feat: Add nix-darwin (macOS) deployment support#319
Conversation
Fix two issues causing CI failures in PR nix-community#319: 1. Code formatting: Run rustfmt to fix formatting in host module and profile.rs where multi-parameter function signatures weren't split across lines per Rust style guidelines. 2. Test compilation: Add missing system_type field to NodeConfig in node_filter.rs test code. The field was added as part of the darwin support feature but the test template wasn't updated accordingly.
|
@zhaofengli let me know if this is the right direction of travel or not. |
|
@zhaofengli ping :-) |
|
I was able to test your branch and verified that that build and apply work. There doesn't appear to be support for allowLocalDeployment as buildOnTarget doesn't seem to work when connecting as root. Otherwise it seems functional, sudo as a user works for buildOnTarget |
based on nix-community#319 - SystemType enum (NixOS vs Darwin) - evalDarwinNode in eval.nix using nix-darwin's darwinSystem - deployment.systemType option for explicit system type - meta.nix-darwin option for the nix-darwin flake input - darwinDefaults support for darwin-specific defaults - Darwin-specific profile activation, boot ID detection, nix-env PATH - Resolved conflicts with detached-activation patch in ssh.rs Co-Authored-By: Moritz Angermann <moritz.angermann@gmail.com>
based on nix-community#319 - SystemType enum (NixOS vs Darwin) - evalDarwinNode in eval.nix using nix-darwin's darwinSystem - deployment.systemType option for explicit system type - meta.nix-darwin option for the nix-darwin flake input - darwinDefaults support for darwin-specific defaults - darwin-specific profile activation, boot ID detection, nix-env PATH - resolved conflicts with detached-activation patch in ssh.rs - use /run/current-system/sw/bin for nix binaries Co-Authored-By: Moritz Angermann <moritz.angermann@gmail.com>
|
sorry for getting back so late! a little heads up here, i plan to review this after #340 so you might need to rebase a few times |
|
I had added some enhancements on top of this / finished out some of the incomplete features and opened a PR here against the upstream of this PR: zw3rk#1 but with no response I personally would really like to see this PR move forward so if nobody takes up the mantle I'd be happy to continue working on it / stop maintaining my fork. :) |
|
if you want you can cherry pick the commits you needed and open a new PR and take over if @angerman doesn't reply soon, though remember to give proper credit in the commit msg! |
If that happens, then yes, of course. I'll preserve the original author commit details during rebase. Hopefully though @angerman just missed the PR and this activity will motivate them. :) |
Add support for deploying to macOS machines using nix-darwin.
Changes:
- Add SystemType enum (NixOS vs Darwin) in mod.rs
- Add evalDarwinNode in eval.nix using nix-darwin's darwinSystem
- Add darwinDefaults support for darwin-specific defaults
- Auto-detect darwin nodes from flake's darwinConfigurations
- Add deployment.systemType option for explicit system type
- Handle darwin-specific profile activation commands
- Fix macOS PATH issues for root user:
- Add DARWIN_NIX_BIN_PATH constant (/nix/var/nix/profiles/default/bin)
- Use remote-program parameter for ssh-ng:// nix-daemon
- Use full path for nix-env during profile activation
Usage in flake.nix:
colmena = {
meta.nix-darwin = inputs.darwin; # Required for darwin nodes
my-mac = {
deployment.systemType = "darwin";
deployment.targetHost = "my-mac.local";
# ... darwin configuration
};
};
Fix two issues causing CI failures in PR nix-community#319: 1. Code formatting: Run rustfmt to fix formatting in host module and profile.rs where multi-parameter function signatures weren't split across lines per Rust style guidelines. 2. Test compilation: Add missing system_type field to NodeConfig in node_filter.rs test code. The field was added as part of the darwin support feature but the test template wasn't updated accordingly.
realize_remote() called nix-store without a full path, which fails on macOS when connecting as root since /nix/var/nix/profiles/default/bin is not in root's PATH. Use DARWIN_NIX_BIN_PATH for nix-store on darwin, matching the existing pattern for nix-env in activate().
