Merge pull request 'fix(deploy): nightly auto-upgrade failed on both ATMs, for different reasons' (#101) from fix/autoupgrade-known-hosts-and-wg into dev
Reviewed-on: #101
This commit is contained in:
commit
387bed0679
1 changed files with 26 additions and 0 deletions
|
|
@ -159,6 +159,18 @@
|
||||||
# Auto-updates (optional - disabled by default for stability)
|
# Auto-updates (optional - disabled by default for stability)
|
||||||
# system.autoUpgrade.enable = false;
|
# system.autoUpgrade.enable = false;
|
||||||
|
|
||||||
|
# Trust the Forgejo host key up front. system.autoUpgrade fetches the flake
|
||||||
|
# over ssh AS ROOT, and a machine whose root has never connected by hand has
|
||||||
|
# no known_hosts entry, so every nightly run dies at
|
||||||
|
# "Host key verification failed" before it reaches authentication. batm3 did
|
||||||
|
# exactly that, silently, from its 2026-08-06 install until 09-22 (#98): it
|
||||||
|
# sat on its install generation for six weeks while reporting a failed unit
|
||||||
|
# nobody was watching. sintra only ever worked because a human had ssh'd as
|
||||||
|
# root once and accepted the key. Declaring it means a freshly flashed ATM
|
||||||
|
# can update from first boot with no manual step.
|
||||||
|
programs.ssh.knownHosts."git.atitlan.io".publicKey =
|
||||||
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMlo3f05o4+bk0+8x2VG91o9GubshOb46HmBPvND9pJx";
|
||||||
|
|
||||||
# pragma: allowlist secret
|
# pragma: allowlist secret
|
||||||
# Ensure WireGuard private key directory exists with correct permissions
|
# Ensure WireGuard private key directory exists with correct permissions
|
||||||
system.activationScripts.wireguard-key = ''
|
system.activationScripts.wireguard-key = ''
|
||||||
|
|
@ -169,6 +181,20 @@
|
||||||
fi
|
fi
|
||||||
'';
|
'';
|
||||||
|
|
||||||
|
# The tunnel is operator-provisioned: wg0.key is written per machine after
|
||||||
|
# flashing, and until it is, `wg set … private-key` exits 1 with
|
||||||
|
# "fopen: No such file or directory". One failed unit makes
|
||||||
|
# switch-to-configuration exit 4, which marks the entire nightly
|
||||||
|
# system.autoUpgrade run as failed — so an ATM that simply never had its
|
||||||
|
# tunnel provisioned reports a broken updater for the life of the machine
|
||||||
|
# (sintra, #98). Skip the unit when there is no key instead of failing
|
||||||
|
# activation over an interface that was never set up; a provisioned machine
|
||||||
|
# is unaffected. Guarded on wg0 still being declared so the live image,
|
||||||
|
# which mkForce's the interfaces away, doesn't get a unit with no ExecStart.
|
||||||
|
systemd.services = lib.mkIf (config.networking.wireguard.interfaces ? wg0) {
|
||||||
|
wireguard-wg0.unitConfig.ConditionPathExists = "/var/lib/wireguard/wg0.key";
|
||||||
|
};
|
||||||
|
|
||||||
# In-place rename migration: lamassu user → bitspire user.
|
# In-place rename migration: lamassu user → bitspire user.
|
||||||
# Runs after `users` activation so the bitspire user exists with its UID.
|
# Runs after `users` activation so the bitspire user exists with its UID.
|
||||||
# Idempotent: re-running on an already-migrated system is a chown no-op.
|
# Idempotent: re-running on an already-migrated system is a chown no-op.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue