3 Commits
Author SHA1 Message Date
jackos1998andClaude Opus 5 d1b9358069 nixos/netboot: Fix installer update failures
CI / Check, build and cache nixfiles (push) Has been cancelled
Update docs / update (push) Has been cancelled
Installer / Build installer (push) Successful in 4m56s
`netboot-update` failed with an opaque curl usage error whenever the
`installer` tag advanced past a build that had not published assets:
the `jq` select found no matching asset, and the empty result was
passed straight to `curl` as the URL. Report the missing asset (and
an unresolvable tag) instead.

The unit also had its network dependency inverted, being `wantedBy`
network-online.target rather than wanting and ordering after it. Fix
the idiom and keep it in the boot transaction via multi-user.target.

On river that is not enough on its own, because the WAN is a pppd
interface that networkd's wait-online knows nothing about, so
network-online.target is reached well before there is a route
off-site. Gate the service on wan-online.target there, following the
same wantedBy + partOf idiom as ipsec, which also re-runs the fetch
whenever the link returns.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 23:21:31 +01:00
jackos1998andClaude Opus 5 41ada3fa60 ci/installer: Switch to gitea-release-action
`release-action` is archived; its repository points at
`gitea-release-action` as the replacement. The inputs were renamed
(`api_key` -> `token`, `title` -> `name`).

The new action is a Node one rather than Go, so the Go setup step
kept in the previous commit is no longer needed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 23:17:25 +01:00
jackos1998andClaude Opus 5 dcf79577ca nixos/git: Buffer uploads on the state volume
Gitea writes uploaded release assets to a temp file before storing
them. That landed in `/tmp`, which is on the 2G tmpfs root, so
uploading the installer ISO failed with:

