Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,6 @@ jobs:
nix profile install --inputs-from . attic#attic-client
attic login rc https://cache.zx.dev ${{ secrets.ATTIC_TOKEN }}
attic use rc:main
- run: nix flake check
- name: Build system configuration
run: |
if [ "${{ matrix.system }}" = "aarch64-darwin" ]; then
Expand Down
68 changes: 68 additions & 0 deletions .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
name: Deploy

on:
workflow_run:
workflows: ["CI"]
types: [completed]
branches: [main]
workflow_dispatch:

jobs:
deploy:
if: >-
github.event_name == 'workflow_dispatch' ||
github.event.workflow_run.conclusion == 'success'
strategy:
max-parallel: 1
matrix:
include:
- host: glyph
system: x86_64-linux
runner: ubuntu-latest
- host: spore
system: x86_64-linux
runner: ubuntu-latest
- host: zeta
system: aarch64-linux
runner: ubuntu-24.04-arm
runs-on: ${{ matrix.runner }}
steps:
- uses: actions/checkout@v4

- uses: cachix/install-nix-action@v31
with:
github_access_token: ${{ secrets.GITHUB_TOKEN }}
extra_nix_config: |
extra-substituters = https://cache.zx.dev/main
extra-trusted-public-keys = main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c=

- name: Configure Attic cache
run: |
nix profile install --inputs-from . attic#attic-client
attic login rc https://cache.zx.dev ${{ secrets.ATTIC_TOKEN }}
attic use rc:main

- name: Connect to Tailscale
uses: tailscale/github-action@v3
with:
oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }}
oauth-secret: ${{ secrets.TS_OAUTH_SECRET }}
tags: tag:ci

- name: Configure SSH
run: |
mkdir -p ~/.ssh
echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key
chmod 600 ~/.ssh/deploy_key
cat >> ~/.ssh/config <<EOF
Host glyph spore zeta
User root
IdentityFile ~/.ssh/deploy_key
StrictHostKeyChecking accept-new
EOF

- name: Deploy to ${{ matrix.host }}
run: |
nix run --inputs-from . deploy-rs -- \
.#${{ matrix.host }} \
--skip-checks
76 changes: 74 additions & 2 deletions flake.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

50 changes: 50 additions & 0 deletions flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,12 @@
};
nixos-hardware.url = "github:NixOS/nixos-hardware";

# Deployment
deploy-rs = {
url = "github:serokell/deploy-rs";
inputs.nixpkgs.follows = "nixpkgs";
};

# Linux
disko = {
url = "github:nix-community/disko";
Expand Down Expand Up @@ -116,6 +122,50 @@
};
};

deploy = {
remoteBuild = false;

nodes = {
glyph = {
hostname = "glyph";
sshUser = "root";
profiles.system = {
user = "root";
path =
inputs.deploy-rs.lib.x86_64-linux.activate.nixos
inputs.self.nixosConfigurations.glyph;
};
};

spore = {
hostname = "spore";
sshUser = "root";
profiles.system = {
user = "root";
path =
inputs.deploy-rs.lib.x86_64-linux.activate.nixos
inputs.self.nixosConfigurations.spore;
};
};

zeta = {
hostname = "zeta";
sshUser = "root";
profiles.system = {
user = "root";
path =
inputs.deploy-rs.lib.aarch64-linux.activate.nixos
inputs.self.nixosConfigurations.zeta;
};
};
};
};

checks =
builtins.mapAttrs
(system: deployLib: deployLib.deployChecks inputs.self.deploy)
inputs.deploy-rs.lib;

nixConfig = {
experimental-features = ["nix-command" "flakes"];
extra-substituters = [
Expand Down
1 change: 1 addition & 0 deletions lib/deploy.pub
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHoM/DCNtytZ/RlLaRYedKrL3ffuGlN7RywrROPx6Wp0 deploy@github-actions
1 change: 1 addition & 0 deletions lib/keys.nix
Original file line number Diff line number Diff line change
Expand Up @@ -16,4 +16,5 @@ in
builtins.listToAttrs hostKeyPairs
// {
home = firstLine (builtins.readFile ./../home/key.pub);
deploy = firstLine (builtins.readFile ./deploy.pub);
}
1 change: 1 addition & 0 deletions modules/nixos/ssh.nix
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@
users.users.root.openssh.authorizedKeys.keys = [
keys.Rhizome
keys.glyph
keys.deploy
];

users.users.mu.openssh.authorizedKeys.keys = [
Expand Down
Loading