@cryptotaxi247 / infra-1 / commits / 462deab4

Drop virtualized macs

Using qemu for the macs seemed to work well for a while, but ultimately became really hard to manage. Especially with hardwarde and software upgrades which became more and more hostile to the idea. Once we get the hardware, owned macs back online we can reinstall macOS and enroll it in MDM instead. This commit also includes a nix-darwin.nix file, which is applied with MDM and https://github.com/DeterminateSystems/macos-ephemeral.

Graham Christensen committed Sep 26, 2022 at 08:15 UTC 462deab484ac2c76764910a8f1a6c45d792b98bd
30 files changed +43 -2133
delft/eris.nix
+1 -16
@@ -1,8 +1,6 @@
1 { resources, config, lib, pkgs, ... }:
2 let
3 inherit (lib) filterAttrs flip mapAttrsToList;
4 -
5 - macs = filterAttrs (_: v: (v.macosGuest or { }).enable or false) resources.machines;
4 in
5 {
6 imports = [
@@ -24,10 +22,7 @@ in
22 10.254.1.9 haumea
23
24 10.254.3.1 webserver
27 -
28 - '' + (toString (flip mapAttrsToList macs (machine: v: ''
29 - ${v.deployment.targetHost} ${machine}
30 - '')));
25 + '';
26
27 networking.firewall.allowedTCPPorts = [
28 443
@@ -242,16 +237,6 @@ in
237 ];
238 labels.role = "bastion";
239 }
245 - {
246 - targets = flip mapAttrsToList macs (machine: v: "${machine}:9101");
247 - labels.mac = "guest";
248 - labels.role = "builder";
249 - }
250 - {
251 - targets = flip mapAttrsToList macs (machine: v: "${machine}:9100");
252 - labels.mac = "host";
253 - labels.role = "builder";
254 - }
240 ];
241 }
242 {
delft/hydra.nix
+1 -58
@@ -88,52 +88,7 @@ in
88 ''
89 ServerAliveInterval 120
90 TCPKeepAlive yes
91 -
92 - Host mac1-guest
93 - Hostname 10.254.2.1
94 - Port 2200
95 - Compression yes
96 -
97 - Host mac2-guest
98 - Hostname 10.254.2.2
99 - Port 2200
100 - Compression yes
101 -
102 - Host mac3-guest
103 - Hostname 10.254.2.3
104 - Port 2200
105 - Compression yes
106 -
107 - Host mac4-guest
108 - Hostname 10.254.2.4
109 - Port 2200
110 - Compression yes
111 -
112 - Host mac5-guest
113 - Hostname 10.254.2.5
114 - Port 2200
115 - Compression yes
116 -
117 - Host mac6-guest
118 - Hostname 10.254.2.6
119 - Port 2200
120 - Compression yes
121 -
122 - Host mac7-guest
123 - Hostname 10.254.2.7
124 - Port 2200
125 - Compression yes
126 -
127 - Host mac8-guest
128 - Hostname 10.254.2.8
129 - Port 2200
130 - Compression yes
131 -
132 - Host mac9-guest
133 - Hostname 10.254.2.9
134 - Port 2200
135 - Compression yes
136 -
91 +
92 Host mac-m1-1
93 Hostname 10.254.2.101
94 Compression yes
@@ -202,18 +157,6 @@ in
157 services.openssh.knownHosts = {
158 "*.cloudscalehydra.detsys.dev" = { certAuthority = true; publicKey = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC6HhovazfX+rqm2YuOwgM1X16Z7bJpLLj4DXWUsuGGqG/OlwIyioVodKPd3dYwsltQD8W4YrWQCOXlqyV50xpngKJX6OXdDt0IWwwgHdW0bT/l+4Yd/B57PbSnXGKLwa7slBwMCGkxpivMwnkQm+1zfQEdVNX5UPiH6xwZSwgsaRHCpumpVUrLNWlWxI5+g3alez/mfp29bgSvMdnIu72Ykb8u0uKOvGVQY7UD9sVU00NSQ16m+NhvvFvVomIF6OXMinBkATuSsoa4jOIg4UTsS5mo8Up8RdZ1qyzxvqf874osn5sYkMVnRZ5G/0bmwdwyYs7mjKh3agt37Fnaj8obyfVRm9aRlKT+Gwc5U2XZF/AdhOq+TdRL2HgaNYwJspHYUQ2jm5YilOgcEfTOgunxDfMIGueqnM6nZoGe7EHA6affr8QLrOXEUVA9uwIMInpLWiDZXk74owDGhIpg8WBpWch+x3SqaLDwLlUYDseJR0BdH9al+UZW1eBinAiEVl6H7KzVLpLqYss38CWT9c7Cq/gltUuwIqgziXFCR4skXfpN5Ozg0Sr9OmkJbxHjGdOmMVT0VKC05KsUEkWW9J18WX3uN1O3Mqu7vWgK9VOqbsnsknP0oBSznniFZYblK0vRgcrKPMAGTZ7RMdTBbys28sj3HKY/CQPv08KV0xgOJQ=="; };
159
205 - # (for i in 10.254.2.{1,2,3,4,5,6,7,8,9}; do ssh-keyscan -t ssh-ed25519 -p 2200 $i 2> /dev/null; done) | sed -e 's/^/ { hostNames = [ "/' -e 's/ ssh/" ]; publicKey = "ssh/' -e 's/$/"; };/'; echo
206 -
207 - mac1-guest = { hostNames = [ "[10.254.2.1]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINkWZobdUDgoXyqzpcWUyBXz7pRCcqxRMS9z6Nyg8lJ/"; };
208 - mac2-guest = { hostNames = [ "[10.254.2.2]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICIzkQ2sjmphJL2oo1FSA/3F7/G+YTraWuPYUXBdZJ/t"; };
209 - mac3-guest = { hostNames = [ "[10.254.2.3]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHDnJQyL2LlWjIE+4wGBZyTapXlCgwTZ+uBh7eoaGPfL"; };
210 - mac4-guest = { hostNames = [ "[10.254.2.4]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBq44jmyZD6fQY+WLPH3Dx9mQXzCK7ZBpfmYjATVvT7T"; };
211 - mac5-guest = { hostNames = [ "[10.254.2.5]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEKH3SXo9u27y105FLNz1PxrDMBZ0gAsBsC9t2ErHbx4"; };
212 - mac6-guest = { hostNames = [ "[10.254.2.6]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBNU5/bIy24ea7twM6j7QAKs1KWJADYNfov94N9YjlVz"; };
213 - mac7-guest = { hostNames = [ "[10.254.2.7]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIN8AwqnYcZhj1jINB5HMAT+VBl+rPH9TCeHPtZMwMIUJ"; };
214 - mac8-guest = { hostNames = [ "[10.254.2.8]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAYH18PbDKKNmRaRYdMbbSqJSC+g5yB83LLSNemxhoCE"; };
215 - mac9-guest = { hostNames = [ "[10.254.2.9]:2200" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP4oOQBk3nRMKcPsDAL54jMAfSy9fwCyfH1qWwp1jwQt"; };
216 -
160 mac-m1-1 = { hostNames = [ "10.254.2.101" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILIpNE/evvR5mVLslm4G5AV6pQ2wdpIl7FPGDh5wZPLF"; };
161 mac-m1-2 = { hostNames = [ "10.254.2.102" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDyGCqoDh+BWnV1NIV2ucyb0WsXz5fH2hKDgC1dhN+Wq"; };
162 mac-m1-3 = { hostNames = [ "10.254.2.103" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGtPVTcBWTENjQ3e9ry7pOTFHk316Ahm3VW1Ys0cMhVf"; };