Remove the #[cfg(target_os = "linux")] gate that prevented apply-local from compiling on macOS. Replace the NixOS-only /etc/os-release check with a platform-aware guard: macOS is accepted directly (for nix-darwin), Linux still validates NixOS via os-release.
Add tests for: - systemType defaults to NixOS - systemType parses "darwin" correctly - darwin systemType is accepted as valid config
|
🙌 |
Addresses issues found while reviewing the nix-darwin support. No change to
existing NixOS deployments.
Correctness:
* systemType detection now reads `deployment.systemType` through the module
system, so function-form node modules (not just attrsets) are routed to the
darwin evaluator; the `meta.nix-darwin` assertion is now actually forced (it
was bound to an unreferenced `let` and never ran).
* apply-local ran `nix-store`/`nix-env` by bare name, which fails on macOS under
sudo's `secure_path`; resolve them to an absolute path when the local machine
is macOS. `DARWIN_NIX_BIN_PATH` is hoisted to a shared const.
* `readlink -e` (GNU-only) errors on BSD/macOS targets; use `readlink -f` with an
`[ -e … ]` guard that preserves the CURRENT_PROFILE fallback on both.
* Non-flake darwin copies used legacy `nix-copy-closure` (relies on the remote
PATH); force the ssh-ng `nix copy` path for darwin.
Cleanup:
* Remove dead `Profile::from_store_path_with_type` (can't be wired in — its local
`exists()` checks would break `buildOnTarget`) and the now-unused
`InvalidProfile`, `SystemType::is_nixos()`, and `RebootOptions::get_system_type()`.
* Add `remote_nix_bin`/`local_nix_bin` helpers; factor eval.nix's duplicated
`specialArgs`/nixpkgs selection into `mkSpecialArgs`/`npkgsFor`; drop redundant
Nix (`or {}`, `nullOr`, unused arg); tighten visibility; tidy darwin tests.
Fix two issues causing CI failures in PR nix-community#319: 1. Code formatting: Run rustfmt to fix formatting in host module and profile.rs where multi-parameter function signatures weren't split across lines per Rust style guidelines. 2. Test compilation: Add missing system_type field to NodeConfig in node_filter.rs test code. The field was added as part of the darwin support feature but the test template wasn't updated accordingly.
Fix two issues causing CI failures in PR nix-community#319: 1. Code formatting: Run rustfmt to fix formatting in host module and profile.rs where multi-parameter function signatures weren't split across lines per Rust style guidelines. 2. Test compilation: Add missing system_type field to NodeConfig in node_filter.rs test code. The field was added as part of the darwin support feature but the test template wasn't updated accordingly.
Fix two issues causing CI failures in PR nix-community#319: 1. Code formatting: Run rustfmt to fix formatting in host module and profile.rs where multi-parameter function signatures weren't split across lines per Rust style guidelines. 2. Test compilation: Add missing system_type field to NodeConfig in node_filter.rs test code. The field was added as part of the darwin support feature but the test template wasn't updated accordingly.
Add support for deploying to macOS machines using nix-darwin, alongside the
existing NixOS support.
Capabilities
SystemType(NixOS vs Darwin), threaded through evaluation, build, copy, andactivation.
evalDarwinNodeineval.nixevaluates darwin nodes via nix-darwin'sdarwinSystem;meta.nix-darwinsupplies the input.deployment.systemType, orauto-detected from a flake's
darwinConfigurations.sw/bin/darwin-rebuild activate), with thebootgoal correctly reported as unsupported on darwin.darwinDefaultsfor darwin-only defaults.colmena apply-localandbuildOnTargetwork on macOS, including whenconnecting as root.
secure_path) lack thenix binaries: absolute nix paths for local/remote commands,
remote-programon the ssh-ng store, and
nix copy(rather than legacynix-copy-closure)for darwin targets.
Credits
The
apply-local/rootbuildOnTargetenablement and the initial darwin testcoverage are by @sini, preserved as their own commits. Thanks!
Usage (flake)
Notes
meta.nix-darwinto be set.nix copyfor closure transfer (the legacynix-copy-closurepath cannot target nix on a macOS host without a PATH on theremote); flake deployments already used this path.