  ParseMultipartForm [E] ... write /tmp/multipart-...: no space
  left on device

Point the service's `TMPDIR` at the state volume, which has room.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 23:17:21 +01:00
4 changed files with 33 additions and 9 deletions
+3 -7
View File
@@ -10,10 +10,6 @@ jobs:
runs-on: ubuntu-26.04 runs-on: ubuntu-26.04
steps: steps:
- uses: actions/checkout@v6 - uses: actions/checkout@v6
- name: Set up Go
uses: https://github.com/actions/setup-go@v4
with:
go-version: '>=1.20.1'
- uses: DeterminateSystems/determinate-nix-action@v3 - uses: DeterminateSystems/determinate-nix-action@v3
with: with:
# Gitea will supply a token in GITHUB_TOKEN, which this action passes to # Gitea will supply a token in GITHUB_TOKEN, which this action passes to
@@ -46,10 +42,10 @@ jobs:
jackos-installer-netboot-${{ steps.setup.outputs.short_rev }}.tar.zst jackos-installer-netboot-${{ steps.setup.outputs.short_rev }}.tar.zst
- name: Create release - name: Create release
uses: https://gitea.com/actions/release-action@main uses: https://gitea.com/actions/gitea-release-action@main
with: with:
title: Latest installer name: Latest installer
api_key: '${{ secrets.RELEASE_TOKEN }}' token: '${{ secrets.RELEASE_TOKEN }}'
files: | files: |
jackos-installer-${{ steps.setup.outputs.short_rev }}.iso jackos-installer-${{ steps.setup.outputs.short_rev }}.iso
jackos-installer-netboot-${{ steps.setup.outputs.short_rev }}.tar.zst jackos-installer-netboot-${{ steps.setup.outputs.short_rev }}.tar.zst
+10
View File
@@ -43,9 +43,19 @@ in
(umask 027; gitea_extra_setup) (umask 027; gitea_extra_setup)
''; '';
# Uploaded release assets are buffered through a temp file before being stored.
# The default /tmp is on the small tmpfs root, so keep them on the state volume.
environment.TMPDIR = "${config.services.gitea.stateDir}/tmp";
} }
]; ];
}; };
tmpfiles.settings."10-gitea-tmp"."${config.services.gitea.stateDir}/tmp".d = {
user = config.services.gitea.user;
group = config.services.gitea.group;
mode = "0700";
};
}; };
services = { services = {
+9
View File
@@ -145,6 +145,15 @@
}; };
}; };
# networkd's wait-online knows nothing about the pppd-owned `wan` interface, so
# network-online.target is reached long before there's a route off-site. Gate the
# installer fetch on the WAN instead, and retry it whenever the link returns.
systemd.services.netboot-update = {
after = [ "wan-online.target" ];
wantedBy = mkForce [ "wan-online.target" ];
partOf = [ "wan-online.target" ];
};
systemd.network = { systemd.network = {
netdevs = mkMerge [ netdevs = mkMerge [
(mkVLAN "wan-pon-ont" vlans.wan-pon-ont) (mkVLAN "wan-pon-ont" vlans.wan-pon-ont)
+11 -2
View File
@@ -129,7 +129,8 @@ in
services = { services = {
netboot-update = { netboot-update = {
description = "Update netboot images"; description = "Update netboot images";
after = [ "systemd-networkd-wait-online.service" ]; wants = [ "network-online.target" ];
after = [ "network-online.target" ];
serviceConfig.Type = "oneshot"; serviceConfig.Type = "oneshot";
path = with pkgs; [ path = with pkgs; [
coreutils curl jq zstd gnutar coreutils curl jq zstd gnutar
@@ -138,6 +139,10 @@ in
update_nixos() { update_nixos() {
latestShort="$(curl -s https://git.nul.ie/api/v1/repos/dev/nixfiles/tags/installer \ latestShort="$(curl -s https://git.nul.ie/api/v1/repos/dev/nixfiles/tags/installer \
| jq -r .commit.sha | cut -c -7)" | jq -r .commit.sha | cut -c -7)"
if [ -z "$latestShort" ] || [ "$latestShort" = "null" ]; then
echo "Couldn't resolve the installer tag to a commit" >&2
return 1
fi
if [ -f nixos-installer/tag.txt ] && [ "$(< nixos-installer/tag.txt)" = "$latestShort" ]; then if [ -f nixos-installer/tag.txt ] && [ "$(< nixos-installer/tag.txt)" = "$latestShort" ]; then
echo "NixOS installer is up to date" echo "NixOS installer is up to date"
return return
@@ -148,6 +153,10 @@ in
fname="jackos-installer-netboot-$latestShort.tar.zst" fname="jackos-installer-netboot-$latestShort.tar.zst"
downloadUrl="$(curl -s https://git.nul.ie/api/v1/repos/dev/nixfiles/releases/tags/installer | \ downloadUrl="$(curl -s https://git.nul.ie/api/v1/repos/dev/nixfiles/releases/tags/installer | \
jq -r ".assets[] | select(.name == \"$fname\").browser_download_url")" jq -r ".assets[] | select(.name == \"$fname\").browser_download_url")"
if [ -z "$downloadUrl" ]; then
echo "No release asset $fname; did the installer build succeed?" >&2
return 1
fi
curl -Lo /tmp/nixos-installer-netboot.tar.zst "$downloadUrl" curl -Lo /tmp/nixos-installer-netboot.tar.zst "$downloadUrl"
tar -C nixos-installer --zstd -xf /tmp/nixos-installer-netboot.tar.zst tar -C nixos-installer --zstd -xf /tmp/nixos-installer-netboot.tar.zst
truncate -s "${cfg.server.installer.storeSize}" nixos-installer/rootfs.ext4 truncate -s "${cfg.server.installer.storeSize}" nixos-installer/rootfs.ext4
@@ -163,7 +172,7 @@ in
update_nixos update_nixos
''; '';
startAt = "06:00"; startAt = "06:00";
wantedBy = [ "network-online.target" ]; wantedBy = [ "multi-user.target" ];
}; };
nbd-server = { nbd-server = {