delft/network.nix
-135
@@ -4,51 +4,6 @@ let
4 networkoverlay = self: super: {
5 prometheus-postgres-exporter = self.callPackage ./prometheus/postgres-exporter.nix { };
6 };
7 -
8 - makeMac = { ip, extra, useCatalina ? false }: {
9 - deployment = {
10 - targetHost = ip;
11 - };
12 -
13 - # work around nix#3462
14 - documentation.nixos.enable = false;
15 -
16 - imports = [
17 - ../macs/host
18 - extra
19 - ({ lib, pkgs, ... }: {
20 - macosGuest = {
21 -
22 - enable = true;
23 - network = {
24 - interiorNetworkPrefix = "10.172.170"; #172="n", 170="x"
25 - externalInterface = "enp3s0f0";
26 - sshInterface = "wg0";
27 - };
28 -
29 - guest = {
30 - sockets = 1;
31 - cores = 2;
32 - threads = 2;
33 - memoryInMegs = 6 * 1024;
34 - ovmfCodeFile = ../macs/dist/OVMF_CODE.fd;
35 - ovmfVarsFile = ../macs/dist/OVMF_VARS-1024x768.fd;
36 - } // (if useCatalina then
37 - {
38 - zvolName = lib.mkForce "rpool/catalina";
39 - guestConfigDir = lib.mkForce ../macs/guest-catalina;
40 - cloverImage = (pkgs.callPackage ../macs/dist/clover-catalina { }).clover-image;
41 - }
42 - else
43 - {
44 - zvolName = "rpool/mac-hdd-2-initial-setup-startup-script.img";
45 - guestConfigDir = ../macs/guest;
46 - }
47 - );
48 - };
49 - })
50 - ];
51 - };
7 in
8 {
9 defaults = {
@@ -86,94 +41,4 @@ in
41 flakes.hydra.nixosModules.hydra
42 ];
43 };
89 -
90 - mac1 = makeMac {
91 - ip = "10.254.2.1";
92 - extra = { pkgs, lib, ... }: {
93 - imports = [
94 - ../macs/nodes/mac1.nix
95 - ];
96 -
97 - macosGuest = {
98 - guest = {
99 - zvolName = lib.mkForce "rpool/catalina";
100 - guestConfigDir = lib.mkForce ../macs/guest-catalina;
101 - cloverImage = (pkgs.callPackage ../macs/dist/clover-catalina { }).clover-image;
102 - };
103 - };
104 - };
105 - };
106 -
107 - mac2 = makeMac {
108 - ip = "10.254.2.2";
109 - useCatalina = false;
110 - extra = {
111 - imports = [
112 - ../macs/nodes/mac2.nix
113 - ];
114 - };
115 - };
116 -
117 - mac3 = makeMac {
118 - ip = "10.254.2.3";
119 - extra = {
120 - imports = [
121 - ../macs/nodes/mac3.nix
122 - ];
123 - };
124 - };
125 -
126 - mac4 = makeMac {
127 - ip = "10.254.2.4";
128 - extra = {
129 - imports = [
130 - ../macs/nodes/mac4.nix
131 - ];
132 - };
133 - };
134 -
135 - mac5 = makeMac {
136 - ip = "10.254.2.5";
137 - extra = {
138 - imports = [
139 - ../macs/nodes/mac5.nix
140 - ];
141 - };
142 - };
143 -
144 - mac6 = makeMac {
145 - ip = "10.254.2.6";
146 - extra = {
147 - imports = [
148 - ../macs/nodes/mac6.nix
149 - ];
150 - };
151 - };
152 -
153 - mac7 = makeMac {
154 - ip = "10.254.2.7";
155 - extra = {
156 - imports = [
157 - ../macs/nodes/mac7.nix
158 - ];
159 - };
160 - };
161 -
162 - mac8 = makeMac {
163 - ip = "10.254.2.8";
164 - extra = {
165 - imports = [
166 - ../macs/nodes/mac8.nix
167 - ];
168 - };
169 - };
170 -
171 - mac9 = makeMac {
172 - ip = "10.254.2.9";
173 - extra = {
174 - imports = [
175 - ../macs/nodes/mac8.nix
176 - ];
177 - };
178 - };
44 }
macs/README.md deleted
-91
@@ -1,91 +0,0 @@
1 -# MacOS Infrastructure
2 -
3 -Contained are Nix expression for deploying the hydra.nixos.org macOS
4 -infrastructure. Each computer is genuine Apple hardware running NixOS
5 -on the host, with macOS using almost all of the host's resources in an
6 -immutable QEMU virtual machine.
7 -
8 -The virtualisation of macOS seems to be a less error-prone, and easier
9 -to recover from problems.
10 -
11 -
12 -## Bootstrapping a new mac
13 -
14 -### Initial Setup
15 -
16 -We distribute the macOS image with `zfs send` / `zfs receive`. First
17 -enable ZFS in the installation environment.
18 -
19 -1. Add `boot.supportedFilesystems = [ "zfs" ];` to
20 - `/etc/nixos/configuration.nix`
21 -2. Run `nixos-rebuild switch`
22 -3. `modprobe zfs`
23 -
24 -### Partitioning, Formatting, Mounting
25 -
26 -1. Partition the disk:
27 -
28 -```
29 -parted /dev/sda -- mklabel gpt
30 -parted /dev/sda -- mkpart primary 512MiB -16GiB
31 -parted /dev/sda -- mkpart primary linux-swap -16GiB -1MiB
32 -parted /dev/sda -- mkpart ESP fat32 1MiB 512MiB
33 -parted /dev/sda -- set 3 boot on
34 -```
35 -
36 -2. Create a zpool with `/dev/sda1` and mount it:
37 -```
38 -zpool create -o ashift=12 -o altroot=/mnt rpool /dev/sda1
39 -zfs create -o mountpoint=legacy rpool/root
40 -mount -t zfs rpool/root/nixos /mnt
41 -```
42 -_note: ashift=12 is copypasta, maybe somebody knows better_
43 -
44 -3. Create the EFI System Partition and mount it:
45 -
46 -```
47 -mkfs.fat -F 32 -n boot /dev/sda3
48 -mkdir /mnt/boot
49 -mount /dev/sda3 /mnt/boot
50 -```
51 -
52 -4. Create and enable swap:
53 -
54 -```
55 -mkswap -L swap /dev/sda2
56 -swapon /dev/sda2
57 -```
58 -
59 -### Generate Configuration
60 -
61 -1. Generate the config
62 -
63 -```
64 -nixos-generate-config --root /mnt
65 -```
66 -
67 -2. Generate a host ID with `head -c 8 /etc/machine-id` , we'll refer
68 - to it soon.
69 -
70 -3. Edit `/mnt/etc/nixos/hardware-configuration.nix` and:
71 -
72 - - change the `/boot` fs device to `/dev/disk/by-label/boot`
73 - - change the `swap` device to `/dev/disk/by-label/swap`
74 - - delete the `cpuFreqGovernor` line
75 - - add `boot.supportedFilesystems = [ "zfs" ];`
76 - - add `networking.hostId = "the-host-id-you-generated";`
77 - - add `nixpkgs.config.allowUnfree = true;` if the `broadcom-sta`
78 - kernel module is enabled.
79 -
80 -### Install
81 -
82 -Run `nixos-install` and reboot.
