flake.nix

 1# The fleet: every host, deployed with Colmena from this repo.
 2#
 3# Layout (see docs/fleet-migration-plan.md):
 4#   hosts.json     host inventory: provider/layout, addresses, pinned SSH host
 5#                  key, stateVersion, roles
 6#   hive.nix       inventory -> Colmena hive (colmenaHive), also exposed as
 7#                  nixosConfigurations
 8#   modules/       fleet modules: base, vm, providers, secrets, fleet checks
 9#   hosts/<name>/  legacy hosts (layout = "legacy"): hand-written hardware and
10#                  networking, installed before the fleet existed
11#
12# sovrn and moods are inputs: they export overlays and NixOS modules, and the
13# fleet puts their roles on hosts. Their nixpkgs must be the fleet's
14# (hive.nix checks it), so a host runs the builds their dev shells and VM
15# tests use.
16{
17  description = "Fleet: NixOS hosts for sovrn, moods and personal infrastructure";
18
19  inputs = {
20    # The shared revision: sovrn and moods lock the same one. Pinned here by
21    # rev, not channel, so nothing moves it implicitly; bump it together with
22    # theirs (`just sync-nixpkgs`).
23    nixpkgs.url = "github:NixOS/nixpkgs/7a0f122f5090cf4c2ade2a13a0e229d4e19ba71f";
24    # Hosts with "nixpkgs": "stable" in hosts.json (infra.rtw.run): the
25    # nixos-26.05 branch, pinned by rev like the shared revision. Bump it on
26    # purpose: point it at a newer nixos-26.05 rev and deploy with --reboot.
27    nixpkgs-stable.url = "github:NixOS/nixpkgs/b25309931cfda5f0b8805f462a29897eeae50168";
28
29    disko = {
30      url = "github:nix-community/disko";
31      inputs.nixpkgs.follows = "nixpkgs";
32    };
33    # Same release as the colmena CLI in nixpkgs (0.5.0): `colmena` reads the
34    # `colmenaHive` output built by this lib.
35    colmena = {
36      url = "github:zhaofengli/colmena/v0.5.0";
37      inputs.nixpkgs.follows = "nixpkgs";
38    };
39
40    # Committed content only (jj: @-). `just deploy-project <p>` bumps one.
41    sovrn.url = "git+file:///home/btburke/projects/sovrn?ref=HEAD";
42    moods.url = "git+file:///home/btburke/projects/moods?ref=HEAD";
43
44    # pgit (static git site generator) for infra.rtw.run's forge.
45    pgit.url = "git+https://git.kilimanjaro.io/pgit";
46  };
47
48  outputs =
49    {
50      nixpkgs,
51      colmena,
52      ...
53    }@inputs:
54    let
55      inherit (nixpkgs) lib;
56      colmenaHive = colmena.lib.makeHive (import ./hive.nix { inherit inputs; });
57
58      forAllSystems = lib.genAttrs [
59        "x86_64-linux"
60        "aarch64-linux"
61      ];
62    in
63    {
64      inherit colmenaHive;
65      # Hive nodes are named by FQDN; nixos-anywhere uses `--flake .#<fqdn>`.
66      nixosConfigurations = colmenaHive.nodes;
67
68      # Per-project generators for host-scoped secrets, used by
69      # `just gen-host-secrets` (gen-secret-<project> NAME HOST; exit 3 when
70      # a value can't be generated). moods has no generated host secrets.
71      apps = forAllSystems (system: {
72        gen-secret-sovrn = inputs.sovrn.apps.${system}.gen-secret;
73      });
74
75      devShells = forAllSystems (
76        system:
77        let
78          pkgs = nixpkgs.legacyPackages.${system};
79        in
80        {
81          default = pkgs.mkShell {
82            packages = [
83              pkgs.colmena
84              pkgs.nixos-anywhere
85              pkgs.nvd
86              pkgs.just
87              pkgs.jq
88              pkgs.age
89              pkgs.openssh
90              pkgs.git
91            ];
92            # `secrets` (~/bin/secrets) and SECRETS_DIR come from the user's
93            # environment, as for sovrn and moods.
94          };
95        }
96      );
97    };
98}