feat(deploy): add aarch64 Raspberry Pi 4 target

The Pi 4 twin of the Pi 5 build: `rpi4-installed` (in-place rebuild target),
`rpi4-image`, and `packages.aarch64-linux.{sd-image-rpi4,atm-app-rpi4}`, all
through the board-keyed machinery of the previous commit. The shared runtime
is untouched; only the board pair is new.

deploy/nixos/hardware/raspberry-pi-4.nix mirrors raspberry-pi-5.nix line for
line except where the boards differ:
- KMS for the kiosk display is an opt-in on the Pi 4
  (`hardware.raspberry-pi."4".fkms-3d`), which also injects the CMA + vc4
  device-tree overlays; the Pi 5 gets it by default. Without it X falls back
  to the framebuffer and Electron renders in software.
- fkms-3d sets videoDrivers itself, so the module doesn't.
Everything else — extlinux boot, console pinned to tty0 so the GPIO UART is
free for a validator, no-suspend, the ttyValidator{0,1,2} udev symlinks — is
identical by design.

Evaluation-verified only: rpi4-installed/rpi4-image instantiate, and against
rpi5 they differ solely in the expected places (bcm2711 device tree, the two
fkms overlays, the rpiVersion=4 kernel, no clk-rp1 in initrd, machine model
in the env seed). Not yet booted on hardware; the doc says so.

docs/raspberry-pi-setup.md covers both boards — build, flash, first boot +
provisioning via the spire seed, in-place updates, peripherals — since #87
shipped the Pi 5 without one. It replaces a never-committed Pi 4 sketch
(parked on wip/rpi4-sketch) whose flake wiring didn't evaluate and whose
provisioning section predated the pairing seed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013A6683cCHnQxFUosx1krY4
This commit is contained in:
Padreug 2026-09-20 11:26:17 +02:00
commit 91c6994dd4
4 changed files with 238 additions and 4 deletions

View file

@ -317,6 +317,10 @@
hardware = nixos-hardware.nixosModules.raspberry-pi-5;
glue = ./deploy/nixos/hardware/raspberry-pi-5.nix;
};
rpi4 = {
hardware = nixos-hardware.nixosModules.raspberry-pi-4;
glue = ./deploy/nixos/hardware/raspberry-pi-4.nix;
};
};
# Shared module list (everything EXCEPT the root fs and the sd-image
@ -483,6 +487,12 @@
rpi5-installed = mkPiInstalled "rpi5";
rpi5-image = mkPiImage "rpi5";
# Raspberry Pi 4 (aarch64) — same runtime and products as rpi5, on the
# previous-generation board (see deploy/nixos/hardware/raspberry-pi-4.nix
# for what differs). 4 GB minimum for Electron; 8 GB comfortable.
rpi4-installed = mkPiInstalled "rpi4";
rpi4-image = mkPiImage "rpi4";
# USB-bootable variant of batm3-installed. This is the config the
# flashed USB stick actually runs — distinct fs labels so stage-1 can't
# latch the internal drive, nofail /boot, no growPartition, autoUpgrade
@ -697,13 +707,16 @@
iso = self.nixosConfigurations.douro.config.system.build.isoImage;
};
# ── Packages (aarch64-linux — Raspberry Pi 5 build) ───────────
# Flashable SD image for the Pi 5. Build on an aarch64 builder (native Pi
# / arm box / `boot.binfmt` emulation on this x86 host):
# ── Packages (aarch64-linux — Raspberry Pi builds) ────────────
# Flashable SD images for the Pi boards. Build on an aarch64 builder
# (native Pi / arm box / `boot.binfmt` emulation on this x86 host):
# nix build .#packages.aarch64-linux.sd-image-rpi5
# nix build .#packages.aarch64-linux.sd-image-rpi4
packages.aarch64-linux = {
sd-image-rpi5 = self.nixosConfigurations.rpi5-image.config.system.build.sdImage;
atm-app-rpi5 = mkAtmAppAarch64 { model = "rpi5"; fiatCode = "USD"; };
sd-image-rpi4 = self.nixosConfigurations.rpi4-image.config.system.build.sdImage;
atm-app-rpi4 = mkAtmAppAarch64 { model = "rpi4"; fiatCode = "USD"; };
};
}
//