83 -
84 -### Addition to the NixOps Network
85 -
86 -calculate your own `-smp` line like this:
87 -
88 - - cores: # of cores per socket
89 - - threads: # of threads per core, ie: hyperthreading? set to 2, none? set to 1
90 - - sockets: # of physical sockets in the system
91 - - cpus = * cores * threads * sockets
macs/bootstrap-macmini deleted
-50
@@ -1,50 +0,0 @@
1 -#!/usr/bin/env bash
2 -
3 -set -ex
4 -
5 -parted /dev/sda -- mklabel gpt
6 -parted /dev/sda -- mkpart primary 512MiB -16GiB
7 -parted /dev/sda -- mkpart primary linux-swap -16GiB -1MiB
8 -parted /dev/sda -- mkpart ESP fat32 1MiB 512MiB
9 -parted /dev/sda -- set 3 boot on
10 -
11 -zpool create -o ashift=12 -o altroot=/mnt rpool /dev/sda1
12 -zfs create -o mountpoint=legacy rpool/root
13 -mount -t zfs rpool/root /mnt
14 -
15 -mkfs.fat -F 32 -n boot /dev/sda3
16 -mkdir /mnt/boot
17 -mount /dev/sda3 /mnt/boot
18 -
19 -mkswap -L swap /dev/sda2
20 -
21 -nixos-generate-config --root /mnt
22 -
23 -hostId=$(head -c 8 /etc/machine-id)
24 -
25 -cat > /mnt/etc/nixos/bootstrap-config.nix <<EOF
26 -{ config, pkgs, lib, ...}:
27 -{ boot.supportedFilesystems = [ "zfs" ];
28 - networking.hostId = "$hostId";
29 - nixpkgs.config.allowUnfree = true;
30 - fileSystems."/boot".device = lib.mkOverride 0 "/dev/disk/by-label/boot";
31 - swapDevices = lib.mkOverride 0 [ { device = "/dev/disk/by-label/swap"; } ];
32 -}
33 -EOF
34 -
35 -sed -i 's|powerManagement.cpuFreqGovernor|#powerManagement.cpuFreqGovernor|' /mnt/etc/nixos/hardware-configuration.nix
36 -
37 -sed -i 's|hardware-configuration.nix|hardware-configuration.nix ./bootstrap-config.nix|' /mnt/etc/nixos/configuration.nix
38 -
39 -sed -i 's|# services.openssh.enable|services.openssh.enable|' /mnt/etc/nixos/configuration.nix
40 -
41 -mkdir -p /mnt/root/.ssh
42 -chmod 0700 /mnt/root
43 -chmod 0700 /mnt/root/.ssh
44 -cat > /mnt/root/.ssh/authorized_keys <<EOF
45 -ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDHp3/OZP2nRS5bM9E1xN8Q2L398kC+m4guORjKsmGjwnnHvYnTml5puE2ogl8Wdenbk7hf82+vKyB+Tktrhx+IBSym4lY+czR6W+39hlPYdLbi980yxYT9KEMSyMWJEgPVJ1BZvHqsHQiad/L3eoPmAIMDmcn4mLh9rya5/oMW/ZgsA6j28ClvWkDRyaTmTLOa0Im4nLoSbdo8kJqU+JX/YcXlMKUvFfdMcj4T9YYwV98LPWHnEHFmjtBBUXRUAIESMXS6pm3Pep3czkKUL4UF0u9f17b40OWlLOF4IQWE2jM9yK09DiIQUzeU2XKRNW116DnmDL5QIRNrYnhkYeeQI3U6WnVTPdTU9kBVTDjhM+6U6/LClGJaWiglwwrzHtVELHgMi280qRefQEftb4CI/IbcPNAxetJevV68I5NAjfdnmMx8YbhfIiEqAJtBi4TvoH7HjDH+72+ZFjQ10fpz/p+DgUtiNlRKz8tXSZ+mbLuhmOJOxtGQTH3viYbSpG/4F9uKW1ekX0RMyRxVvpjMxHtCL4daJI4RTHFXy4R16OKAlYe7gs9sqv7O0IujLJPex/rnN2U4syGaSH5q3UnGxci6qgn8yLEhSP+Gj0xdv5H3fVjr/kNNZGWDOz6nDUaJT+eWlmWU7hOvm0ricrz9GEPUTQ0Rh70sWTQFq3poWQ== cardno:000606167509
46 -ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDY8wRHQtq9uBzdiAYzpSNmF+nmIHmW+AOeBTDNmdva+CFGIBbB56q7w6GCOhfXs8edrPY4qOcQGaOD0ussIvHnqkVfw8e6CbxnpXKeAuIz7+1V72AhLPzOkif4yPrI6tSYF5nvzq6U4Yk1qFnXiLQjkA1s4EcZH6V0KbHMsu7Mtv3Irspdn8KUI3j2UwZcssFu1EuLHhLNussziRQK9tOg9ixb0U1WXuUJn7Noh9odTAsAt6jLFdr5eN/IINgC9WQqvY/W94Tc2/z5TWR7z382pEkMBR/3sf+nYKA82069tagkyrtJ/YXi00CWU4vjpnMvwPEYcmtCddfCPi8ZIUrn grahamc@Morbo
47 -EOF
48 -chmod 0600 /mnt/root/.ssh/authorized_keys
49 -
50 -nixos-install
macs/dist/OVMF_CODE.fd
Binary files a/macs/dist/OVMF_CODE.fd and /dev/null differ
macs/dist/OVMF_VARS-1024x768.fd
Binary files a/macs/dist/OVMF_VARS-1024x768.fd and /dev/null differ
macs/dist/clover-catalina/config.plist.template deleted
-53
@@ -1,53 +0,0 @@
1 -<?xml version="1.0" encoding="UTF-8"?>
2 -<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
3 -<plist version="1.0">
4 -<dict>
5 - <key>Boot</key>
6 - <dict>
7 - <key>Arguments</key>
8 - <string>@params@</string>
9 - <key>DefaultVolume</key>
10 - <string>system</string>
11 - <key>Log</key>
12 - <true/>
13 - <key>Secure</key>
14 - <false/>
15 - <key>Timeout</key>
16 - <integer>@timeout@</integer>
17 - </dict>
18 - <key>GUI</key>
19 - <dict>
20 - <key>Scan</key>
21 - <dict>
22 - <key>Entries</key>
23 - <true/>
24 - <key>Tool</key>
25 - <true/>
26 - </dict>
27 - <key>ScreenResolution</key>
28 - <string>@resolution@</string>
29 - <key>Theme</key>
30 - <string>embedded</string>
31 - </dict>
32 - <key>RtVariables</key>
33 - <dict>
34 - <key>BooterConfig</key>
35 - <string>0x28</string>
36 - <key>CsrActiveConfig</key>
37 - <string>@csrFlag@</string>
38 - </dict>
39 - <key>SMBIOS</key>
40 - <dict>
41 - <key>Trust</key>
42 - <false/>
43 - </dict>
44 - <key>SystemParameters</key>
45 - <dict>
46 - <key>InjectKexts</key>
47 - <false/>
48 - <key>InjectSystemID</key>
49 - <true/>
50 - </dict>
51 -</dict>
52 -</plist>
53 -
macs/dist/clover-catalina/default.nix deleted
-89
@@ -1,89 +0,0 @@
1 -{ lib
2 -, runCommand
3 -, fetchurl
4 -, libguestfs
5 -, libguestfs-appliance
6 -, p7zip
7 -, resolution ? "1024x768"
8 -, csrFlag ? "0x3"
9 -, params ? "-v"
10 -, timeout ? "3"
11 -# https://github.com/Clover-EFI-Bootloader/clover/blob/6b8018b1fec958d672951f87cefd8b6cfd5318ac/rEFIt_UEFI/Platform/boot.h#L127-L135
12 -}:
13 -
14 -lib.fix (self: {
15 - clover-image = runCommand "clover.qcow2" {
16 - buildInputs = [ libguestfs ];
17 - inherit resolution csrFlag params timeout;
18 - LIBGUESTFS_PATH = libguestfs-appliance;
19 - } ''
20 - export HOME=$NIX_BUILD_TOP
21 - mkdir work
22 - cp --no-preserve=mode ${self.clover-iso} clover.iso
23 - guestfish -a clover.iso -m "/dev/sda:/:norock" <<EOF
24 - copy-out /EFI work
25 - EOF
26 - eval $(guestfish --listen)
27 - guestfish --remote disk-create clover2.img qcow2 256M
28 - guestfish --remote add clover2.img
29 - time guestfish --remote run
30 - guestfish --remote part-init /dev/sda gpt
31 - guestfish --remote part-add /dev/sda p 2048 200000
32 - guestfish --remote -- part-add /dev/sda p 202048 -2048
33 - guestfish --remote part-set-gpt-type /dev/sda 1 C12A7328-F81F-11D2-BA4B-00A0C93EC93B
34 - guestfish --remote part-set-bootable /dev/sda 1 true
35 - guestfish --remote mkfs vfat /dev/sda1 label:EFI
36 - guestfish --remote mkfs vfat /dev/sda2 label:clover
37 - guestfish --remote mount /dev/sda2 /
38 - guestfish --remote mkdir /ESP
