diff --git a/docs/install-simple.md b/docs/install-simple.md new file mode 100644 index 0000000..77cc00e --- /dev/null +++ b/docs/install-simple.md @@ -0,0 +1,153 @@ +# NixOSインストール手順(SOPSなし・ディスク暗号化なし) + +この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を +使用しないホスト向けの、独立したインストール手順である。 + +SOPSとディスク暗号化を使用する場合は、[暗号化ありの手順](install.md)を参照。 + +## 事前準備 + +1. [ISOビルド](iso-build.md)を参照してISOを作成 +2. USBに書き込んで対象マシンでブート + +## ネットワーク接続 + +### 有線LAN + +DHCPで自動設定される。 + +### Wi-Fi(有線が使えない場合) + +```bash +nmcli device wifi connect --ask +``` + +## SSH接続 + +コンソールに表示されたIPアドレスに接続: + +```bash +ssh root@ +``` + +## インストール手順 + +### 1. dotfilesのクローン + +```bash +git clone git@github.com:moons-14/dotfiles.git ~/dotfiles +cd ~/dotfiles +``` + +### 2. ホスト設定の作成 + +`hosts//nixos.nix`を作成し、`hosts/default.nix`にホストと使用する +プロファイルを登録する。ホスト固有の設定だけをホストディレクトリに置き、 +再利用可能な設定は適切なunitまたはprofileに置く。 + +### 3. インストール先ディスクの確認 + +```bash +lsblk -o NAME,PATH,SIZE,MODEL,SERIAL,TYPE,FSTYPE,MOUNTPOINTS +ls -l /dev/disk/by-id/ +``` + +以降の操作では指定したディスクの既存データが消去される。対象を必ず確認し、 +可能であれば`/dev/sda`や`/dev/nvme0n1`ではなく、安定した +`/dev/disk/by-id/...`パスを使用する。 + +### 4. Disko設定の作成 + +`hosts//disko.nix`を作成する: + +```nix +_: +{ + disko.enableConfig = true; + + disko.devices.disk.main = { + type = "disk"; + device = "/dev/disk/by-id/"; + content = { + type = "gpt"; + partitions = { + ESP = { + size = "512M"; + type = "EF00"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + }; + }; + root = { + size = "100%"; + content = { + type = "filesystem"; + format = "ext4"; + mountpoint = "/"; + }; + }; + }; + }; + }; +} +``` + +``を手順3で確認した実際のディスクIDに置き換える。指定した +ディスクの既存データは消去される。 + +### 5. パーティション作成とマウント + +```bash +disko --mode destroy,format,mount hosts//disko.nix +``` + +Diskoの実行結果を確認する: + +```bash +findmnt /mnt +findmnt /mnt/boot +``` + +### 6. ハードウェア設定の生成 + +```bash +nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \ + > ~/dotfiles/hosts//hardware-configuration.nix +``` + +### 7. ホストモジュールから設定を読み込む + +`hosts//nixos.nix`で、生成したハードウェア設定とDisko設定を読み込む: + +```nix +{ + imports = [ + ./hardware-configuration.nix + ./disko.nix + ]; +} +``` + +### 8. NixOSインストール + +```bash +nixos-install --flake ~/dotfiles# +``` + +SOPSを使用しないため、age鍵の登録、シークレットの再暗号化、SSHホストキーの +事前生成とコピーは不要である。OpenSSHを有効にしたホストでは、SSHホストキーは +通常の初回起動時に生成される。 + +### 9. 再起動 + +```bash +reboot +``` + +## インストール後の確認 + +- 正しいディスクから起動できるか +- `/`と`/boot`が意図したファイルシステムからマウントされているか +- ネットワークと、設定している場合はSSH接続が利用できるか diff --git a/docs/install.md b/docs/install.md index cd5786a..b6608b9 100644 --- a/docs/install.md +++ b/docs/install.md @@ -1,4 +1,10 @@ -# NixOSインストール手順 +# NixOSインストール手順(SOPS・ディスク暗号化あり) + +この手順は、SOPSによるシークレット管理とLUKSによるディスク暗号化を +使用するホスト向けである。 + +どちらも使用しない場合は、 +[SOPSなし・ディスク暗号化なしの手順](install-simple.md)を参照。 ## 事前準備 @@ -83,54 +89,36 @@ sops updatekeys secrets/hosts//*.yaml 新しいホスト用の`hosts//disko.nix`を作成。 -#### シンプル構成(暗号化なし) - -```nix -_: -{ - disko.enableConfig = true; - - disko.devices.disk.main = { - type = "disk"; - device = "/dev/sda"; - content = { - type = "gpt"; - partitions = { - ESP = { - size = "512M"; - type = "EF00"; - content = { - type = "filesystem"; - format = "vfat"; - mountpoint = "/boot"; - }; - }; - root = { - size = "100%"; - content = { - type = "filesystem"; - format = "ext4"; - mountpoint = "/"; - }; - }; - }; - }; - }; -} -``` - -#### LUKS暗号化 + btrfs - -`hosts/x1g13/disko.nix`を参照。 +LUKS暗号化とbtrfsの構成は`hosts/x1g13/disko.nix`を参照。 ### 7. ディスクのパーティション ```bash cd ~/dotfiles -nix run github:nix-community/disko -- --mode disko hosts//disko.nix +disko --mode destroy,format,mount hosts//disko.nix ``` -### 8. ホストキーのコピー +### 8. ハードウェア設定の生成 + +対象マシンのハードウェア設定を生成し、新しいホストのディレクトリへ直接保存: + +```bash +nixos-generate-config --no-filesystems --root /mnt --show-hardware-config \ + > ~/dotfiles/hosts//hardware-configuration.nix +``` + +`hosts//nixos.nix`から生成した設定とDisko設定を読み込む: + +```nix +{ + imports = [ + ./hardware-configuration.nix + ./disko.nix + ]; +} +``` + +### 9. ホストキーのコピー ```bash mkdir -p /mnt/etc/ssh @@ -138,13 +126,13 @@ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ``` -### 9. NixOSインストール +### 10. NixOSインストール ```bash nixos-install --flake ~/dotfiles# ``` -### 10. 再起動 +### 11. 再起動 ```bash reboot diff --git a/docs/iso-build.md b/docs/iso-build.md index 0455312..c4072d8 100644 --- a/docs/iso-build.md +++ b/docs/iso-build.md @@ -70,7 +70,10 @@ ssh root@ root のパスワードログインとキーボード対話認証は無効で、 `hosts/installer/nixos.nix` に登録された公開鍵だけが利用できる。 -以降の作業は [NixOS インストール手順](install.md) を参照する。 +以降の作業は、構成に応じて次の手順を参照する: + +- [SOPSなし・ディスク暗号化なし](install-simple.md) +- [SOPS・ディスク暗号化あり](install.md) ## ISO に含まれる主な設定とツール diff --git a/hosts/installer/nixos.nix b/hosts/installer/nixos.nix index e26cf63..a9fce8e 100644 --- a/hosts/installer/nixos.nix +++ b/hosts/installer/nixos.nix @@ -76,6 +76,12 @@ ║ ║ ║ Installation Workflow: ║ ║ ║ + ║ Choose a guide after cloning: ║ + ║ Simple: docs/install-simple.md ║ + ║ SOPS + LUKS: docs/install.md ║ + ║ ║ + ║ The workflow below is for SOPS + LUKS: ║ + ║ ║ ║ 1. Clone dotfiles: ║ ║ git clone git@github.com:moons-14/dotfiles.git ~/dotfiles║ ║ ║ @@ -103,37 +109,25 @@ ║ # See hosts/x1g13/disko.nix for reference ║ ║ ║ ║ 7. Partition disk with disko: ║ - ║ nix run github:nix-community/disko -- \ ║ - ║ --mode disko hosts//disko.nix ║ + ║ disko --mode destroy,format,mount \ ║ + ║ hosts//disko.nix ║ ║ ║ - ║ 8. Copy host key to installed system: ║ + ║ 8. Generate hardware configuration: ║ + ║ nixos-generate-config --no-filesystems --root /mnt \ ║ + ║ --show-hardware-config > \ ║ + ║ ~/dotfiles/hosts//hardware-configuration.nix ║ + ║ # Import hardware-configuration.nix and disko.nix ║ + ║ # from hosts//nixos.nix ║ + ║ ║ + ║ 9. Copy host key to installed system: ║ ║ mkdir -p /mnt/etc/ssh ║ ║ cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ ║ ║ chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key ║ ║ ║ - ║ 9. Install NixOS: ║ + ║ 10. Install NixOS: ║ ║ nixos-install --flake ~/dotfiles# ║ ║ ║ - ║ Disko Configuration Examples: ║ - ║ ║ - ║ Simple (no encryption): ║ - ║ disko.devices.disk.main = { ║ - ║ type = "disk"; ║ - ║ device = "/dev/sda"; ║ - ║ content = { ║ - ║ type = "gpt"; ║ - ║ partitions = { ║ - ║ ESP = { size = "512M"; type = "EF00"; ║ - ║ content = { type = "filesystem"; ║ - ║ format = "vfat"; mountpoint = "/boot"; }; }; ║ - ║ root = { size = "100%"; ║ - ║ content = { type = "filesystem"; ║ - ║ format = "ext4"; mountpoint = "/"; }; }; ║ - ║ }; ║ - ║ }; ║ - ║ }; ║ - ║ ║ - ║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║ + ║ LUKS + btrfs (see hosts/x1g13/disko.nix): ║ ║ - Use partuuid for device path ║ ║ - Set askPassword = true for LUKS ║ ║ - Configure btrfs subvolumes ║ diff --git a/hosts/ops/disko.nix b/hosts/ops/disko.nix new file mode 100644 index 0000000..e9fe39b --- /dev/null +++ b/hosts/ops/disko.nix @@ -0,0 +1,30 @@ +_: { + disko.enableConfig = true; + + disko.devices.disk.main = { + type = "disk"; + device = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0"; + content = { + type = "gpt"; + partitions = { + ESP = { + size = "512M"; + type = "EF00"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + }; + }; + root = { + size = "100%"; + content = { + type = "filesystem"; + format = "ext4"; + mountpoint = "/"; + }; + }; + }; + }; + }; +} diff --git a/hosts/ops/nixos.nix b/hosts/ops/nixos.nix index aa94860..2657d87 100644 --- a/hosts/ops/nixos.nix +++ b/hosts/ops/nixos.nix @@ -2,5 +2,6 @@ imports = [ ./hardware-configuration.nix ./networking.nix + ./disko.nix ]; }