From d4721d1d2254fbc16d762851b358143b7fa1c184 Mon Sep 17 00:00:00 2001 From: moons Date: Thu, 3 Sep 2026 04:32:47 +0900 Subject: [PATCH] nix builder --- hosts/nix-builder/harmonia.nix | 37 +++++++++++++++++++ .../workload/deploy-rs-target/meta.nix | 8 ++++ modules/users/nixdeploy/nixos.nix | 28 ++++++++++++++ 3 files changed, 73 insertions(+) create mode 100644 hosts/nix-builder/harmonia.nix create mode 100644 modules/profiles/workload/deploy-rs-target/meta.nix create mode 100644 modules/users/nixdeploy/nixos.nix diff --git a/hosts/nix-builder/harmonia.nix b/hosts/nix-builder/harmonia.nix new file mode 100644 index 0000000..fef54bc --- /dev/null +++ b/hosts/nix-builder/harmonia.nix @@ -0,0 +1,37 @@ +_: + +{ + sops.secrets.nix-cache-signing-key = { + mode = "0400"; + }; + + nix.settings = { + build-dir = "/var/lib/nix-build"; + + secret-key-files = [ + "/var/lib/secrets/nix-cache-signing-key" + ]; + + auto-optimise-store = false; + keep-outputs = false; + keep-derivations = true; + }; + + services.harmonia.cache = { + enable = true; + + signKeyPaths = [ + "/var/lib/secrets/nix-cache-signing-key" + ]; + + settings = { + bind = "[::]:5000"; + priority = 30; + workers = 4; + }; + }; + + networking.firewall.allowedTCPPorts = [ + 5000 + ]; +} diff --git a/modules/profiles/workload/deploy-rs-target/meta.nix b/modules/profiles/workload/deploy-rs-target/meta.nix new file mode 100644 index 0000000..8506ffc --- /dev/null +++ b/modules/profiles/workload/deploy-rs-target/meta.nix @@ -0,0 +1,8 @@ +{ + description = "NixOS deploy-rs deployment target"; + + includes = [ + "services.openssh" + "users.nixdeploy" + ]; +} diff --git a/modules/users/nixdeploy/nixos.nix b/modules/users/nixdeploy/nixos.nix new file mode 100644 index 0000000..a783473 --- /dev/null +++ b/modules/users/nixdeploy/nixos.nix @@ -0,0 +1,28 @@ +{ pkgs, ... }: +{ + users.groups.nixdeploy = { }; + + users.users.nixdeploy = { + isSystemUser = true; + group = "nixdeploy"; + home = "/var/lib/nixdeploy"; + createHome = true; + shell = pkgs.bashInteractive; + openssh.authorizedKeys.keys = [ + "restrict ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFPg1aw0qXBmrQe6lzBwutX5t9Sxg2OeVN/homjqU6Ja moons@nix-builder" + ]; + }; + + security.sudo.extraRules = [ + { + users = [ "nixdeploy" ]; + + commands = [ + { + command = "ALL"; + options = [ "NOPASSWD" ]; + } + ]; + } + ]; +}