39 - guestfish --remote mount /dev/sda1 /ESP
40 -
41 - guestfish --remote mkdir /ESP/EFI
42 - guestfish --remote mkdir /ESP/EFI/CLOVER
43 - guestfish --remote mkdir /ESP/EFI/CLOVER/kexts
44 - guestfish --remote mkdir /ESP/EFI/CLOVER/kexts/Other
45 - guestfish --remote copy-in work/EFI/BOOT /ESP/EFI
46 - guestfish --remote copy-in work/EFI/CLOVER/CLOVERX64.efi /ESP/EFI/CLOVER
47 -
48 - guestfish --remote copy-in work/EFI/CLOVER/drivers /ESP/EFI/CLOVER
49 - guestfish --remote copy-in work/EFI/CLOVER/drivers/off/PartitionDxe.efi /ESP/EFI/CLOVER/drivers/UEFI
50 - guestfish --remote copy-in work/EFI/CLOVER/drivers/off/ApfsDriverLoader.efi /ESP/EFI/CLOVER/drivers/UEFI
51 -
52 - cp --no-preserve=mode ${self.startup-nsh} startup.nsh
53 - guestfish --remote copy-in startup.nsh /
54 -
55 - guestfish --remote copy-in work/EFI/CLOVER/drivers/off/AppleImageCodec.efi /ESP/EFI/CLOVER/drivers/UEFI
56 - guestfish --remote copy-in work/EFI/CLOVER/drivers/off/FirmwareVolume.efi /ESP/EFI/CLOVER/drivers/UEFI
57 - guestfish --remote copy-in work/EFI/CLOVER/drivers/off/AppleKeyAggregator.efi /ESP/EFI/CLOVER/drivers/UEFI
58 - guestfish --remote copy-in work/EFI/CLOVER/drivers/off/AppleUITheme.efi /ESP/EFI/CLOVER/drivers/UEFI
59 - guestfish --remote copy-in work/EFI/CLOVER/drivers/off/AppleKeyFeeder.efi /ESP/EFI/CLOVER/drivers/UEFI
60 - guestfish --remote copy-in work/EFI/CLOVER/drivers/off/HashServiceFix.efi /ESP/EFI/CLOVER/drivers/UEFI
61 -
62 - guestfish --remote copy-in work/EFI/CLOVER/drivers/UEFI/VBoxHfs.efi /ESP/EFI/CLOVER/drivers/UEFI
63 - guestfish --remote copy-in work/EFI/CLOVER/drivers/UEFI/SMCHelper.efi /ESP/EFI/CLOVER/drivers/UEFI
64 - guestfish --remote copy-in work/EFI/CLOVER/drivers/UEFI/FSInject.efi /ESP/EFI/CLOVER/drivers/UEFI
65 - guestfish --remote copy-in work/EFI/CLOVER/drivers/UEFI/AptioInputFix.efi /ESP/EFI/CLOVER/drivers/UEFI
66 -
67 - guestfish --remote copy-in work/EFI/CLOVER/tools /ESP/EFI/CLOVER
68 - substituteAll ${./config.plist.template} work/config.plist
69 - guestfish --remote copy-in work/config.plist /ESP/EFI/CLOVER
70 - guestfish --remote rm /ESP/EFI/CLOVER/drivers/UEFI/AudioDxe.efi
71 - guestfish --remote umount-all
72 - guestfish --remote shutdown
73 - mv clover2.img $out
74 - '';
75 - cloverVersion = "5130";
76 - clover-iso-7z = fetchurl {
77 - url = "https://github.com/CloverHackyColor/CloverBootloader/releases/download/${self.cloverVersion}/Clover-${self.cloverVersion}-X64.iso.7z";
78 - sha256 = "0fv0mw03fjqvlhrnv9zixp88dm3ak4sjq84kfs7m6zglq83ar2lx";
79 - };
80 - clover-iso = runCommand "clover.iso" { buildInputs = [ p7zip ]; } ''
81 - 7z x ${self.clover-iso-7z}
82 - mv -v *.iso $out
83 - '';
84 - # https://github.com/kholia/OSX-KVM/blob/bda4cc8e698356510c27747b7a929339f450890c/Catalina/startup.nsh
85 - startup-nsh = runCommand "startup.nsh" {} ''
86 - echo "fs0:\EFI\CLOVER\CLOVERX64.efi" > $out
87 - '';
88 -})
89 -
macs/dist/config.plist.template deleted
-53
@@ -1,53 +0,0 @@
1 -<?xml version="1.0" encoding="UTF-8"?>
2 -<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
3 -<plist version="1.0">
4 -<dict>
5 - <key>Boot</key>
6 - <dict>
7 - <key>Arguments</key>
8 - <string>@params@</string>
9 - <key>DefaultVolume</key>
10 - <string>system</string>
11 - <key>Log</key>
12 - <true/>
13 - <key>Secure</key>
14 - <false/>
15 - <key>Timeout</key>
16 - <integer>@timeout@</integer>
17 - </dict>
18 - <key>GUI</key>
19 - <dict>
20 - <key>Scan</key>
21 - <dict>
22 - <key>Entries</key>
23 - <true/>
24 - <key>Tool</key>
25 - <true/>
26 - </dict>
27 - <key>ScreenResolution</key>
28 - <string>@resolution@</string>
29 - <key>Theme</key>
30 - <string>embedded</string>
31 - </dict>
32 - <key>RtVariables</key>
33 - <dict>
34 - <key>BooterConfig</key>
35 - <string>0x28</string>
36 - <key>CsrActiveConfig</key>
37 - <string>@csrFlag@</string>
38 - </dict>
39 - <key>SMBIOS</key>
40 - <dict>
41 - <key>Trust</key>
42 - <false/>
43 - </dict>
44 - <key>SystemParameters</key>
45 - <dict>
46 - <key>InjectKexts</key>
47 - <false/>
48 - <key>InjectSystemID</key>
49 - <true/>
50 - </dict>
51 -</dict>
52 -</plist>
53 -
macs/guest-catalina/apply.sh deleted
-108
@@ -1,108 +0,0 @@
1 -#!/usr/bin/env bash
2 -
3 -LOGHOST=10.172.170.1
4 -echo "apply started at $(date)" | nc -w0 -u $LOGHOST 1514
5 -
6 -printf "\n*.*\t@$LOGHOST:1514\n" | tee -a /etc/syslog.conf
7 -pkill syslog
8 -pkill asl
9 -
10 -exec 3>&1
11 -exec 2> >(nc -u $LOGHOST 1514)
12 -exec 1>&2
13 -
14 -PS4='${BASH_SOURCE}::${FUNCNAME[0]}::$LINENO '
15 -set -o pipefail
16 -set -ex
17 -date
18 -
19 -function finish {
20 - set +e
21 - cd /
22 - sleep 1
23 - umount -f /Volumes/CONFIG
24 -}
25 -trap finish EXIT
26 -
27 -cat <<EOF | tee -a /etc/ssh/sshd_config
28 -PermitRootLogin prohibit-password
29 -PasswordAuthentication no
30 -PermitEmptyPasswords no
31 -ChallengeResponseAuthentication no
32 -EOF
33 -
34 -launchctl stop com.openssh.sshd
35 -launchctl start com.openssh.sshd
36 -
37 -
38 -cd /Volumes/CONFIG
39 -
40 -cp -r ./etc/ssh/ssh_host_* /etc/ssh
41 -chown root:wheel /etc/ssh/ssh_host_*
42 -chmod 600 /etc/ssh/ssh_host_*
43 -cd /
44 -
45 -echo "%admin ALL = NOPASSWD: ALL" | tee /etc/sudoers.d/passwordless
46 -
47 -(
48 - # Make this thing work as root
49 - export USER=root
50 - export HOME=~root
51 - export ALLOW_PREEXISTING_INSTALLATION=1
52 - env
53 - curl -vL https://nixos.org/releases/nix/nix-2.3.10/install > ~nixos/install-nix
54 - chmod +rwx ~nixos/install-nix
55 - cat /dev/null | sudo -i -H -u nixos -- sh ~nixos/install-nix --daemon --darwin-use-unencrypted-nix-store-volume
56 -)
57 -
58 -(
59 - # Make this thing work as root
60 - export USER=root
61 - export HOME=~root
62 -
63 - . '/nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh'
64 - env
65 - ls -la /private || true
66 - ls -la /private/var || true
67 - ls -la /private/var/run || true
68 - ln -s /private/var/run /run || true
69 -
70 - # todo: clean up this channel business, which is complicated because
71 - # channels on darwin are a bit ill defined and have a very bad UX.
