Initial commit
This commit is contained in:
commit
80acbe079c
16
.editorconfig
Normal file
16
.editorconfig
Normal file
@ -0,0 +1,16 @@
|
||||
# top-most EditorConfig file
|
||||
root = true
|
||||
|
||||
# Unix-style newlines with a newline ending every file
|
||||
[*]
|
||||
end_of_line = lf
|
||||
insert_final_newline = true
|
||||
|
||||
# 2 space indentation
|
||||
[*.nix]
|
||||
indent_style = space
|
||||
indent_size = 2
|
||||
|
||||
[Makefile]
|
||||
indent_style = tab
|
||||
|
||||
1
.gitignore
vendored
Normal file
1
.gitignore
vendored
Normal file
@ -0,0 +1 @@
|
||||
result
|
||||
19
Makefile
Normal file
19
Makefile
Normal file
@ -0,0 +1,19 @@
|
||||
# Special variables
|
||||
.DEFAULT_GOAL := help # Set default target to run
|
||||
.SILENT: # Disable printing recipes at runtime
|
||||
.ONESHELL: # Run target recipes in one shell invocation
|
||||
.PHONY: build-image \ # Phony targets
|
||||
clean \
|
||||
help
|
||||
|
||||
help: ## Shows this help prompt.
|
||||
egrep -h '\s##\s' $(MAKEFILE_LIST) \
|
||||
| sort \
|
||||
| awk 'BEGIN {FS = ":.*?## "}; {printf "\033[36m%-20s\033[0m %s\n", $$1, $$2}'
|
||||
|
||||
clean:
|
||||
rm -f result
|
||||
|
||||
build-image: clean ## Builds Linode campatible NixOS disk image.
|
||||
nix build ".#nixosConfigurations.linode-image.config.system.build.raw"
|
||||
|
||||
25
README.md
Normal file
25
README.md
Normal file
@ -0,0 +1,25 @@
|
||||
# base-nixos-linode
|
||||
|
||||
A repository that builds a base NixOS Linode image. The make build
|
||||
tool is used to build the image and also to manage a Linode instance.
|
||||
A dotenv file is provided and used to define values to a specific
|
||||
Linode instance, such as the IP address and admin account name.
|
||||
|
||||
## Basics
|
||||
|
||||
All repository commands can be found simply by running the make command,
|
||||
like this: ```make```
|
||||
|
||||
Help text should be displayed on the screen with available commands and
|
||||
what they do.
|
||||
|
||||
## Build Instructions
|
||||
|
||||
Run the following command: ```make build-image```
|
||||
|
||||
## Managing a Linode Instance
|
||||
|
||||
Two make targets are defined to manage a Linode instance: nixos-switch
|
||||
and ssh. Run nixos-switch to build a Linode compatible NixOS image
|
||||
from the configuration in /nixos-config.
|
||||
|
||||
20
build-image.nix
Normal file
20
build-image.nix
Normal file
@ -0,0 +1,20 @@
|
||||
{ config, lib, modulesPath, pkgs, ... }:
|
||||
|
||||
{
|
||||
imports = [
|
||||
./nixos-config
|
||||
];
|
||||
|
||||
system.build.raw = import "${modulesPath}/../lib/make-disk-image.nix" {
|
||||
inherit config lib pkgs;
|
||||
name = "linode-image";
|
||||
format = "raw";
|
||||
partitionTableType = "none";
|
||||
postVM =
|
||||
''
|
||||
${pkgs.gzip}/bin/gzip -6 -c -- $diskImage > \
|
||||
$out/linode-image.img.gz
|
||||
rm $diskImage
|
||||
'';
|
||||
};
|
||||
}
|
||||
27
flake.lock
generated
Normal file
27
flake.lock
generated
Normal file
@ -0,0 +1,27 @@
|
||||
{
|
||||
"nodes": {
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1735264675,
|
||||
