Compare commits
5
Commits
05918ec2ce
...
installer
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d1b9358069 | ||
|
|
41ada3fa60 | ||
|
|
dcf79577ca | ||
|
|
cea32c5f16 | ||
|
|
cbc48e456d |
@@ -7,20 +7,22 @@ on:
|
||||
jobs:
|
||||
installer:
|
||||
name: Build installer
|
||||
runs-on: ubuntu-22.04
|
||||
runs-on: ubuntu-26.04
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Set up Go
|
||||
uses: https://github.com/actions/setup-go@v4
|
||||
- uses: actions/checkout@v6
|
||||
- uses: DeterminateSystems/determinate-nix-action@v3
|
||||
with:
|
||||
go-version: '>=1.20.1'
|
||||
- uses: cachix/install-nix-action@v27
|
||||
with:
|
||||
github_access_token: ${{ secrets.GH_PULL_TOKEN }}
|
||||
extra_nix_config: |
|
||||
# Gitea will supply a token in GITHUB_TOKEN, which this action passes to
|
||||
# Nix (as access-tokens) when downloading from GitHub
|
||||
github-token: ${{ secrets.GH_PULL_TOKEN }}
|
||||
extra-conf: |
|
||||
# Make sure we're using sandbox
|
||||
sandbox-fallback = false
|
||||
|
||||
# Determinate performance features
|
||||
lazy-trees = true
|
||||
eval-cores = 0
|
||||
|
||||
extra-substituters = https://nix-cache.nul.ie
|
||||
extra-trusted-public-keys = nix-cache.nul.ie-1:BzH5yMfF4HbzY1C977XzOxoPhEc9Zbu39ftPkUbH+m4=
|
||||
|
||||
@@ -40,10 +42,10 @@ jobs:
|
||||
jackos-installer-netboot-${{ steps.setup.outputs.short_rev }}.tar.zst
|
||||
|
||||
- name: Create release
|
||||
uses: https://gitea.com/actions/release-action@main
|
||||
uses: https://gitea.com/actions/gitea-release-action@main
|
||||
with:
|
||||
title: Latest installer
|
||||
api_key: '${{ secrets.RELEASE_TOKEN }}'
|
||||
name: Latest installer
|
||||
token: '${{ secrets.RELEASE_TOKEN }}'
|
||||
files: |
|
||||
jackos-installer-${{ steps.setup.outputs.short_rev }}.iso
|
||||
jackos-installer-netboot-${{ steps.setup.outputs.short_rev }}.tar.zst
|
||||
|
||||
@@ -43,9 +43,19 @@ in
|
||||
|
||||
(umask 027; gitea_extra_setup)
|
||||
'';
|
||||
|
||||
# Uploaded release assets are buffered through a temp file before being stored.
|
||||
# The default /tmp is on the small tmpfs root, so keep them on the state volume.
|
||||
environment.TMPDIR = "${config.services.gitea.stateDir}/tmp";
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
tmpfiles.settings."10-gitea-tmp"."${config.services.gitea.stateDir}/tmp".d = {
|
||||
user = config.services.gitea.user;
|
||||
group = config.services.gitea.group;
|
||||
mode = "0700";
|
||||
};
|
||||
};
|
||||
|
||||
services = {
|
||||
|
||||
@@ -145,6 +145,15 @@
|
||||
};
|
||||
};
|
||||
|
||||
# networkd's wait-online knows nothing about the pppd-owned `wan` interface, so
|
||||
# network-online.target is reached long before there's a route off-site. Gate the
|
||||
# installer fetch on the WAN instead, and retry it whenever the link returns.
|
||||
systemd.services.netboot-update = {
|
||||
after = [ "wan-online.target" ];
|
||||
wantedBy = mkForce [ "wan-online.target" ];
|
||||
partOf = [ "wan-online.target" ];
|
||||
};
|
||||
|
||||
systemd.network = {
|
||||
netdevs = mkMerge [
|
||||
(mkVLAN "wan-pon-ont" vlans.wan-pon-ont)
|
||||
|
||||
@@ -64,10 +64,10 @@ let
|
||||
ip = "${iproute2}/bin/ip";
|
||||
nbd-client = "${nbd}/bin/nbd-client";
|
||||
};
|
||||
extraConfig = ''
|
||||
DefaultTimeoutStartSec=20
|
||||
DefaultDeviceTimeoutSec=20
|
||||
'';
|
||||
settings.Manager = {
|
||||
DefaultTimeoutStartSec = "20s";
|
||||
DefaultDeviceTimeoutSec = "20s";
|
||||
};
|
||||
|
||||
network = {
|
||||
enable = true;
|
||||
|
||||
@@ -129,7 +129,8 @@ in
|
||||
services = {
|
||||
netboot-update = {
|
||||
description = "Update netboot images";
|
||||
after = [ "systemd-networkd-wait-online.service" ];
|
||||
wants = [ "network-online.target" ];
|
||||
after = [ "network-online.target" ];
|
||||
serviceConfig.Type = "oneshot";
|
||||
path = with pkgs; [
|
||||
coreutils curl jq zstd gnutar
|
||||
@@ -138,6 +139,10 @@ in
|
||||
update_nixos() {
|
||||
latestShort="$(curl -s https://git.nul.ie/api/v1/repos/dev/nixfiles/tags/installer \
|
||||
| jq -r .commit.sha | cut -c -7)"
|
||||
if [ -z "$latestShort" ] || [ "$latestShort" = "null" ]; then
|
||||
echo "Couldn't resolve the installer tag to a commit" >&2
|
||||
return 1
|
||||
fi
|
||||
if [ -f nixos-installer/tag.txt ] && [ "$(< nixos-installer/tag.txt)" = "$latestShort" ]; then
|
||||
echo "NixOS installer is up to date"
|
||||
return
|
||||
@@ -148,6 +153,10 @@ in
|
||||
fname="jackos-installer-netboot-$latestShort.tar.zst"
|
||||
downloadUrl="$(curl -s https://git.nul.ie/api/v1/repos/dev/nixfiles/releases/tags/installer | \
|
||||
jq -r ".assets[] | select(.name == \"$fname\").browser_download_url")"
|
||||
if [ -z "$downloadUrl" ]; then
|
||||
echo "No release asset $fname; did the installer build succeed?" >&2
|
||||
return 1
|
||||
fi
|
||||
curl -Lo /tmp/nixos-installer-netboot.tar.zst "$downloadUrl"
|
||||
tar -C nixos-installer --zstd -xf /tmp/nixos-installer-netboot.tar.zst
|
||||
truncate -s "${cfg.server.installer.storeSize}" nixos-installer/rootfs.ext4
|
||||
@@ -163,7 +172,7 @@ in
|
||||
update_nixos
|
||||
'';
|
||||
startAt = "06:00";
|
||||
wantedBy = [ "network-online.target" ];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
};
|
||||
|
||||
nbd-server = {
|
||||
|
||||
Reference in New Issue
Block a user