72 - # If me, Graham, the author of the multi-user darwin installer can't
73 - # even figure this out, how can I possibly expect anybody else to know.
74 - nix-channel --add https://github.com/LnL7/nix-darwin/archive/master.tar.gz darwin
75 - nix-channel --add https://nixos.org/channels/nixpkgs-20.09-darwin nixpkgs
76 - nix-channel --update
77 -
78 - sudo -i -H -u nixos -- nix-channel --add https://github.com/LnL7/nix-darwin/archive/master.tar.gz darwin
79 - sudo -i -H -u nixos -- nix-channel --add https://nixos.org/channels/nixpkgs-20.09-darwin nixpkgs
80 - sudo -i -H -u nixos -- nix-channel --update
81 -
82 - export NIX_PATH=$NIX_PATH:darwin=https://github.com/LnL7/nix-darwin/archive/master.tar.gz
83 -
84 - installer=$(nix-build https://github.com/LnL7/nix-darwin/archive/master.tar.gz -A installer --no-out-link)
85 - set +e
86 - yes | sudo -i -H -u nixos -- $installer/bin/darwin-installer;
87 - echo $?
88 - set -e
89 -)
90 -
91 -(
92 - export USER=root
93 - export HOME=~root
94 -
95 - rm -f /etc/nix/nix.conf
96 - rm -f /etc/bashrc
97 - ln -s /etc/static/bashrc /etc/bashrc
98 - . /etc/static/bashrc
99 - cat /Volumes/CONFIG/darwin-configuration.nix | sudo -u nixos -- tee ~nixos/.nixpkgs/darwin-configuration.nix
100 -
101 - while ! sudo -i -H -u nixos -- nix ping-store; do
102 - cat /var/log/nix-daemon.log
103 - sleep 1
104 - done
105 -
106 - sudo -i -H -u nixos -- darwin-rebuild switch
107 -)
108 -
macs/guest/apply.sh deleted
-106
@@ -1,106 +0,0 @@
1 -#!/usr/bin/env bash
2 -
3 -echo "apply started at $(date)" | nc -w0 -u 10.172.170.1 1514
4 -
5 -printf '\n*.*\t@10.172.170.1:1514\n' | tee -a /etc/syslog.conf
6 -pkill syslog
7 -pkill asl
8 -
9 -exec 3>&1
10 -exec 2> >(nc -u 10.172.170.1 1514)
11 -exec 1>&2
12 -
13 -PS4='${BASH_SOURCE}::${FUNCNAME[0]}::$LINENO '
14 -set -o pipefail
15 -set -ex
16 -date
17 -
18 -function finish {
19 - set +e
20 - cd /
21 - sleep 1
22 - umount -f /Volumes/CONFIG
23 -}
24 -trap finish EXIT
25 -
26 -cat <<EOF | tee -a /etc/ssh/sshd_config
27 -PermitRootLogin prohibit-password
28 -PasswordAuthentication no
29 -PermitEmptyPasswords no
30 -ChallengeResponseAuthentication no
31 -EOF
32 -
33 -launchctl stop com.openssh.sshd
34 -launchctl start com.openssh.sshd
35 -
36 -
37 -cd /Volumes/CONFIG
38 -
39 -cp -r ./etc/ssh/ssh_host_* /etc/ssh
40 -chown root:wheel /etc/ssh/ssh_host_*
41 -chmod 600 /etc/ssh/ssh_host_*
42 -cd /
43 -
44 -echo "%admin ALL = NOPASSWD: ALL" | tee /etc/sudoers.d/passwordless
45 -
46 -(
47 - # Make this thing work as root
48 - export USER=root
49 - export HOME=~root
50 - export ALLOW_PREEXISTING_INSTALLATION=1
51 - env
52 -
53 - sudo -i -H -u nixos -- sh /Volumes/CONFIG/install --daemon < /dev/null
54 -)
55 -
56 -(
57 - # Make this thing work as root
58 - export USER=root
59 - export HOME=~root
60 -
61 - . '/nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh'
62 - env
63 - ls -la /private || true
64 - ls -la /private/var || true
65 - ls -la /private/var/run || true
66 - ln -s /private/var/run /run || true
67 -
68 - # todo: clean up this channel business, which is complicated because
69 - # channels on darwin are a bit ill defined and have a very bad UX.
70 - # If me, Graham, the author of the multi-user darwin installer can't
71 - # even figure this out, how can I possibly expect anybody else to know.
72 - nix-channel --add https://github.com/LnL7/nix-darwin/archive/master.tar.gz darwin
73 - nix-channel --add https://nixos.org/channels/nixpkgs-20.09-darwin nixpkgs
74 - nix-channel --update
75 -
76 - sudo -i -H -u nixos -- nix-channel --add https://github.com/LnL7/nix-darwin/archive/master.tar.gz darwin
77 - sudo -i -H -u nixos -- nix-channel --add https://nixos.org/channels/nixpkgs-20.09-darwin nixpkgs
78 - sudo -i -H -u nixos -- nix-channel --update
79 -
80 - export NIX_PATH=$NIX_PATH:darwin=https://github.com/LnL7/nix-darwin/archive/master.tar.gz
81 -
82 - installer=$(nix-build https://github.com/LnL7/nix-darwin/archive/master.tar.gz -A installer --no-out-link)
83 - set +e
84 - yes | sudo -i -H -u nixos -- $installer/bin/darwin-installer;
85 - echo $?
