-
Notifications
You must be signed in to change notification settings - Fork 1
/
flake.nix
143 lines (119 loc) · 3.75 KB
/
flake.nix
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
{
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-24.05";
nixos-hardware.url = "github:NixOS/nixos-hardware/master";
nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixos-unstable";
agenix = {
url = "github:ryantm/agenix";
inputs.nixpkgs.follows = "nixpkgs";
};
home-manager = {
url = "github:nix-community/home-manager/release-24.05";
inputs.nixpkgs.follows = "nixpkgs";
};
lanzaboote = {
url = "github:nix-community/lanzaboote/v0.4.1";
inputs.nixpkgs.follows = "nixpkgs";
};
colmena = {
url = "github:zhaofengli/colmena";
inputs = {
nixpkgs.follows = "nixpkgs";
stable.follows = "nixpkgs";
};
};
authentik-nix = {
url = "github:nix-community/authentik-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
nixvim = {
url = "github:nix-community/nixvim/nixos-24.05";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-index-database = {
url = "github:nix-community/nix-index-database";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = { self, nixpkgs, ... }@inputs: let
lib = nixpkgs.lib;
in {
nixosConfigurations = (import ./machines inputs);
#colmena = {
# meta = {
# nixpkgs = import inputs.nixpkgs { system = "x86_64-linux"; };
# nodeNixpkgs = builtins.mapAttrs (_: v: v.pkgs) self.nixosConfigurations;
# nodeSpecialArgs = builtins.mapAttrs (_: v: v._module.specialArgs) self.nixosConfigurations;
# };
#} // builtins.mapAttrs (_: v: { imports = v._module.args.modules; }) self.nixosConfigurations;
colmena = lib.recursiveUpdate
(builtins.mapAttrs (k: v: { imports = v._module.args.modules; }) self.nixosConfigurations)
{
meta = {
nixpkgs = import nixpkgs {
system = "x86_64-linux";
overlays = [];
};
nodeNixpkgs = builtins.mapAttrs (_: v: v.pkgs) self.nixosConfigurations;
nodeSpecialArgs = builtins.mapAttrs (_: v: v._module.specialArgs) self.nixosConfigurations;
};
defaults.deployment.targetUser = "bonus";
braxis.deployment = {
tags = [ "vm" "server" ];
};
bunker.deployment = {
tags = [ "vm" "server" ];
targetHost = "bunker.warp.lan";
};
endion.deployment = {
tags = [ "vm" "server" ];
};
kaldir.deployment = {
tags = [ "phys" "server" ];
buildOnTarget = true;
targetHost = "kaldir.warp.lan";
};
scv.deployment = {
tags = [ "vm" "server" ];
buildOnTarget = true;
};
shakuras.deployment = {
tags = [ "vm" "server" ];
};
raven.deployment = {
tags = [ "vm" "server" ];
};
nexus.deployment = {
tags = [ "vm" "server" ];
};
vortex-alpha.deployment = {
tags = [ "vm" "server" "vortex" ];
targetHost = "192.168.4.119";
};
vortex-beta.deployment = {
tags = [ "vm" "server" "vortex" ];
targetHost = "192.168.4.118";
};
vortex-gamma.deployment = {
tags = [ "vm" "server" "vortex" ];
targetHost = "192.168.4.120";
};
artanis.deployment = {
allowLocalDeployment = true;
buildOnTarget = true;
tags = [ "phys" ];
privilegeEscalationCommand = ["doas" "--"];
};
zeratul.deployment = {
allowLocalDeployment = true;
buildOnTarget = true;
tags = [ "phys" ];
privilegeEscalationCommand = ["doas" "--"];
};
depot.deployment = {
tags = [ "vm" "server" ];
targetHost = "depot.warp.lan";
};
};
};
}