summaryrefslogtreecommitdiff
path: root/modules
diff options
context:
space:
mode:
authorEmily <vcs@emily.moe>2024-11-07 06:02:34 +0000
committerGitHub <noreply@github.com>2024-11-07 06:02:34 +0000
commit366b99abfe07ebc0ab56f68b126394344cab00f5 (patch)
treef5dbdc438213a23051bb056c638ad894dd893c6e /modules
parent98e7dba87238e4fa4eac609dc44f07dab40661c4 (diff)
parent2af06b086283be3ab3824a86f35f6301c95b372b (diff)
Merge pull request #1140 from Enzime/aarch64-tests
release: fix tests not running on `aarch64-darwin`
Diffstat (limited to 'modules')
-rw-r--r--modules/examples/hydra.nix17
-rw-r--r--modules/examples/lnl.nix13
-rw-r--r--modules/examples/ofborg.nix29
-rw-r--r--modules/services/ofborg/default.nix10
4 files changed, 12 insertions, 57 deletions
diff --git a/modules/examples/hydra.nix b/modules/examples/hydra.nix
index 3160498..eb1c5d9 100644
--- a/modules/examples/hydra.nix
+++ b/modules/examples/hydra.nix
@@ -1,25 +1,16 @@
{ config, lib, pkgs, ... }:
-with lib;
-
let
- environment = concatStringsSep " "
+ environment = lib.concatStringsSep " "
[ "NIX_REMOTE=daemon"
"NIX_SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
];
in
{
- # Create /etc/bashrc that loads the nix-darwin environment.
- programs.bash.enable = true;
- programs.bash.completion.enable = false;
-
- # Recreate /run/current-system symlink after boot.
- services.activate-system.enable = true;
-
services.nix-daemon.enable = true;
- nix.settings.substituters = [ http://cache1 ];
+ nix.settings.substituters = [ "http://cache1" ];
nix.settings.trusted-public-keys = [ "cache.daiderd.com-1:R8KOWZ8lDaLojqD+v9dzXAqGn29gEzPTTbr/GIpCTrI=" ];
nix.settings.trusted-users = [ "@admin" "@hydra" ];
@@ -31,7 +22,7 @@ in
nix.gc.automatic = true;
nix.gc.options = "--max-freed $((25 * 1024**3 - 1024 * $(df -P -k /nix/store | tail -n 1 | awk '{ print $4 }')))";
- environment.etc."per-user/hydra/ssh/authorized_keys".text = concatStringsSep "\n"
+ environment.etc."per-user/hydra/ssh/authorized_keys".text = lib.concatStringsSep "\n"
[ "command=\"${environment} ${config.nix.package}/bin/nix-store --serve --write\" ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCVsc0pHGsskoayziMhA2e59bHPWe0bbKgusmqhuJFBGQ1BAk9UmPzKCWE3nCiV6CLD1+SygVkBjb06DYtc+94BnzviCa9qZtL0G4+2vhp6x8OvXh8xlf/eWw3k5MWlvu+kjJFpbW8wHWTiUqzH+uEeHklAosT0lFNjiIYd/Vs3JAezhUR62a6c7ZjWOd5F7ALGEKzOiwC4i37kSgGsIWNCbe0Ku7gyr718zhMGeyxax6saHhnkSpIB+7d6oHhKeiJSFMWctNmz1/qxXUPbxNaJvqgdKlVHhN+B7x/TIbkVr5pTC59Okx9LTcpflFIv79VT+Gf1K7VypZpSvJjG0xFRt8iDs1+ssWFBfvpo94vUbZ+ZwMDcBGR5iJeO41Gj5fYn5aaDl32RXfJ9Fkwael1L6pcXtkIc66jk+KQQpgoeNj8Y3Emntpqva/2AM41wDDvr5tKp5KhEKFLM95CoiWq+g88pZLcpqLK7wooDVqNkVUEbMaj9lBN0AzU9mcsIRGvTa6CmWAdBvwqS2fRZD97Oarqct9AWgb0X6mOUq9BJNi4i4xvjgnVkylLwtLUnibR/PeXMtkb9bv6BEZXNf5ACqxSjKXJyaIHI65I5TILCr5eEgaujgvmkREn6U3T1NZAUIeVe9aVYLqehYh79OHUBzggoHqidRrXBB/6zdg9UgQ=="
"command=\"${environment} ${config.nix.package}/bin/nix-store --serve --write\" ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCnubA1pRqlpoAXkZ1q5nwhqi1RY2z840wFLFDj7vAMSups9E2U8PNIVtuVYApZpkBWIpzD4GGbQTF5Itnu5uBpJswc2Yat9yGWO/guuVyXIaRoBIM0Pg1WBWcWsz+k4rNludu9UQ74FHqEiqZIuIuOcgV+RIZn8xQlGt2kUqN9TWboHhZz8Zhx7EtGSJH6MJRLn3mA/pPjOF6k1jiiFG1pVDuqBTZPANkelWYCWAJ46jCyhxXltWE/jkBYGc/XbB8yT7DFE1XC6TVsSEp68R9PhVG3yqxqY06sniEyduSoGt/TDr6ycERd93bvLElXFATes85YiFszeaUgayYSKwQPe0q7YeHMhIXL0UYJYaKVVgT9saFDiHDzde7kKe+NA+J4+TbIk7Y/Ywn0jepsYV13M7TyEqgqbu9fvVGF3JI9+4g0m1gAzHTa7n6iiAedtz+Pi79uCEpRD2hWSSoLWroyPlep8j1p2tygtFsrieePEukesoToCTwqg1Ejnjh+yKdtUbc6xpyRvl3hKeO8QbCpfaaVd27e4vE4lP2JMW6nOo8b0wlVXQIFe5K2zh52q1MSwhLAq6Kg8oPmgj0lru4IivmPc+/NVwd3Qj3E9ZB8LRfTesfbcxHrC8lF5dL/QpLMeLwebrwCxL19gI0kxmDIaUQuHSyP3B2z+EmBKcN/Xw=="
];
@@ -53,4 +44,6 @@ in
chown hydra:hydra ~hydra ~hydra/.ssh ~hydra/.ssh/authorized_keys
echo "ok"
'';
+
+ system.stateVersion = 5;
}
diff --git a/modules/examples/lnl.nix b/modules/examples/lnl.nix
index d944158..dccae07 100644
--- a/modules/examples/lnl.nix
+++ b/modules/examples/lnl.nix
@@ -1,10 +1,6 @@
{ config, lib, inputs, pkgs, ... }:
{
- # imports = [ ~/.config/nixpkgs/darwin/local-configuration.nix ];
-
- # system.patches = [ ./pam.patch ];
-
system.defaults.NSGlobalDomain.AppleKeyboardUIMode = 3;
system.defaults.NSGlobalDomain.ApplePressAndHoldEnabled = false;
system.defaults.NSGlobalDomain.InitialKeyRepeat = 10;
@@ -50,13 +46,10 @@
pkgs.gnupg
pkgs.htop
pkgs.jq
- pkgs.mosh
pkgs.ripgrep
pkgs.shellcheck
- pkgs.vault
pkgs.qes
- pkgs.darwin-zsh-completions
];
services.yabai.enable = true;
@@ -96,7 +89,7 @@
'';
nix.settings.trusted-public-keys = [ "cache.daiderd.com-1:R8KOWZ8lDaLojqD+v9dzXAqGn29gEzPTTbr/GIpCTrI=" ];
- nix.settings.trusted-substituters = [ https://d3i7ezr9vxxsfy.cloudfront.net ];
+ nix.settings.trusted-substituters = [ "https://d3i7ezr9vxxsfy.cloudfront.net" ];
nix.settings.sandbox = true;
nix.settings.extra-sandbox-paths = [ "/private/tmp" "/private/var/tmp" "/usr/bin/env" ];
@@ -302,8 +295,6 @@
fi
'';
- # environment.darwinConfig = "$HOME/.config/nixpkgs/darwin/configuration.nix";
-
nixpkgs.config.allowUnfree = true;
nixpkgs.overlays = [
@@ -331,4 +322,6 @@
nix.configureBuildUsers = true;
nix.nrBuildUsers = 32;
+
+ system.stateVersion = 5;
}
diff --git a/modules/examples/ofborg.nix b/modules/examples/ofborg.nix
deleted file mode 100644
index 6cef6e7..0000000
--- a/modules/examples/ofborg.nix
+++ /dev/null
@@ -1,29 +0,0 @@
-{ config, lib, pkgs, ... }:
-
-with lib;
-
-{
- # Logs are enabled by default.
- # $ tail -f /var/log/ofborg.log
- services.ofborg.enable = true;
- # services.ofborg.configFile = "/var/lib/ofborg/config.json";
-
- # $ nix-channel --add https://github.com/NixOS/ofborg/archive/released.tar.gz ofborg
- # $ nix-channel --update
- services.ofborg.package = (import <ofborg> {}).ofborg.rs;
-
- # Keep nix-daemon updated.
- services.nix-daemon.enable = true;
-
- nix.gc.automatic = true;
- nix.gc.options = "--max-freed $((25 * 1024**3 - 1024 * $(df -P -k /nix/store | tail -n 1 | awk '{ print $4 }')))";
-
- # Manage user for ofborg, this enables creating/deleting users
- # depending on what modules are enabled.
- users.knownGroups = [ "ofborg" ];
- users.knownUsers = [ "ofborg" ];
-
- # Used for backwards compatibility, please read the changelog before changing.
- # $ darwin-rebuild changelog
- system.stateVersion = 5;
-}
diff --git a/modules/services/ofborg/default.nix b/modules/services/ofborg/default.nix
index 4c35615..8959cc8 100644
--- a/modules/services/ofborg/default.nix
+++ b/modules/services/ofborg/default.nix
@@ -46,12 +46,6 @@ in
};
config = mkIf cfg.enable {
-
- assertions = [
- { assertion = elem "ofborg" config.users.knownGroups; message = "set users.knownGroups to enable ofborg group"; }
- { assertion = elem "ofborg" config.users.knownUsers; message = "set users.knownUsers to enable ofborg user"; }
- ];
-
warnings = mkIf (isDerivation cfg.configFile) [
"services.ofborg.configFile is a derivation, credentials will be world readable"
];
@@ -87,9 +81,13 @@ in
users.users.ofborg.shell = "/bin/bash";
users.users.ofborg.description = "OfBorg service user";
+ users.knownUsers = [ "ofborg" ];
+
users.groups.ofborg.gid = mkDefault 531;
users.groups.ofborg.description = "Nix group for OfBorg service";
+ users.knownGroups = [ "ofborg" ];
+
# FIXME: create logfiles automatically if defined.
system.activationScripts.preActivation.text = ''
mkdir -p '${user.home}'