86 - set -e
87 -)
88 -
89 -(
90 - export USER=root
91 - export HOME=~root
92 -
93 - rm -f /etc/nix/nix.conf
94 - rm -f /etc/bashrc
95 - ln -s /etc/static/bashrc /etc/bashrc
96 - . /etc/static/bashrc
97 - cat /Volumes/CONFIG/darwin-configuration.nix | sudo -u nixos -- tee ~nixos/.nixpkgs/darwin-configuration.nix
98 -
99 - while ! sudo -i -H -u nixos -- nix ping-store; do
100 - cat /var/log/nix-daemon.log
101 - sleep 1
102 - done
103 -
104 - sudo -i -H -u nixos -- darwin-rebuild switch
105 -)
106 -
macs/guest/darwin-configuration.nix deleted
-73
@@ -1,73 +0,0 @@
1 -{ config, lib, pkgs, ... }:
2 -
3 -with lib;
4 -
5 -let
6 - sshKeys = rec {
7 - hydra-queue-runner = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCyM48VC5fpjJssLI8uolFscP4/iEoMHfkPoT9R3iE3OEjadmwa1XCAiXUoa7HSshw79SgPKF2KbGBPEVCascdAcErZKGHeHUzxj7v3IsNjObouUOBbJfpN4DR7RQT28PZRsh3TvTWjWnA9vIrSY/BvAK1uezFRuObvatqAPMrw4c0DK+JuGuCNkKDGHLXNSxYBc5Pmr1oSU7/BDiHVjjyLIsAMIc20+q8SjWswKqL1mY193mN7FpUMBtZrd0Za9fMFRII9AofEIDTOayvOZM6+/1dwRWZXM6jhE6kaPPF++yromHvDPBnd6FfwODKLvSF9BkA3pO5CqrD8zs7ETmrV hydra-queue-runner@chef";
8 - };
9 - environment = concatStringsSep " "
10 - [
11 - "NIX_SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
12 - ];
13 -
14 - authorizedNixStoreKey = key:
15 - "command=\"${environment} ${config.nix.package}/bin/nix-store --serve --write\" ${key}";
16 -in
17 -
18 -{
19 - environment.systemPackages =
20 - [
21 - config.nix.package
22 - ];
23 -
24 - programs.bash.enable = true;
25 - programs.bash.enableCompletion = false;
26 -
27 - #services.activate-system.enable = true;
28 -
29 - services.nix-daemon.enable = true;
30 -
31 - nix.maxJobs = 4;
32 - nix.buildCores = 1;
33 - nix.gc.automatic = true;
34 - nix.gc.interval = { Minute = 15; };
35 - nix.gc.options = let
36 - gbFree = 50;
37 - in "--max-freed $((${toString gbFree} * 1024**3 - 1024 * $(df -P -k /nix/store | tail -n 1 | awk '{ print $4 }')))";
38 -
39 - # If we drop below 20GiB during builds, free 20GiB
40 - nix.extraOptions = ''
41 - min-free = ${toString (30*1024*1024*1024)}
42 - max-free = ${toString (50*1024*1024*1024)}
43 - '';
44 -
45 - environment.etc."per-user/root/ssh/authorized_keys".text = concatStringsSep "\n"
46 - ([
47 - (authorizedNixStoreKey sshKeys.hydra-queue-runner)
48 - ]);
49 -
50 -
51 - system.activationScripts.postActivation.text = ''
52 - printf "disabling spotlight indexing... "
53 - mdutil -i off -d / &> /dev/null
54 - mdutil -E / &> /dev/null
55 - echo "ok"
56 -
57 - printf "configuring ssh keys for hydra on the root account... "
58 - mkdir -p ~root/.ssh
59 - cp -f /etc/per-user/root/ssh/authorized_keys ~root/.ssh/authorized_keys
60 - chown root:wheel ~root ~root/.ssh ~root/.ssh/authorized_keys
61 - echo "ok"
62 - '';
63 -
64 - launchd.daemons.prometheus-node-exporter = {
65 - script = ''
66 - exec ${pkgs.prometheus-node-exporter}/bin/node_exporter
67 - '';
68 -
69 - serviceConfig.KeepAlive = true;
70 - serviceConfig.StandardErrorPath = "/var/log/prometheus-node-exporter.log";
71 - serviceConfig.StandardOutPath = "/var/log/prometheus-node-exporter.log";
72 - };
73 -}
macs/host/clover.qcow2.nix deleted
-64
@@ -1,64 +0,0 @@
1 -{ lib
2 -, runCommand
3 -, fetchurl
4 -, libguestfs
5 -, libguestfs-appliance
6 -, resolution ? "1024x768"
7 -, csrFlag ? "0x3"
8 -, params ? "-v"
9 -, timeout ? "3"
10 -# https://github.com/Clover-EFI-Bootloader/clover/blob/6b8018b1fec958d672951f87cefd8b6cfd5318ac/rEFIt_UEFI/Platform/boot.h#L127-L135
11 -}:
12 -
13 -lib.fix (self: {
14 - clover-image = runCommand "clover.qcow2" {
15 - buildInputs = [ libguestfs ];
16 - inherit resolution csrFlag params timeout;
17 - LIBGUESTFS_PATH = libguestfs-appliance;
18 - } ''
19 - export HOME=$NIX_BUILD_TOP
20 - mkdir work
21 - cp --no-preserve=mode ${self.clover-iso} clover.iso
22 - guestfish -a clover.iso -m "/dev/sda:/:norock" <<EOF
23 - copy-out /EFI work
24 - EOF
25 - eval $(guestfish --listen)
26 - guestfish --remote disk-create clover2.img qcow2 256M
27 - guestfish --remote add clover2.img
28 - time guestfish --remote run
29 - guestfish --remote part-init /dev/sda gpt
30 - guestfish --remote part-add /dev/sda p 2048 200000
31 - guestfish --remote -- part-add /dev/sda p 202048 -2048
32 - guestfish --remote part-set-gpt-type /dev/sda 1 C12A7328-F81F-11D2-BA4B-00A0C93EC93B
33 - guestfish --remote part-set-bootable /dev/sda 1 true
34 - guestfish --remote mkfs vfat /dev/sda1 label:EFI
35 - guestfish --remote mkfs vfat /dev/sda2 label:clover
36 - guestfish --remote mount /dev/sda2 /
37 - guestfish --remote mkdir /ESP
38 - guestfish --remote mount /dev/sda1 /ESP
39 - guestfish --remote mkdir /ESP/EFI
40 - guestfish --remote mkdir /ESP/EFI/CLOVER
41 - guestfish --remote copy-in work/EFI/BOOT /ESP/EFI
42 - guestfish --remote copy-in work/EFI/CLOVER/CLOVERX64.efi /ESP/EFI/CLOVER
43 - guestfish --remote copy-in work/EFI/CLOVER/drivers64UEFI /ESP/EFI/CLOVER
44 - guestfish --remote copy-in work/EFI/CLOVER/drivers-Off/drivers64UEFI/PartitionDxe-64.efi /ESP/EFI/CLOVER/drivers64UEFI
45 - guestfish --remote copy-in work/EFI/CLOVER/drivers-Off/drivers64UEFI/ApfsDriverLoader-64.efi /ESP/EFI/CLOVER/drivers64UEFI
46 - guestfish --remote copy-in work/EFI/CLOVER/drivers-Off/drivers64UEFI/OsxAptioFix3Drv-64.efi /ESP/EFI/CLOVER/drivers64UEFI
47 - guestfish --remote copy-in work/EFI/CLOVER/tools /ESP/EFI/CLOVER
48 - substituteAll ${./../dist/config.plist.template} work/config.plist
49 - guestfish --remote copy-in work/config.plist /ESP/EFI/CLOVER
50 - guestfish --remote rm /ESP/EFI/CLOVER/drivers64UEFI/AudioDxe-64.efi
51 - guestfish --remote umount-all
52 - guestfish --remote shutdown
53 - mv clover2.img $out
54 - '';
55 - cloverVersion = "4934";
56 - clover-iso-lzma = fetchurl {
57 - url = "mirror://sourceforge/cloverefiboot/CloverISO-${self.cloverVersion}.tar.lzma";
58 - sha256 = "0ivwaapgir2yvsyp7gi9ddj6r97j99n99cz0xwqhcrijimp06hcl";
59 - };
60 - clover-iso = runCommand "clover.iso" {} ''
61 - tar -xvf ${self.clover-iso-lzma}
62 - mv -v *.iso $out
63 - '';
64 -})
macs/host/default.nix deleted
-226
@@ -1,226 +0,0 @@
1 -
2 -{ pkgs, lib, config, ... }:
3 -let
4 - inherit (lib) mkOption types;
5 -in {
6 - options = {
7 - monitorama = {
8 - enable = mkOption {
9 - default = false;
10 - type = types.bool;
11 - description = ''
12 - Whether to enable a prometheus proxy for prom nodes behind
13 - a NAT.