"narHash": "sha256-MgdXpeX2GuJbtlBrH9EdsUeWl/yXEubyvxM1G+yO4Ak=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "d49da4c08359e3c39c4e27c74ac7ac9b70085966",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-24.11",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"root": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs"
|
||||
}
|
||||
}
|
||||
},
|
||||
"root": "root",
|
||||
"version": 7
|
||||
}
|
||||
18
flake.nix
Normal file
18
flake.nix
Normal file
@ -0,0 +1,18 @@
|
||||
{
|
||||
description = "A base Linode NixOS image";
|
||||
|
||||
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-24.11";
|
||||
|
||||
outputs = { self, nixpkgs }: {
|
||||
nixosConfigurations.linode-image = nixpkgs.lib.nixosSystem {
|
||||
system = "x86_64-linux";
|
||||
modules = [ ./build-image.nix ];
|
||||
specialArgs = {
|
||||
domain = "linode-domain";
|
||||
hostname = "linode-hostname";
|
||||
};
|
||||
};
|
||||
|
||||
nixosModules.default = ./nixos-config;
|
||||
};
|
||||
}
|
||||
16
nixos-config/default.nix
Normal file
16
nixos-config/default.nix
Normal file
@ -0,0 +1,16 @@
|
||||
{ modulesPath, ... }:
|
||||
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/profiles/qemu-guest.nix")
|
||||
|
||||
./hardware
|
||||
./services
|
||||
|
||||
./nix.nix
|
||||
./state-version.nix
|
||||
./system-packages.nix
|
||||
./timezone.nix
|
||||
];
|
||||
}
|
||||
|
||||
39
nixos-config/hardware/boot.nix
Normal file
39
nixos-config/hardware/boot.nix
Normal file
@ -0,0 +1,39 @@
|
||||
{ lib, ... }:
|
||||
|
||||
{
|
||||
boot = {
|
||||
# Enable LISH and Linode Booting w/ GRUB
|
||||
loader = {
|
||||
# Increase Timeout to Allow LISH Connection
|
||||
# NOTE: The image generator tries to set a timeout of 0, so we must force
|
||||
timeout = lib.mkDefault 10;
|
||||
|
||||
grub = {
|
||||
enable = true;
|
||||
forceInstall = true;
|
||||
device = "nodev";
|
||||
fsIdentifier = "label";
|
||||
|
||||
# Allow serial connection for GRUB to be able to use LISH
|
||||
extraConfig = ''
|
||||
serial --speed=19200 --unit=0 --word=8 --parity=no --stop=1;
|
||||
terminal_input serial;
|
||||
terminal_output serial
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
# Add Required Kernel Modules
|
||||
# NOTE: These are not documented in the install guide
|
||||
initrd.availableKernelModules = [
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"ahci"
|
||||
"sd_mod"
|
||||
];
|
||||
|
||||
# Set Up LISH Serial Connection
|
||||
kernelParams = [ "console=ttyS0,19200n8" ];
|
||||
kernelModules = [ "virtio_net" ];
|
||||
};
|
||||
}
|
||||
3
nixos-config/hardware/cpu.nix
Normal file
3
nixos-config/hardware/cpu.nix
Normal file
@ -0,0 +1,3 @@
|
||||
{
|
||||
hardware.cpu.amd.updateMicrocode = true;
|
||||
}
|
||||
10
nixos-config/hardware/default.nix
Normal file
10
nixos-config/hardware/default.nix
Normal file
@ -0,0 +1,10 @@
|
||||
{
|
||||
imports = [
|
||||
./boot.nix
|
||||
./cpu.nix
|
||||
./file-systems.nix
|
||||
./networking.nix
|
||||
./swap-devices.nix
|
||||
];
|
||||
}
|
||||
|
||||
9
nixos-config/hardware/file-systems.nix
Normal file
9
nixos-config/hardware/file-systems.nix
Normal file
@ -0,0 +1,9 @@
