flake.nix
1# The fleet: every host, deployed with Colmena from this repo.
2#
3# Layout (see docs/fleet-migration-plan.md):
4# hosts.json host inventory: provider/layout, addresses, pinned SSH host
5# key, stateVersion, roles
6# hive.nix inventory -> Colmena hive (colmenaHive), also exposed as
7# nixosConfigurations
8# modules/ fleet modules: base, vm, providers, secrets, fleet checks
9# hosts/<name>/ legacy hosts (layout = "legacy"): hand-written hardware and
10# networking, installed before the fleet existed
11#
12# sovrn and moods are inputs: they export overlays and NixOS modules, and the
13# fleet puts their roles on hosts. Their nixpkgs must be the fleet's
14# (hive.nix checks it), so a host runs the builds their dev shells and VM
15# tests use.
16{
17 description = "Fleet: NixOS hosts for sovrn, moods and personal infrastructure";
18
19 inputs = {
20 # The shared revision: sovrn and moods lock the same one. Pinned here by
21 # rev, not channel, so nothing moves it implicitly; bump it together with
22 # theirs (`just sync-nixpkgs`).
23 nixpkgs.url = "github:NixOS/nixpkgs/7a0f122f5090cf4c2ade2a13a0e229d4e19ba71f";
24 # Hosts with "nixpkgs": "stable" in hosts.json (infra.rtw.run): the
25 # nixos-26.05 branch, pinned by rev like the shared revision. Bump it on
26 # purpose: point it at a newer nixos-26.05 rev and deploy with --reboot.
27 nixpkgs-stable.url = "github:NixOS/nixpkgs/b25309931cfda5f0b8805f462a29897eeae50168";
28
29 disko = {
30 url = "github:nix-community/disko";
31 inputs.nixpkgs.follows = "nixpkgs";
32 };
33 # Same release as the colmena CLI in nixpkgs (0.5.0): `colmena` reads the
34 # `colmenaHive` output built by this lib.
35 colmena = {
36 url = "github:zhaofengli/colmena/v0.5.0";
37 inputs.nixpkgs.follows = "nixpkgs";
38 };
39
40 # Committed content only (jj: @-). `just deploy-project <p>` bumps one.
41 sovrn.url = "git+file:///home/btburke/projects/sovrn?ref=HEAD";
42 moods.url = "git+file:///home/btburke/projects/moods?ref=HEAD";
43
44 # pgit (static git site generator) for infra.rtw.run's forge.
45 pgit.url = "git+https://git.kilimanjaro.io/pgit";
46 };
47
48 outputs =
49 {
50 nixpkgs,
51 colmena,
52 ...
53 }@inputs:
54 let
55 inherit (nixpkgs) lib;
56 colmenaHive = colmena.lib.makeHive (import ./hive.nix { inherit inputs; });
57
58 forAllSystems = lib.genAttrs [
59 "x86_64-linux"
60 "aarch64-linux"
61 ];
62 in
63 {
64 inherit colmenaHive;
65 # Hive nodes are named by FQDN; nixos-anywhere uses `--flake .#<fqdn>`.
66 nixosConfigurations = colmenaHive.nodes;
67
68 # Per-project generators for host-scoped secrets, used by
69 # `just gen-host-secrets` (gen-secret-<project> NAME HOST; exit 3 when
70 # a value can't be generated). moods has no generated host secrets.
71 apps = forAllSystems (system: {
72 gen-secret-sovrn = inputs.sovrn.apps.${system}.gen-secret;
73 });
74
75 devShells = forAllSystems (
76 system:
77 let
78 pkgs = nixpkgs.legacyPackages.${system};
79 in
80 {
81 default = pkgs.mkShell {
82 packages = [
83 pkgs.colmena
84 pkgs.nixos-anywhere
85 pkgs.nvd
86 pkgs.just
87 pkgs.jq
88 pkgs.age
89 pkgs.openssh
90 pkgs.git
91 ];
92 # `secrets` (~/bin/secrets) and SECRETS_DIR come from the user's
93 # environment, as for sovrn and moods.
94 };
95 }
96 );
97 };
98}