Latest installer
token: '${{ secrets.RELEASE_TOKEN }}'
files: |
jackos-installer-${{ steps.setup.outputs.short_rev }}.iso
jackos-installer-netboot-${{ steps.setup.outputs.short_rev }}.tar.zst
+10
View File
@@ -43,9 +43,19 @@ in
(umask 027; gitea_extra_setup)
'';
# Uploaded release assets are buffered through a temp file before being stored.
# The default /tmp is on the small tmpfs root, so keep them on the state volume.
environment.TMPDIR = "${config.services.gitea.stateDir}/tmp";
}
];
};
tmpfiles.settings."10-gitea-tmp"."${config.services.gitea.stateDir}/tmp".d = {
user = config.services.gitea.user;
group = config.services.gitea.group;
mode = "0700";
};
};
services = {
+9
View File
@@ -145,6 +145,15 @@
};
};
# networkd's wait-online knows nothing about the pppd-owned `wan` interface, so
# network-online.target is reached long before there's a route off-site. Gate the
# installer fetch on the WAN instead, and retry it whenever the link returns.
systemd.services.netboot-update = {
after = [ "wan-online.target" ];
wantedBy = mkForce [ "wan-online.target" ];
partOf = [ "wan-online.target" ];
};
systemd.network = {
netdevs = mkMerge [
(mkVLAN "wan-pon-ont" vlans.wan-pon-ont)
+4 -4
View File
@@ -64,10 +64,10 @@ let
ip = "${iproute2}/bin/ip";
nbd-client = "${nbd}/bin/nbd-client";
};
extraConfig = ''
DefaultTimeoutStartSec=20
DefaultDeviceTimeoutSec=20
'';
settings.Manager = {
DefaultTimeoutStartSec = "20s";
DefaultDeviceTimeoutSec = "20s";
};
network = {
enable = true;
+11 -2
View File
@@ -129,7 +129,8 @@ in
services = {
netboot-update = {
description = "Update netboot images";
after = [ "systemd-networkd-wait-online.service" ];
wants = [ "network-online.target" ];
after = [ "network-online.target" ];
serviceConfig.Type = "oneshot";
path = with pkgs; [
coreutils curl jq zstd gnutar
@@ -138,6 +139,10 @@ in
update_nixos() {
latestShort="$(curl -s https://git.nul.ie/api/v1/repos/dev/nixfiles/tags/installer \
| jq -r .commit.sha | cut -c -7)"
if [ -z "$latestShort" ] || [ "$latestShort" = "null" ]; then
echo "Couldn't resolve the installer tag to a commit" >&2
return 1
fi
if [ -f nixos-installer/tag.txt ] && [ "$(< nixos-installer/tag.txt)" = "$latestShort" ]; then
echo "NixOS installer is up to date"
return
@@ -148,6 +153,10 @@ in
fname="jackos-installer-netboot-$latestShort.tar.zst"
downloadUrl="$(curl -s https://git.nul.ie/api/v1/repos/dev/nixfiles/releases/tags/installer | \
jq -r ".assets[] | select(.name == \"$fname\").browser_download_url")"
if [ -z "$downloadUrl" ]; then
echo "No release asset $fname; did the installer build succeed?" >&2
return 1
fi
curl -Lo /tmp/nixos-installer-netboot.tar.zst "$downloadUrl"
tar -C nixos-installer --zstd -xf /tmp/nixos-installer-netboot.tar.zst
truncate -s "${cfg.server.installer.storeSize}" nixos-installer/rootfs.ext4
@@ -163,7 +172,7 @@ in
update_nixos
'';
startAt = "06:00";
wantedBy = [ "network-online.target" ];
wantedBy = [ "multi-user.target" ];
};
nbd-server = {