05918ec2ce
The ISO target had drifted from nixpkgs and no longer evaluated: `iso-image.nix` now defines `image.baseName` itself, which conflicts with ours, so force it. Drop the `boot.initrd.systemd.enable = false` override from the `asISO` build target. The missing `/dev/root` it worked around is no longer an issue, and scripted initrd is deprecated for removal in 26.11. Replace the wpa_supplicant stanza, which upstream's `installation-device.nix` no longer carries, with NetworkManager. Keep it out of `multi-user.target` so nothing network-related starts until asked; NetworkManager enables wpa_supplicant as its backend, which is D-Bus activated on demand. Pick up three more bits from that profile: the installer `variant_id`, the pstore drop-in that stops an install evacuating the target's persistent entries, and the mdadm `PROGRAM` stub that silences the unset-mail warning. Built and booted as an ISO to confirm. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2.3 KiB
2.3 KiB
installer
The custom NixOS installer image used to bootstrap new boxes.
- Source:
nixos/installer.nix - Host: — (a build target, not a deployed box)
Role
- Defines
nixos.systems.installer, a minimal server system rendered as a bootable ISO viaconfig.my.buildAs.iso(my.asISO); the same base can also be built as a kexec or netboot tree. - Build it with the devshell commands:
build-iso installer(orbuild-kexec installer/build-netboot installer). Theupdate-installercommand force-tagsinstallerto trigger a release rebuild in CI.
Image contents
- Broad hardware support (
my.build.allHardwarepulls in the nixpkgs all-hardware profile); EFI- and USB-bootable, zstd-compressed squashfs. Volume IDjackos-<release>-<arch>, menu label "/dev/player0 Installer", image base namejackos-installer. - Root SSH with the deploy key authorized (
PermitRootLogin prohibit-password); a randominstaller-<hex>hostname is set at boot. INSTALL_ROOT=/mntin the session environment, plus ashow-hw-configalias wrappingnixos-generate-config --show-hardware-config --root $INSTALL_ROOT.- NixOS documentation enabled, NetworkManager available but not started at boot (run
systemctl start NetworkManager, thennmtui), GC and memory-overcommit tuning for low-memory targets, LVM thin and NFS support. - Identifies itself as
VARIANT_ID=installerin/etc/os-release, and leaves the target's persistent pstore entries alone (Unlink=no) so an install doesn't evacuate them. - No regular user (
my.user.enable = false), no tmpfs-root management, no NAT, and not a deploy target (my.deploy.enable = false).
Installing a box
The devshell's installer commands (devshell/install.nix) drive
an install over SSH against a booted installer reachable at $INSTALLER:
installer-shell— get a shell on the installer.do-install <system>— builds the system's toplevel,nix copys the closure to the installer's$INSTALL_ROOTremote store, sets the system profile, touches/etc/NIXOS, and runsswitch-to-configuration bootwithNIXOS_INSTALL_BOOTLOADER=1(skip the bootloader with--no-bootloader, skip substitution with--no-substitute).