|
||||
{
|
||||
fileSystems = {
|
||||
"/" = {
|
||||
device = "/dev/sda";
|
||||
fsType = "ext4";
|
||||
autoResize = true;
|
||||
};
|
||||
};
|
||||
}
|
||||
26
nixos-config/hardware/networking.nix
Normal file
26
nixos-config/hardware/networking.nix
Normal file
@ -0,0 +1,26 @@
|
||||
{ lib
|
||||
, domain ? "linode-domain"
|
||||
, hostname ? "linode-hostname"
|
||||
, ... }:
|
||||
|
||||
{
|
||||
networking = {
|
||||
useDHCP = lib.mkForce false;
|
||||
usePredictableInterfaceNames = false;
|
||||
|
||||
interfaces.eth0 = {
|
||||
useDHCP = true;
|
||||
|
||||
# Linode expects IPv6 privacy extensions to be disabled, so disable them
|
||||
# See: https://www.linode.com/docs/guides/manual-network-configuration/#static-vs-dynamic-addressing
|
||||
tempAddress = "disabled";
|
||||
};
|
||||
|
||||
domain = domain;
|
||||
hostName = hostname;
|
||||
|
||||
firewall = {
|
||||
enable = true;
|
||||
};
|
||||
};
|
||||
}
|
||||
3
nixos-config/hardware/swap-devices.nix
Normal file
3
nixos-config/hardware/swap-devices.nix
Normal file
@ -0,0 +1,3 @@
|
||||
{
|
||||
swapDevices = [ { device = "/dev/sdb"; } ];
|
||||
}
|
||||
15
nixos-config/nix.nix
Normal file
15
nixos-config/nix.nix
Normal file
@ -0,0 +1,15 @@
|
||||
{
|
||||
nix = {
|
||||
optimise = {
|
||||
automatic = true;
|
||||
dates = [ "weekly" ];
|
||||
};
|
||||
|
||||
|
||||
gc = {
|
||||
automatic = true;
|
||||
options = "--delete-older-than 7d";
|
||||
dates = "weekly";
|
||||
};
|
||||
};
|
||||
}
|
||||
5
nixos-config/services/default.nix
Normal file
5
nixos-config/services/default.nix
Normal file
@ -0,0 +1,5 @@
|
||||
{
|
||||
imports = [
|
||||
./openssh.nix
|
||||
];
|
||||
}
|
||||
12
nixos-config/services/openssh.nix
Normal file
12
nixos-config/services/openssh.nix
Normal file
@ -0,0 +1,12 @@
|
||||
{
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
openFirewall = true;
|
||||
|
||||
settings = {
|
||||
PermitRootLogin = "prohibit-password";
|
||||
KbdInteractiveAuthentication = false;
|
||||
PasswordAuthentication = false;
|
||||
};
|
||||
};
|
||||
}
|
||||
3
nixos-config/state-version.nix
Normal file
3
nixos-config/state-version.nix
Normal file
@ -0,0 +1,3 @@
|
||||
{
|
||||
system.stateVersion = "24.11";
|
||||
}
|
||||
30
nixos-config/system-packages.nix
Normal file
30
nixos-config/system-packages.nix
Normal file
@ -0,0 +1,30 @@
|
||||
{ pkgs, ... }:
|
||||
|
||||
{
|
||||
environment.systemPackages = with pkgs;
|
||||
[
|
||||
# Install diagnostic tools for Linode support
|
||||
inetutils
|
||||
mtr
|
||||
sysstat
|
||||
|
||||
# Base image packages
|
||||
busybox
|
||||
gnumake
|
||||
neovim
|
||||
wget
|
||||
];
|
||||
|
||||
|
||||
programs.zsh =
|
||||
{
|
||||
enable = true;
|
||||
|
||||
vteIntegration = true;
|
||||
|
||||
autosuggestions.enable = true;
|
||||
enableCompletion = true;
|
||||
ohMyZsh.enable = true;
|
||||
syntaxHighlighting.enable = true;
|
||||
};
|
||||
}
|
||||
3
nixos-config/timezone.nix
Normal file
3
nixos-config/timezone.nix
Normal file
@ -0,0 +1,3 @@
|
||||
{
|
||||
time.timeZone = "America/New_York";
|
||||
}
|
||||
Loading…
x
Reference in New Issue
Block a user