14 - '';
15 - };
16 -
17 - hosts = mkOption {
18 - type = types.attrsOf types.str;
19 - description = ''
20 - Key, value pairs of name -> ip:port/paths. The name will be
21 - used in a proxy's path.
22 - '';
23 - example = {
24 - "/mac1/host" = "http://192.168.2.101:9100/metrics";
25 - "/mac1/guest" = "http://192.168.2.101:9101/metrics";
26 - };
27 - };
28 - };
29 - macosGuest = {
30 - enable = mkOption {
31 - default = false;
32 - type = types.bool;
33 - description = ''
34 - Whether to enable the macOS guest, including networking and
35 - the QEMU VM.
36 - '';
37 - };
38 -
39 - network = {
40 - externalInterface = mkOption {
41 - type = types.str;
42 - description = ''
43 - Public network interface to forward traffic through.
44 - '';
45 - };
46 -
47 - sshInterface = mkOption {
48 - type = types.str;
49 - description = ''
50 - Public network interface to receive SSH connections on.
51 - '';
52 - };
53 -
54 - interiorNetworkPrefix = mkOption {
55 - type = types.str;
56 - description = ''
57 - The first three octets of the network to use for the virtual
58 - machine. The VM always runs in a /24 network. If you use the
59 - value "192.168.1", the host will have IP 192.168.1.1 and the
60 - guest will have IP 192.168.1.2
61 - '';
62 -
63 - example = "192.168.1";
64 - };
65 - };
66 -
67 - guest = {
68 - sockets = mkOption {
69 - type = types.int;
70 - description = ''
71 - The number of physical CPU Sockets in the system.
72 -
73 - # lscpu
74 - Architecture: x86_64
75 - CPU op-mode(s): 32-bit, 64-bit
76 - Byte Order: Little Endian
77 - CPU(s): 4
78 - On-line CPU(s) list: 0-3
79 - Thread(s) per core: 2
80 - Core(s) per socket: 2
81 - Socket(s): 1 <------
82 - '';
83 - };
84 -
85 - cores = mkOption {
86 - type = types.int;
87 - description = ''
88 - The number of Cores per Socket.
89 -
90 - # lscpu
91 - Architecture: x86_64
92 - CPU op-mode(s): 32-bit, 64-bit
93 - Byte Order: Little Endian
94 - CPU(s): 4
95 - On-line CPU(s) list: 0-3
96 - Thread(s) per core: 2
97 - Core(s) per socket: 2 <------
98 - Socket(s): 1
99 - '';
100 - };
101 -
102 - threads = mkOption {
103 - type = types.int;
104 - description = ''
105 - The number of Threads per Core.
106 -
107 - # lscpu
108 - Architecture: x86_64
109 - CPU op-mode(s): 32-bit, 64-bit
110 - Byte Order: Little Endian
111 - CPU(s): 4
112 - On-line CPU(s) list: 0-3
113 - Thread(s) per core: 2 <------
114 - Core(s) per socket: 2
115 - Socket(s): 1
116 - '';
117 - };
118 -
119 - memoryInMegs = mkOption {
120 - type = types.int;
121 - description = ''
122 - I have no idea what "megs" is, but QEMU's documentatation
123 - says this is the number of megs. Save 1G or 2G or so for
124 - the host and ZFS.
125 - '';
126 - };
127 -
128 -
129 - MACAddress = mkOption {
130 - type = types.str;
131 - description = ''
132 - The MAC address to assign the guest's NIC.
133 - '';
134 -
135 - default = "52:54:00:c9:18:27";
136 - };
137 -
138 - persistentConfigDir = mkOption {
139 - type = types.str;
140 - description = ''
141 - A path on the guest to store secret, persistent
142 - configuration like SSH host keys.
143 -
144 - Host keys are generated on the host and copied to the VM
145 - to ensure they don't change on every boot.
146 - '';
147 - default = "/var/lib/macos-vm-persistent-config";
148 - };
149 -
150 - zvolName = mkOption {
151 - type = types.str;
152 - description = ''
153 - Name of the zvol containing the root disk image.
154 - '';
155 - example = "rpool/my-disk-image";
156 - };
157 -
158 - snapshotName = mkOption {
159 - type = types.str;
160 - description = ''
161 - Name of the snapshot on the zvolName.
162 -
163 - There must be a snapshot because the disk state is rolled
164 - back on every boot.
165 -
166 - The snapshot name is combined with zvolName like:
167 - zvolName@snapshotName
168 - '';
169 - example = "pristine";
170 - default = "pristine";
171 - };
172 -
173 - guestConfigDir = mkOption {
174 - type = types.path;
175 - description = ''
176 - A directory of configuration files to expose to the VM.
177 -
178 - At a minimum, it should contain an `apply.sh` file in the
179 - root. This is executed by the macOS VM on boot-up. Note
180 - the configuration will be mounted at /Volumes/CONFIG as a
181 - cdrom.
182 -
183 - At /Volumes/CONFIG/etc/ssh/ will be SSH host keys which
184 - should be copied to /etc/ssh/ on the host. Additionally,
185 - the script should finish by unmounting /Volumes/CONFIG
186 - otherwise it is possible for programs runnig on the guest
187 - to read the SSH host keys.
188 - '';
189 - };
190 -
191 - ovmfCodeFile = mkOption {
192 - type = types.path;
193 - description = ''
194 - Path to the OVMF Code File.
195 - '';
196 - };
197 -
198 - ovmfVarsFile = mkOption {
199 - type = types.path;
200 - description = ''
201 - Path to the OVMF Variable File.
202 - '';
203 - };
204 -
205 - cloverImage = mkOption {
206 - type = types.path;
207 - default = (pkgs.callPackage ./clover.qcow2.nix {
208 - # 0x23 means allow dtrace and untrusted kexts
209 - # https://github.com/Clover-EFI-Bootloader/clover/blob/6b8018b1fec958d672951f87cefd8b6cfd5318ac/rEFIt_UEFI/Platform/boot.h#L127-L135
210 - csrFlag = "0x23";
211 - }).clover-image;
212 - description = ''
213 - Path to the Clover bootloader.
