diff --git a/deploy/nixos/configuration.nix b/deploy/nixos/configuration.nix index 330421c..652de98 100644 --- a/deploy/nixos/configuration.nix +++ b/deploy/nixos/configuration.nix @@ -181,6 +181,20 @@ fi ''; + # The tunnel is operator-provisioned: wg0.key is written per machine after + # flashing, and until it is, `wg set … private-key` exits 1 with + # "fopen: No such file or directory". One failed unit makes + # switch-to-configuration exit 4, which marks the entire nightly + # system.autoUpgrade run as failed — so an ATM that simply never had its + # tunnel provisioned reports a broken updater for the life of the machine + # (sintra, #98). Skip the unit when there is no key instead of failing + # activation over an interface that was never set up; a provisioned machine + # is unaffected. Guarded on wg0 still being declared so the live image, + # which mkForce's the interfaces away, doesn't get a unit with no ExecStart. + systemd.services = lib.mkIf (config.networking.wireguard.interfaces ? wg0) { + wireguard-wg0.unitConfig.ConditionPathExists = "/var/lib/wireguard/wg0.key"; + }; + # In-place rename migration: lamassu user → bitspire user. # Runs after `users` activation so the bitspire user exists with its UID. # Idempotent: re-running on an already-migrated system is a chown no-op.