From 89eeb23d1cd0a944c617e8bf60e372be96dcbd75 Mon Sep 17 00:00:00 2001 From: moons Date: Mon, 27 Jul 2026 18:41:42 +0900 Subject: [PATCH] add docs --- .gitignore | 1 + docs/fingerprint.md | 68 +++++++++++++++++++ docs/install.md | 157 ++++++++++++++++++++++++++++++++++++++++++++ docs/iso-build.md | 26 ++++++++ docs/sops-key.md | 17 +++++ 5 files changed, 269 insertions(+) create mode 100644 docs/fingerprint.md create mode 100644 docs/install.md create mode 100644 docs/iso-build.md create mode 100644 docs/sops-key.md diff --git a/.gitignore b/.gitignore index b261cfc..de6af78 100644 --- a/.gitignore +++ b/.gitignore @@ -4,6 +4,7 @@ !README.md !LICENSE !AGENTS.md +!/docs/ !.github/ !.gitea/ diff --git a/docs/fingerprint.md b/docs/fingerprint.md new file mode 100644 index 0000000..2875af3 --- /dev/null +++ b/docs/fingerprint.md @@ -0,0 +1,68 @@ +# Fingerprint Commands + +This note covers the basic `fprintd` commands used by the fingerprint module. + +## Enroll a new fingerprint + +Register a fingerprint for the current user: + +```sh +fprintd-enroll $USER +``` + +To enroll a specific finger, pass the finger name: + +```sh +fprintd-enroll -f right-index-finger $USER +``` + +Common finger names include: + +- `left-thumb` +- `left-index-finger` +- `right-thumb` +- `right-index-finger` + +Follow the prompts and swipe or touch the sensor until enrollment completes. + +## List enrolled fingerprints + +Show fingerprints registered for the current user: + +```sh +fprintd-list $USER +``` + +You can also list fingerprints for another user: + +```sh +fprintd-list +``` + +## Delete fingerprints + +Delete one enrolled fingerprint for the current user: + +```sh +fprintd-delete +``` + +Delete all enrolled fingerprints for the current user: + +```sh +fprintd-delete $USER +``` + +Delete fingerprints for another user: + +```sh +fprintd-delete +``` + +## Verify authentication + +Test fingerprint authentication for the current user: + +```sh +fprintd-verify +``` diff --git a/docs/install.md b/docs/install.md new file mode 100644 index 0000000..cd5786a --- /dev/null +++ b/docs/install.md @@ -0,0 +1,157 @@ +# NixOSインストール手順 + +## 事前準備 + +1. [ISOビルド](iso-build.md)を参照してISOを作成 +2. USBに書き込んで対象マシンでブート + +## ネットワーク接続 + +### 有線LAN + +DHCPで自動設定される。 + +### WiFi(有線が使えない場合) + +```bash +nmcli device wifi connect --ask +``` + +## SSH接続 + +コンソールに表示されたIPアドレスに接続: + +```bash +ssh root@ +``` + +## インストール手順 + +### 1. dotfilesのクローン + +```bash +git clone git@github.com:moons-14/dotfiles.git ~/dotfiles +``` + +### 2. SSHホストキーの生成 + +新しいホスト用のSSHホストキーを生成: + +```bash +ssh-keygen -t ed25519 -f /tmp/ssh_host_ed25519_key -N "" +``` + +### 3. age公開鍵の取得 + +SSHホストキーからage公開鍵を取得: + +```bash +ssh-to-age -i /tmp/ssh_host_ed25519_key.pub +``` + +出力されたage公開鍵をコピー。 + +### 4. .sops.yamlの編集 + +```bash +cd ~/dotfiles +vim .sops.yaml +``` + +以下を追加: + +```yaml +keys: + - &host_ + +creation_rules: + - path_regex: ^secrets/hosts//[^/]+\.ya?ml$ + key_groups: + - age: + - *admin_yubikey1 + - *host_ +``` + +### 5. シークレットの再暗号化 + +```bash +sops updatekeys secrets/common/system.yaml +sops updatekeys secrets/hosts//*.yaml +``` + +### 6. disko設定の作成 + +新しいホスト用の`hosts//disko.nix`を作成。 + +#### シンプル構成(暗号化なし) + +```nix +_: +{ + disko.enableConfig = true; + + disko.devices.disk.main = { + type = "disk"; + device = "/dev/sda"; + content = { + type = "gpt"; + partitions = { + ESP = { + size = "512M"; + type = "EF00"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + }; + }; + root = { + size = "100%"; + content = { + type = "filesystem"; + format = "ext4"; + mountpoint = "/"; + }; + }; + }; + }; + }; +} +``` + +#### LUKS暗号化 + btrfs + +`hosts/x1g13/disko.nix`を参照。 + +### 7. ディスクのパーティション + +```bash +cd ~/dotfiles +nix run github:nix-community/disko -- --mode disko hosts//disko.nix +``` + +### 8. ホストキーのコピー + +```bash +mkdir -p /mnt/etc/ssh +cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/ +chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key +``` + +### 9. NixOSインストール + +```bash +nixos-install --flake ~/dotfiles# +``` + +### 10. 再起動 + +```bash +reboot +``` + +## インストール後の確認 + +- SSHでログインできるか +- sopsシークレットが復号できるか +- diskoでパーティションが正しく設定されているか diff --git a/docs/iso-build.md b/docs/iso-build.md new file mode 100644 index 0000000..d62af15 --- /dev/null +++ b/docs/iso-build.md @@ -0,0 +1,26 @@ +# カスタムISOビルド + +## ビルド + +```bash +nix build .#nixosConfigurations.installer.config.system.build.isoImage +``` + +## ISO書き込み + +```bash +# USBデバイスの確認 +lsblk + +# 書き込み(/dev/sdXは実際のデバイスに置き換える) +sudo dd if=./result/nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress +sync +``` + +## ISOの特徴 + +- SSH鍵認証でrootログイン可能 +- 有線LANはDHCPで自動設定 +- WiFiは`nmcli`で手動設定可能 +- disko/sops/ageなどのツールを内蔵 +- ブート時にIPアドレスとヘルプを表示 diff --git a/docs/sops-key.md b/docs/sops-key.md new file mode 100644 index 0000000..8dbc9d3 --- /dev/null +++ b/docs/sops-key.md @@ -0,0 +1,17 @@ +# Generate Sops key file + +```bash +mkdir -p ~/.config/sops/age +chmod 700 ~/.config/sops/age + +age-plugin-yubikey --identity --slot 1 \ + > ~/.config/sops/age/yubikey-identity.txt + +chmod 600 ~/.config/sops/age/yubikey-identity.txt +``` + +## Edit sops file + +```bash +sops secrets/common/system.yaml +```