2022-11-13 21:45:50 +00:00
|
|
|
{
|
|
|
|
description = "hacc infra stuff";
|
|
|
|
|
|
|
|
inputs = {
|
2023-09-19 22:33:36 +00:00
|
|
|
mattermost-webapp.url = "https://releases.mattermost.com/7.8.11/mattermost-7.8.11-linux-amd64.tar.gz";
|
2022-11-13 21:45:50 +00:00
|
|
|
mattermost-webapp.flake = false;
|
2023-09-19 22:33:36 +00:00
|
|
|
mattermost-server.url = "github:mattermost/mattermost-server?ref=v7.8.11";
|
2022-11-13 21:45:50 +00:00
|
|
|
mattermost-server.flake = false;
|
|
|
|
|
2023-06-06 00:04:11 +00:00
|
|
|
nixpkgs.url = "nixpkgs/nixos-23.05";
|
2023-09-27 15:14:05 +00:00
|
|
|
nixpkgs-oldstable.url = "github:/NixOS/nixpkgs?rev=c4aec3c021620d98861639946123214207e98344";
|
2022-11-14 17:19:26 +00:00
|
|
|
nix-hexchen.url = "gitlab:hexchen/nixfiles";
|
2023-06-06 00:04:11 +00:00
|
|
|
nixos-mailserver.url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-23.05";
|
2023-01-22 01:25:07 +00:00
|
|
|
tracktrain.url = "git+https://stuebinm.eu/git/tracktrain?ref=main";
|
|
|
|
tracktrain.flake = false;
|
2022-11-13 22:04:55 +00:00
|
|
|
|
|
|
|
deploy-rs.url = "github:serokell/deploy-rs";
|
|
|
|
deploy-rs.inputs.nixpkgs.follows = "nixpkgs";
|
2023-09-25 15:14:45 +00:00
|
|
|
deploy-rs.inputs.flake-compat.follows = "nix-hexchen/apple-silicon/flake-compat";
|
2023-04-19 18:08:45 +00:00
|
|
|
sops-nix.url = "github:Mic92/sops-nix";
|
|
|
|
sops-nix.inputs.nixpkgs-stable.follows = "nixpkgs";
|
2022-11-25 21:48:27 +00:00
|
|
|
|
|
|
|
# these exist mostly to make the flake.lock somewhat more human-friendly
|
|
|
|
# note that in theory doing this might break things, but it seems fairly unlikely
|
|
|
|
nix-hexchen.inputs = {
|
|
|
|
nixos-mailserver.follows = "nixos-mailserver";
|
|
|
|
deploy-rs.follows = "deploy-rs";
|
|
|
|
doom-emacs.follows = "nix-hexchen/nix-doom-emacs/doom-emacs";
|
|
|
|
emacs-overlay.follows = "nix-hexchen/nix-doom-emacs/emacs-overlay";
|
|
|
|
flake-utils.follows = "/deploy-rs/utils";
|
2023-09-25 15:14:45 +00:00
|
|
|
flake-compat.follows = "nix-hexchen/apple-silicon/flake-compat";
|
2023-04-19 18:08:45 +00:00
|
|
|
sops-nix.follows = "sops-nix";
|
2022-11-25 21:48:27 +00:00
|
|
|
};
|
|
|
|
nixos-mailserver.inputs = {
|
2023-06-06 00:04:11 +00:00
|
|
|
"nixpkgs-23_05".follows = "nixpkgs";
|
|
|
|
utils.follows = "/deploy-rs/utils";
|
|
|
|
flake-compat.follows = "/deploy-rs/flake-compat";
|
2022-11-25 21:48:27 +00:00
|
|
|
};
|
2022-11-13 21:45:50 +00:00
|
|
|
};
|
|
|
|
|
2023-04-19 18:08:45 +00:00
|
|
|
outputs = { self, nixpkgs, nix-hexchen, deploy-rs, sops-nix, ... }@inputs:
|
2022-11-13 21:45:50 +00:00
|
|
|
let modules = nix-hexchen.nixosModules;
|
2023-02-18 13:45:14 +00:00
|
|
|
profiles = nix-hexchen.nixosModules.profiles // {
|
|
|
|
container = import ./modules/container-profile.nix;
|
|
|
|
};
|
2022-11-13 21:45:50 +00:00
|
|
|
pkgs = import ./pkgs {
|
|
|
|
sources = inputs;
|
|
|
|
system = "x86_64-linux";
|
|
|
|
};
|
2023-02-18 13:45:14 +00:00
|
|
|
evalConfig = config: (nixpkgs.lib.nixosSystem {
|
2022-11-13 21:45:50 +00:00
|
|
|
system = "x86_64-linux";
|
|
|
|
modules = [
|
|
|
|
config
|
|
|
|
nix-hexchen.nixosModules.network.nftables
|
|
|
|
{ nixpkgs.pkgs = pkgs; }
|
|
|
|
];
|
|
|
|
specialArgs = {
|
|
|
|
inherit modules profiles evalConfig;
|
|
|
|
sources = inputs;
|
2023-02-18 13:45:14 +00:00
|
|
|
};
|
|
|
|
}).config.system.build.toplevel;
|
2022-11-13 21:45:50 +00:00
|
|
|
in {
|
|
|
|
# do this by hand instead of via nix-hexchen/lib/hosts.nix, since that one
|
|
|
|
# apparently can't support pkgs depending on flake inputs
|
|
|
|
nixosConfigurations.parsons = nixpkgs.lib.nixosSystem {
|
|
|
|
system = "x86_64-linux";
|
|
|
|
modules = [
|
|
|
|
./hosts/parsons/configuration.nix
|
2023-04-19 18:08:45 +00:00
|
|
|
sops-nix.nixosModules.sops
|
2022-11-13 21:45:50 +00:00
|
|
|
{ nixpkgs.pkgs = pkgs; }
|
2023-03-23 14:29:29 +00:00
|
|
|
{ environment.etc."haccfiles".source = self.outPath; }
|
2022-11-13 21:45:50 +00:00
|
|
|
];
|
|
|
|
specialArgs = {
|
|
|
|
# with a few exceptions, the flake inputs can be used the same
|
|
|
|
# as the niv-style (import nix/sources.nix {})
|
|
|
|
sources = inputs;
|
|
|
|
inherit modules profiles evalConfig;
|
|
|
|
};
|
|
|
|
};
|
2022-11-13 22:04:55 +00:00
|
|
|
|
|
|
|
deploy.nodes.parsons = {
|
|
|
|
hostname = "parsons";
|
|
|
|
profiles.system = {
|
|
|
|
user = "root";
|
2022-11-15 14:19:36 +00:00
|
|
|
autoRollback = false;
|
2022-11-13 22:04:55 +00:00
|
|
|
path = deploy-rs.lib.x86_64-linux.activate.nixos
|
|
|
|
self.nixosConfigurations.parsons;
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
# This is highly advised, and will prevent many possible mistakes
|
|
|
|
checks = builtins.mapAttrs
|
|
|
|
(system: deployLib: deployLib.deployChecks self.deploy)
|
|
|
|
deploy-rs.lib;
|
2023-02-24 16:33:48 +00:00
|
|
|
|
|
|
|
packages.x86_64-linux =
|
2023-09-25 15:14:50 +00:00
|
|
|
pkgs; # self.nixosConfigurations.parsons.config.hacc.websites.builders;
|
2022-11-13 21:45:50 +00:00
|
|
|
};
|
2022-11-13 22:04:55 +00:00
|
|
|
|
2022-11-13 21:45:50 +00:00
|
|
|
}
|