Skip to content

Commit 3efad67

Browse files
stackptrclaude
andcommitted
feat: add deploy-rs for automated NixOS deployments via GitHub Actions
Integrates deploy-rs to enable push-based deployments to glyph, spore, and zeta after CI passes on main. Uses Tailscale for connectivity and Attic cache for pre-built closures. Magic rollback is enabled for safety. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
1 parent 7e6db42 commit 3efad67

6 files changed

Lines changed: 195 additions & 2 deletions

File tree

‎.github/workflows/deploy.yml‎

Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
name: Deploy
2+
3+
on:
4+
workflow_run:
5+
workflows: ["CI"]
6+
types: [completed]
7+
branches: [main]
8+
workflow_dispatch:
9+
10+
jobs:
11+
deploy:
12+
if: >-
13+
github.event_name == 'workflow_dispatch' ||
14+
github.event.workflow_run.conclusion == 'success'
15+
strategy:
16+
max-parallel: 1
17+
matrix:
18+
include:
19+
- host: glyph
20+
system: x86_64-linux
21+
runner: ubuntu-latest
22+
- host: spore
23+
system: x86_64-linux
24+
runner: ubuntu-latest
25+
- host: zeta
26+
system: aarch64-linux
27+
runner: ubuntu-24.04-arm
28+
runs-on: ${{ matrix.runner }}
29+
steps:
30+
- uses: actions/checkout@v4
31+
32+
- uses: cachix/install-nix-action@v31
33+
with:
34+
github_access_token: ${{ secrets.GITHUB_TOKEN }}
35+
extra_nix_config: |
36+
extra-substituters = https://cache.zx.dev/main
37+
extra-trusted-public-keys = main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c=
38+
39+
- name: Configure Attic cache
40+
run: |
41+
nix profile install --inputs-from . attic#attic-client
42+
attic login rc https://cache.zx.dev ${{ secrets.ATTIC_TOKEN }}
43+
attic use rc:main
44+
45+
- name: Connect to Tailscale
46+
uses: tailscale/github-action@v3
47+
with:
48+
oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }}
49+
oauth-secret: ${{ secrets.TS_OAUTH_SECRET }}
50+
tags: tag:ci
51+
52+
- name: Configure SSH
53+
run: |
54+
mkdir -p ~/.ssh
55+
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
56+
chmod 600 ~/.ssh/deploy_key
57+
cat >> ~/.ssh/config <<EOF
58+
Host glyph spore zeta
59+
User root
60+
IdentityFile ~/.ssh/deploy_key
61+
StrictHostKeyChecking accept-new
62+
EOF
63+
64+
- name: Deploy to ${{ matrix.host }}
65+
run: |
66+
nix run --inputs-from . deploy-rs -- \
67+
.#${{ matrix.host }} \
68+
--skip-checks

‎flake.lock‎

Lines changed: 74 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎flake.nix‎

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,12 @@
3333
};
3434
nixos-hardware.url = "github:NixOS/nixos-hardware";
3535

36+
# Deployment
37+
deploy-rs = {
38+
url = "github:serokell/deploy-rs";
39+
inputs.nixpkgs.follows = "nixpkgs";
40+
};
41+
3642
# Linux
3743
disko = {
3844
url = "github:nix-community/disko";
@@ -116,6 +122,50 @@
116122
};
117123
};
118124

125+
deploy = {
126+
remoteBuild = false;
127+
128+
nodes = {
129+
glyph = {
130+
hostname = "glyph";
131+
sshUser = "root";
132+
profiles.system = {
133+
user = "root";
134+
path =
135+
inputs.deploy-rs.lib.x86_64-linux.activate.nixos
136+
inputs.self.nixosConfigurations.glyph;
137+
};
138+
};
139+
140+
spore = {
141+
hostname = "spore";
142+
sshUser = "root";
143+
profiles.system = {
144+
user = "root";
145+
path =
146+
inputs.deploy-rs.lib.x86_64-linux.activate.nixos
147+
inputs.self.nixosConfigurations.spore;
148+
};
149+
};
150+
151+
zeta = {
152+
hostname = "zeta";
153+
sshUser = "root";
154+
profiles.system = {
155+
user = "root";
156+
path =
157+
inputs.deploy-rs.lib.aarch64-linux.activate.nixos
158+
inputs.self.nixosConfigurations.zeta;
159+
};
160+
};
161+
};
162+
};
163+
164+
checks =
165+
builtins.mapAttrs
166+
(system: deployLib: deployLib.deployChecks inputs.self.deploy)
167+
inputs.deploy-rs.lib;
168+
119169
nixConfig = {
120170
experimental-features = ["nix-command" "flakes"];
121171
extra-substituters = [

‎lib/deploy.pub‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHoM/DCNtytZ/RlLaRYedKrL3ffuGlN7RywrROPx6Wp0 deploy@github-actions

‎lib/keys.nix‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,4 +16,5 @@ in
1616
builtins.listToAttrs hostKeyPairs
1717
// {
1818
home = firstLine (builtins.readFile ./../home/key.pub);
19+
deploy = firstLine (builtins.readFile ./deploy.pub);
1920
}

‎modules/nixos/ssh.nix‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99
users.users.root.openssh.authorizedKeys.keys = [
1010
keys.Rhizome
1111
keys.glyph
12+
keys.deploy
1213
];
1314

1415
users.users.mu.openssh.authorizedKeys.keys = [

0 commit comments

Comments
 (0)