mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-07 07:54:08 +09:00
add docs
This commit is contained in:
@@ -4,6 +4,7 @@
|
|||||||
!README.md
|
!README.md
|
||||||
!LICENSE
|
!LICENSE
|
||||||
!AGENTS.md
|
!AGENTS.md
|
||||||
|
!/docs/
|
||||||
|
|
||||||
!.github/
|
!.github/
|
||||||
!.gitea/
|
!.gitea/
|
||||||
|
|||||||
@@ -0,0 +1,68 @@
|
|||||||
|
# Fingerprint Commands
|
||||||
|
|
||||||
|
This note covers the basic `fprintd` commands used by the fingerprint module.
|
||||||
|
|
||||||
|
## Enroll a new fingerprint
|
||||||
|
|
||||||
|
Register a fingerprint for the current user:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
fprintd-enroll $USER
|
||||||
|
```
|
||||||
|
|
||||||
|
To enroll a specific finger, pass the finger name:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
fprintd-enroll -f right-index-finger $USER
|
||||||
|
```
|
||||||
|
|
||||||
|
Common finger names include:
|
||||||
|
|
||||||
|
- `left-thumb`
|
||||||
|
- `left-index-finger`
|
||||||
|
- `right-thumb`
|
||||||
|
- `right-index-finger`
|
||||||
|
|
||||||
|
Follow the prompts and swipe or touch the sensor until enrollment completes.
|
||||||
|
|
||||||
|
## List enrolled fingerprints
|
||||||
|
|
||||||
|
Show fingerprints registered for the current user:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
fprintd-list $USER
|
||||||
|
```
|
||||||
|
|
||||||
|
You can also list fingerprints for another user:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
fprintd-list <username>
|
||||||
|
```
|
||||||
|
|
||||||
|
## Delete fingerprints
|
||||||
|
|
||||||
|
Delete one enrolled fingerprint for the current user:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
fprintd-delete
|
||||||
|
```
|
||||||
|
|
||||||
|
Delete all enrolled fingerprints for the current user:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
fprintd-delete $USER
|
||||||
|
```
|
||||||
|
|
||||||
|
Delete fingerprints for another user:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
fprintd-delete <username>
|
||||||
|
```
|
||||||
|
|
||||||
|
## Verify authentication
|
||||||
|
|
||||||
|
Test fingerprint authentication for the current user:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
fprintd-verify
|
||||||
|
```
|
||||||
+157
@@ -0,0 +1,157 @@
|
|||||||
|
# NixOSインストール手順
|
||||||
|
|
||||||
|
## 事前準備
|
||||||
|
|
||||||
|
1. [ISOビルド](iso-build.md)を参照してISOを作成
|
||||||
|
2. USBに書き込んで対象マシンでブート
|
||||||
|
|
||||||
|
## ネットワーク接続
|
||||||
|
|
||||||
|
### 有線LAN
|
||||||
|
|
||||||
|
DHCPで自動設定される。
|
||||||
|
|
||||||
|
### WiFi(有線が使えない場合)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nmcli device wifi connect <SSID> --ask
|
||||||
|
```
|
||||||
|
|
||||||
|
## SSH接続
|
||||||
|
|
||||||
|
コンソールに表示されたIPアドレスに接続:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh root@<ip-address>
|
||||||
|
```
|
||||||
|
|
||||||
|
## インストール手順
|
||||||
|
|
||||||
|
### 1. dotfilesのクローン
|
||||||
|
|
||||||
|
```bash
|
||||||
|
git clone [email protected]:moons-14/dotfiles.git ~/dotfiles
|
||||||
|
```
|
||||||
|
|
||||||
|
### 2. SSHホストキーの生成
|
||||||
|
|
||||||
|
新しいホスト用のSSHホストキーを生成:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh-keygen -t ed25519 -f /tmp/ssh_host_ed25519_key -N ""
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3. age公開鍵の取得
|
||||||
|
|
||||||
|
SSHホストキーからage公開鍵を取得:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ssh-to-age -i /tmp/ssh_host_ed25519_key.pub
|
||||||
|
```
|
||||||
