File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ name : Deploy
2+
3+ on :
4+ workflow_run :
5+ workflows : ["CI"]
6+ types : [completed]
7+ branches : [main]
8+ workflow_dispatch :
9+
10+ jobs :
11+ deploy :
12+ if : >-
13+ github.event_name == 'workflow_dispatch' ||
14+ github.event.workflow_run.conclusion == 'success'
15+ strategy :
16+ max-parallel : 1
17+ matrix :
18+ include :
19+ - host : glyph
20+ system : x86_64-linux
21+ runner : ubuntu-latest
22+ - host : spore
23+ system : x86_64-linux
24+ runner : ubuntu-latest
25+ - host : zeta
26+ system : aarch64-linux
27+ runner : ubuntu-24.04-arm
28+ runs-on : ${{ matrix.runner }}
29+ steps :
30+ - uses : actions/checkout@v4
31+
32+ - uses : cachix/install-nix-action@v31
33+ with :
34+ github_access_token : ${{ secrets.GITHUB_TOKEN }}
35+ extra_nix_config : |
36+ extra-substituters = https://cache.zx.dev/main
37+ extra-trusted-public-keys = main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c=
38+
39+ - name : Configure Attic cache
40+ run : |
41+ nix profile install --inputs-from . attic#attic-client
42+ attic login rc https://cache.zx.dev ${{ secrets.ATTIC_TOKEN }}
43+ attic use rc:main
44+
45+ - name : Connect to Tailscale
46+ uses : tailscale/github-action@v3
47+ with :
48+ oauth-client-id : ${{ secrets.TS_OAUTH_CLIENT_ID }}
49+ oauth-secret : ${{ secrets.TS_OAUTH_SECRET }}
50+ tags : tag:ci
51+
52+ - name : Configure SSH
53+ run : |
54+ mkdir -p ~/.ssh
55+ echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
56+ chmod 600 ~/.ssh/deploy_key
57+ cat >> ~/.ssh/config <<EOF
58+ Host glyph spore zeta
59+ User root
60+ IdentityFile ~/.ssh/deploy_key
61+ StrictHostKeyChecking accept-new
62+ EOF
63+
64+ - name : Deploy to ${{ matrix.host }}
65+ run : |
66+ nix run --inputs-from . deploy-rs -- \
67+ .#${{ matrix.host }} \
68+ --skip-checks
Original file line number Diff line number Diff line change 3333 } ;
3434 nixos-hardware . url = "github:NixOS/nixos-hardware" ;
3535
36+ # Deployment
37+ deploy-rs = {
38+ url = "github:serokell/deploy-rs" ;
39+ inputs . nixpkgs . follows = "nixpkgs" ;
40+ } ;
41+
3642 # Linux
3743 disko = {
3844 url = "github:nix-community/disko" ;
116122 } ;
117123 } ;
118124
125+ deploy = {
126+ remoteBuild = false ;
127+
128+ nodes = {
129+ glyph = {
130+ hostname = "glyph" ;
131+ sshUser = "root" ;
132+ profiles . system = {
133+ user = "root" ;
134+ path =
135+ inputs . deploy-rs . lib . x86_64-linux . activate . nixos
136+ inputs . self . nixosConfigurations . glyph ;
137+ } ;
138+ } ;
139+
140+ spore = {
141+ hostname = "spore" ;
142+ sshUser = "root" ;
143+ profiles . system = {
144+ user = "root" ;
145+ path =
146+ inputs . deploy-rs . lib . x86_64-linux . activate . nixos
147+ inputs . self . nixosConfigurations . spore ;
148+ } ;
149+ } ;
150+
151+ zeta = {
152+ hostname = "zeta" ;
153+ sshUser = "root" ;
154+ profiles . system = {
155+ user = "root" ;
156+ path =
157+ inputs . deploy-rs . lib . aarch64-linux . activate . nixos
158+ inputs . self . nixosConfigurations . zeta ;
159+ } ;
160+ } ;
161+ } ;
162+ } ;
163+
164+ checks =
165+ builtins . mapAttrs
166+ ( system : deployLib : deployLib . deployChecks inputs . self . deploy )
167+ inputs . deploy-rs . lib ;
168+
119169 nixConfig = {
120170 experimental-features = [ "nix-command" "flakes" ] ;
121171 extra-substituters = [
Original file line number Diff line number Diff line change 1+ ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHoM/DCNtytZ/RlLaRYedKrL3ffuGlN7RywrROPx6Wp0 deploy@github-actions
Original file line number Diff line number Diff line change 1616 builtins . listToAttrs hostKeyPairs
1717 // {
1818 home = firstLine ( builtins . readFile ./../home/key.pub ) ;
19+ deploy = firstLine ( builtins . readFile ./deploy.pub ) ;
1920 }
Original file line number Diff line number Diff line change 99 users . users . root . openssh . authorizedKeys . keys = [
1010 keys . Rhizome
1111 keys . glyph
12+ keys . deploy
1213 ] ;
1314
1415 users . users . mu . openssh . authorizedKeys . keys = [
You can’t perform that action at this time.
0 commit comments