feat(deploy): add auto-upgrade, cachix, and passwordless sudo for douro-installed
- Passwordless sudo for lamassu user (nixos-rebuild without TTY) - Cachix binary cache (aiolabs) as substituter - Daily auto-upgrade timer pulling latest flake from Forgejo - trusted-users includes lamassu for nix commands Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
03b5720883
commit
34179a4e34
1 changed files with 22 additions and 0 deletions
22
flake.nix
22
flake.nix
|
|
@ -96,6 +96,28 @@
|
|||
# Electron sandbox needs unprivileged user namespaces
|
||||
boot.kernel.sysctl."kernel.unprivileged_userns_clone" = 1;
|
||||
|
||||
# Passwordless sudo for remote nixos-rebuild switch
|
||||
security.sudo.wheelNeedsPassword = false;
|
||||
|
||||
# Allow lamassu user to use nix commands + pull from aiolabs binary cache
|
||||
nix.settings = {
|
||||
trusted-users = [ "root" "lamassu" ];
|
||||
substituters = [ "https://cache.nixos.org" "https://aiolabs.cachix.org" ];
|
||||
trusted-public-keys = [
|
||||
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
|
||||
"aiolabs.cachix.org-1:PrAjsGU9PE77tFKP2+iO+mgR88c4xv3utM9JmpTblUQ="
|
||||
];
|
||||
};
|
||||
|
||||
# Auto-upgrade: pulls latest flake and runs nixos-rebuild switch
|
||||
# To update manually: sudo nixos-rebuild switch --flake git+ssh://forgejo@git.atitlan.io/aiolabs/lamassu-next.git#douro-installed
|
||||
system.autoUpgrade = {
|
||||
enable = true;
|
||||
flake = "git+ssh://forgejo@git.atitlan.io/aiolabs/lamassu-next.git#douro-installed";
|
||||
dates = "04:00"; # daily at 4am
|
||||
allowReboot = false;
|
||||
};
|
||||
|
||||
# Env template — runtime secrets provisioned via provision-atm.sh
|
||||
system.activationScripts.lamassu-env = ''
|
||||
mkdir -p /var/lib/lamassu-atm
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue