feat(deploy): run the tejo from USB (disk-image-tejo-usb) #120
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/tejo-usb"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Gives the tejo the run-from-USB shape douro and batm3 already have: the stick is the system, and the factory Debian (
ubilinux4) on internal storage is never touched.nix build .#disk-image-tejo-usbbuilt and was verified on bohm — 6.2 GB sparse / 4.0 GB actual:bios_grub(0.02–1 MiB), ESP fat16 labelled ESP-USB, ext4 root labelled nixos-usbeb 63 90), and the ESP has both/grub/i386-pcand/grub/x86_64-efiplus/EFI/BOOT/BOOTX64.EFINot douro's bootloader
The tejo is the same Aaeon UP Board as sintra —
tejo-installedandsintra-installedsharehardware/upboard.nix— anddisk-image-sintra-usbalready records the finding that Aaeon firmware USB-boots in Legacy/BIOS mode: it boots the live ISO via isolinux, not the ESP. systemd-boot is UEFI-only, so a dd'd systemd-boot stick wouldn't be recognised as bootable at all. So tejo gets GRUB on a hybrid table, BIOS and UEFI. That's also the safe choice given the machine is unreachable right now and the firmware couldn't be checked directly — the image boots either path.Commits
81a001crefactor — one USB-image helper for both bootloader shapes.disk-image-sintra-usbwas a 60-line inline copy of whatmkUsbDiskImagealready does, and the two had drifted: the sintra image never picked up thenofail/bootor theuas/autosuspend hardening batm3 and douro carry.mkUsbDiskImagenow takespartitionTableType(efi→ systemd-boot,hybrid→ GRUB) andgrubBiosDevice; newusbGrubHybridModule+usbBusHardening.sintra-usbbecomes a named config so a running stick updates in place like the others.The hardening is scoped to the
-usbconfigs rather thanhardware/upboard.nix— that file is shared with sintra's eMMC install, and I didn't want to change a production machine's cmdline.grub.devicesis"nodev"in the config and mkForce'd to the build VM's disk only for the image: an in-placeswitch-to-configurationon a live stick has no/dev/vda, and GRUB's embedded core.img reads grub.cfg off the partition, so the MBR stage needs no per-generation rewrite. Plain definition rather than mkForce, because two mkForce lists merge into[ "/dev/vda" "nodev" ]instead of replacing.c3e01c9feat —tejo-usb+disk-image-tejo-usb, plus README on which models take which bootloader shape.6042d69fix — tejo had no WireGuard address. Found while checking the machine would be reachable after flashing.wg0.ipswas set inhardware/douro.nixandhardware/batm3.nix, buthardware/upboard.nixis shared by tejo and sintra, so an address there would be claimed by both on the same /24 — neither got one. tejo evaluated towg0.ips = [ ]: interface up, no IP, tunnel silently dead. Replaced both per-hardware definitions with onewireguardIpForModeltable keyed on model, like thefiatCodeForModel/nfcReaderForModeltables next to it.Verification
douro-usbandbatm3-usbevaluate to identicalkernelParams,blacklistedKernelModules,fileSystems, bootloader andautoUpgradeconfig as before the refactortejo-usbevaluates identically tosintra-usb, as it should10.0.0.4/24and batm310.0.0.5/24unchanged, tejo now10.0.0.3/24, sintra still deliberately empty (LAN-reachable, never had a tunnel address)nixpkgs-fmtcleanBefore flashing
The wg address is only half of it — the VPS maps peer pubkey to tunnel IP, so the machine needs
/var/lib/wireguard/wg0.keycarried over from its current Debian install, or a fresh key with its pubkey added to the VPS peer list. Both wireguard units areConditionPathExists-guarded on that key, so a keyless first boot is clean and the tunnel starts once it's dropped in.Expect
Warning: Bill validator device /dev/ttyUSB0 not foundon first boot — that's #117 (nix module defaults vsdevice.ts), not a real fault. tejo's actual table is validator/dev/ttyJ5(id003), dispenser/dev/ttyJ7(f56), GTQ 5/20/50/100.disk-image-sintra-usb was a 60-line inline copy of everything mkUsbDiskImage already does, plus the GRUB/hybrid bits the Aaeon firmware needs — so the two implementations had already drifted: the sintra image never picked up the `nofail` /boot that keeps a slow ESP-USB enumeration out of emergency mode, nor the uas/autosuspend hardening batm3.nix and douro.nix carry. - mkUsbDiskImage takes named args with `partitionTableType` ("efi" for systemd-boot, "hybrid" for GRUB) and `grubBiosDevice`. The ESP relabel is layout-independent: the hybrid table creates the ESP first and bios_grub second, so it stays partition 1 either way. - New `usbGrubHybridModule` + `usbBusHardening` modules. The hardening is scoped to the -usb configs rather than hardware/upboard.nix, which sintra's eMMC install also reads — no cmdline change on a production machine. - `nixosConfigurations.sintra-usb` is now a named config, so a running stick can be updated in place (nix copy + switch-to-configuration) like batm3-usb and douro-usb. - grub.devices is "nodev" in the config and mkForce'd to the build VM's disk only for the image: an in-place switch on a live stick has no /dev/vda, and GRUB's embedded core.img reads grub.cfg off the partition, so the MBR stage needs no per-generation rewrite. Plain definition rather than mkForce, since two mkForce lists merge into [ "/dev/vda" "nodev" ] instead of replacing. douro-usb and batm3-usb evaluate to byte-identical kernelParams, blacklistedKernelModules, fileSystems, bootloader and autoUpgrade config as before. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>