|
|
||||||
|
出力されたage公開鍵をコピー。
|
||||||
|
|
||||||
|
### 4. .sops.yamlの編集
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd ~/dotfiles
|
||||||
|
vim .sops.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
以下を追加:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
keys:
|
||||||
|
- &host_<hostname> <age公開鍵>
|
||||||
|
|
||||||
|
creation_rules:
|
||||||
|
- path_regex: ^secrets/hosts/<hostname>/[^/]+\.ya?ml$
|
||||||
|
key_groups:
|
||||||
|
- age:
|
||||||
|
- *admin_yubikey1
|
||||||
|
- *host_<hostname>
|
||||||
|
```
|
||||||
|
|
||||||
|
### 5. シークレットの再暗号化
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sops updatekeys secrets/common/system.yaml
|
||||||
|
sops updatekeys secrets/hosts/<hostname>/*.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
### 6. disko設定の作成
|
||||||
|
|
||||||
|
新しいホスト用の`hosts/<hostname>/disko.nix`を作成。
|
||||||
|
|
||||||
|
#### シンプル構成(暗号化なし)
|
||||||
|
|
||||||
|
```nix
|
||||||
|
_:
|
||||||
|
{
|
||||||
|
disko.enableConfig = true;
|
||||||
|
|
||||||
|
disko.devices.disk.main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/sda";
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
root = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "ext4";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
#### LUKS暗号化 + btrfs
|
||||||
|
|
||||||
|
`hosts/x1g13/disko.nix`を参照。
|
||||||
|
|
||||||
|
### 7. ディスクのパーティション
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd ~/dotfiles
|
||||||
|
nix run github:nix-community/disko -- --mode disko hosts/<hostname>/disko.nix
|
||||||
|
```
|
||||||
|
|
||||||
|
### 8. ホストキーのコピー
|
||||||
|
|
||||||
|
```bash
|
||||||
|
mkdir -p /mnt/etc/ssh
|
||||||
|
cp /tmp/ssh_host_ed25519_key* /mnt/etc/ssh/
|
||||||
|
chmod 600 /mnt/etc/ssh/ssh_host_ed25519_key
|
||||||
|
```
|
||||||
|
|
||||||
|
### 9. NixOSインストール
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nixos-install --flake ~/dotfiles#<hostname>
|
||||||
|
```
|
||||||
|
|
||||||
|
### 10. 再起動
|
||||||
|
|
||||||
|
```bash
|
||||||
|
reboot
|
||||||
|
```
|
||||||
|
|
||||||
|
## インストール後の確認
|
||||||
|
|
||||||
|
- SSHでログインできるか
|
||||||
|
- sopsシークレットが復号できるか
|
||||||
|
- diskoでパーティションが正しく設定されているか
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
# カスタムISOビルド
|
||||||
|
|
||||||
|
## ビルド
|
||||||
|
|
||||||
|
```bash
|
||||||
|
nix build .#nixosConfigurations.installer.config.system.build.isoImage
|
||||||
|
```
|
||||||
|
|
||||||
|
## ISO書き込み
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# USBデバイスの確認
|
||||||
|
lsblk
|
||||||
|
|
||||||
|
# 書き込み(/dev/sdXは実際のデバイスに置き換える)
|
||||||
|
sudo dd if=./result/nixos-minimal-*.iso of=/dev/sdX bs=4M status=progress
|
||||||
|
sync
|
||||||
|
```
|
||||||
|
|
||||||
|
## ISOの特徴
|
||||||
|
|
||||||
|
- SSH鍵認証でrootログイン可能
|
||||||
|
- 有線LANはDHCPで自動設定
|
||||||
|
- WiFiは`nmcli`で手動設定可能
|
||||||
|
- disko/sops/ageなどのツールを内蔵
|
||||||
|
- ブート時にIPアドレスとヘルプを表示
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Generate Sops key file
|
||||||
|
|
||||||
|
```bash
|
||||||
|
mkdir -p ~/.config/sops/age
|
||||||
|
chmod 700 ~/.config/sops/age
|
||||||
|
|
||||||
|
age-plugin-yubikey --identity --slot 1 \
|
||||||
|
> ~/.config/sops/age/yubikey-identity.txt
|
||||||
|
|
||||||
|
chmod 600 ~/.config/sops/age/yubikey-identity.txt
|
||||||
|
```
|
||||||
|
|
||||||
|
## Edit sops file
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sops secrets/common/system.yaml
|
||||||
|
```
|
||||||
Reference in New Issue
Block a user