From acacbb12e440ba084ec6c8b8752e383464b5926b Mon Sep 17 00:00:00 2001 From: "quentin@aristote.fr" Date: Wed, 29 Jan 2025 17:47:43 +0100 Subject: nix: remote builds: factor out --- config/nix/default.nix | 33 --------------------------------- config/nix/remote-builds.nix | 29 ----------------------------- 2 files changed, 62 deletions(-) delete mode 100644 config/nix/default.nix delete mode 100644 config/nix/remote-builds.nix (limited to 'config/nix') diff --git a/config/nix/default.nix b/config/nix/default.nix deleted file mode 100644 index c930095..0000000 --- a/config/nix/default.nix +++ /dev/null @@ -1,33 +0,0 @@ -{lib, ...}: { - imports = [./remote-builds.nix]; - - personal.nix = { - enable = true; - autoUpgrade = { - enable = true; - autoUpdateInputs = ["nixpkgs" "nixpkgs-unstable"]; - }; - gc.enable = true; - flake = "git+file:///etc/nixos/"; - }; - nix.settings.max-jobs = lib.mkDefault 1; - nixpkgs.flake = { - setNixPath = true; - setFlakeRegistry = true; - }; - - systemd.services.nixos-upgrade = let - mkForce = lib.mkOverride 51; - in { - # restart at most once every hour - serviceConfig = { - Restart = "on-failure"; - RestartSec = "5sec"; - MemoryAccounting = true; - MemoryHigh = "1G"; - MemoryMax = "1.5G"; - }; - startLimitBurst = mkForce 1; - startLimitIntervalSec = mkForce 3600; - }; -} diff --git a/config/nix/remote-builds.nix b/config/nix/remote-builds.nix deleted file mode 100644 index d252af2..0000000 --- a/config/nix/remote-builds.nix +++ /dev/null @@ -1,29 +0,0 @@ -{...}: { - programs.ssh = { - extraConfig = '' - Host hephaistos.aristote.mesh - # Prevent using ssh-agent or another keyfile, useful for testing - IdentitiesOnly yes - IdentityFile /etc/ssh/nixremote - # The weakly privileged user on the remote builder – if not set, 'root' is used – which will hopefully fail - User nixremote - ''; - knownHosts."hephaistos.aristote.mesh".publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHvtqi8tziBuviUV8LDK2ddQQUbHdJYB02dgWTK5Olxq"; - }; - - nix = { - distributedBuilds = true; - buildMachines = [ - { - hostName = "hephaistos.aristote.mesh"; - system = "x86_64-linux"; - # Nix custom ssh-variant that avoids lots of "trusted-users" settings pain - protocol = "ssh-ng"; - maxJobs = 4; - speedFactor = 4; - supportedFeatures = ["nixos-test" "benchmark" "big-parallel" "kvm"]; - mandatoryFeatures = []; - } - ]; - }; -} -- cgit v1.2.3