214 - '';
215 - };
216 -
217 - };
218 - };
219 - };
220 -
221 - imports = [
222 - ./networking.nix
223 - ./qemu.nix
224 - ./monitorama.nix
225 - ];
226 -}
macs/host/monitorama.nix deleted
-24
@@ -1,24 +0,0 @@
1 -{ lib, config, ... }:
2 -let
3 - inherit (lib) mkIf;
4 -in {
5 - config = mkIf config.monitorama.enable {
6 - networking.firewall.allowedTCPPorts = [ 9111 ];
7 - services.nginx = {
8 - enable = true;
9 - virtualHosts = {
10 - default = {
11 - default = true;
12 - listen = [ { addr = "0.0.0.0"; port = 9111; } ];
13 - locations = builtins.mapAttrs (name: value: { proxyPass = value; }) config.monitorama.hosts;
14 - };
15 - } // (
16 - builtins.mapAttrs (name: value: {
17 - listen = [ { addr = "0.0.0.0"; port = 9111; } ];
18 - locations."/metrics".proxyPass = value;
19 - })
20 - config.monitorama.hosts
21 - );
22 - };
23 - };
24 -}
macs/host/networking.nix deleted
-121
@@ -1,121 +0,0 @@
1 -{ lib, pkgs, config, ... }:
2 -let
3 - inherit (lib) mkIf;
4 -
5 - subnetIP = "${config.macosGuest.network.interiorNetworkPrefix}.0";
6 - routerIP = "${config.macosGuest.network.interiorNetworkPrefix}.1";
7 - guestIP = "${config.macosGuest.network.interiorNetworkPrefix}.2";
8 - broadcastIP = "${config.macosGuest.network.interiorNetworkPrefix}.255";
9 -in {
10 - config = mkIf config.macosGuest.enable {
11 - boot.kernel.sysctl."net.ipv4.conf.all.forwarding" = true;
12 - boot.kernel.sysctl."net.ipv4.conf.default.forwarding" = true;
13 -
14 - networking.firewall.extraCommands = ''
15 - ip46tables -A nixos-fw -i tap0 -p udp --dport 53 -j nixos-fw-accept # knot dns / kresd
16 - '';
17 -
18 - networking.firewall.allowedTCPPorts = [
19 - 2200 # forwarded to :22 on the guest for external SSH
20 - 9101 # forwarded to :9100 on the guest
21 - config.services.prometheus.exporters.node.port
22 - ];
23 - networking.firewall.allowedUDPPorts = [
24 - 1514 # guest sends logs here
25 - ];
26 -
27 - networking.nat = {
28 - enable = true;
29 - externalInterface = config.macosGuest.network.externalInterface;
30 - internalInterfaces = [
31 - "tap0"
32 - ];
33 - internalIPs = [
34 - "${subnetIP}/24"
35 - ];
36 - };
37 -
38 - networking.interfaces."tap0" = {
39 - virtual = true;
40 - ipv4.addresses = [
41 - {
42 - address = routerIP;
43 - prefixLength = 24;
44 - }
45 - ];
46 - };
47 -
48 - services.openssh.enable = true;
49 -
50 - services.dhcpd4 = {
51 - enable = true;
52 - interfaces = [ "tap0" ];
53 - extraConfig = ''
54 - authoritative;
55 - subnet ${subnetIP} netmask 255.255.255.0 {
56 - option routers ${routerIP};
57 - option broadcast-address ${broadcastIP};
58 - option domain-name-servers ${routerIP};
59 -
60 - group {
61 - host builder {
62 - hardware ethernet ${config.macosGuest.guest.MACAddress};
63 - fixed-address ${guestIP};
64 - }
65 - }
66 - }
67 - '';
68 - };
69 -
70 - services.kresd = {
71 - enable = true;
72 - listenPlain = [ "[::1]:53" "127.0.0.1:53" "${routerIP}:53" ];
73 - extraConfig = ''
74 - modules = {
75 - 'policy', -- Block queries to local zones/bad sites
76 - 'stats', -- Track internal statistics
77 - 'predict', -- Prefetch expiring/frequent records
78 - }
79 - -- Smaller cache size
80 - cache.size = 10 * MB
81 - '';
82 - };
83 -
84 - services.prometheus.exporters.node = {
85 - enable = true;
86 - };
87 -
88 - systemd.services.netcatsyslog = {
89 - wantedBy = [ "multi-user.target" ];
90 - script = let
91 - ncl = pkgs.writeScript "ncl" ''
92 - #!/bin/sh
93 - set -euxo pipefail
94 - ${pkgs.netcat}/bin/nc -dklun 1514 | ${pkgs.coreutils}/bin/tr '<' $'\n'
95 - '';
96 - in ''
97 - set -euxo pipefail
98 - ${pkgs.expect}/bin/unbuffer ${ncl}
99 - '';
100 - };
101 -
102 - systemd.services.forward-wg0-ssh-to-guest = {
103 - wantedBy = [ "multi-user.target" ];
104 - after = [ "wireguard-wg0.service" ];
105 - script = ''
106 - set -euxo pipefail
107 - exec ${pkgs.socat}/bin/socat TCP-LISTEN:2200,fork,so-bindtodevice=${config.macosGuest.network.sshInterface} TCP:${guestIP}:22
108 - '';
109 - };
110 -
111 - systemd.services.forward-wg0-prometheus-to-guest = {
112 - wantedBy = [ "multi-user.target" ];
113 - after = [ "wireguard-wg0.service" ];
114 - script = ''
115 - set -euxo pipefail
116 - exec ${pkgs.socat}/bin/socat TCP-LISTEN:9101,fork,so-bindtodevice=${config.macosGuest.network.sshInterface} TCP:${guestIP}:9100
117 - '';
118 - };
119 -
120 - };
121 -}
macs/host/qemu.nix deleted
-111
@@ -1,111 +0,0 @@
1 -
2 -{ config, lib, pkgs, ... }:
3 -let
4 - inherit (config.macosGuest.guest) threads cores sockets memoryInMegs
5 - ovmfCodeFile ovmfVarsFile cloverImage zvolName snapshotName
6 - guestConfigDir persistentConfigDir;
7 - inherit (lib) mkIf;
8 -
9 - zvolDevice = "/dev/zvol/${zvolName}";
10 - snapshot = "${zvolName}@${snapshotName}";
11 -in {
12 - config = mkIf config.macosGuest.enable {
13 - systemd.services.create-macos-secrets = {
14 - path = with pkgs; [ openssh ];
15 -
16 - serviceConfig = {
17 - Type = "oneshot";
18 - RemainAfterExit = true;
19 - };
20 -
21 - script = ''
22 - if [ ! -f ${persistentConfigDir}/etc/ssh/ssh_host_ed25519_key ]; then
23 - mkdir -p ${persistentConfigDir}/etc/ssh
24 - ssh-keygen -A -f ${persistentConfigDir}
25 - fi
26 - '';
27 - };
28 -
29 - systemd.services."run-macos-vm" = rec {
30 - requires = [ "create-macos-secrets.service" "dhcpd4.service" "kresd@1.service" "network-online.target" ];
31 - after = requires;
32 - wantedBy = [ "multi-user.target" ];
33 - wants = [ "netcatsyslog.service" "healthcheck-macos-vm.timer" ];
34 - before = [ "healthcheck-macos-vm.timer" ];
35 - path = with pkgs; [ zfs qemu cdrkit rsync findutils ];
36 -
37 - serviceConfig.PrivateTmp = true;
38 -
39 - preStart = let
40 - nixInstall = pkgs.fetchurl {
41 - url = "https://nixos.org/releases/nix/nix-2.3.10/install";
42 - sha256 = "8fa6f064bf758adf501deb35c6837b8c4f9402f66ff86964537524103376958e";
43 - };
44 - in ''
45 - zfs rollback ${snapshot}
46 -
47 - # Create a cloud-init style cdrom
48 - rm -rf /tmp/cdr
49 - cp -r ${persistentConfigDir} /tmp/cdr
50 - rsync -r ${guestConfigDir}/ /tmp/cdr
51 -
52 - cp ${nixInstall} /tmp/cdr/install
53 - chmod +x /tmp/cdr/install
54 -
55 - cd /tmp/cdr
56 - find .
57 - genisoimage -v -J -r -V CONFIG -o /tmp/config.iso .
58 - '';
59 - postStop = "zfs rollback ${snapshot}";
60 - script = ''
61 - qemu-system-x86_64 \
62 - -enable-kvm \
63 - -cpu Penryn,kvm=on,vendor=GenuineIntel,+invtsc,vmware-cpuid-freq=on,+aes,+xsave,+avx,+xsaveopt,avx2,+smep \
64 - -machine pc-q35-2.9 \
65 - -smp cpus=${toString (cores * threads * sockets)},cores=${toString cores},threads=${toString threads},sockets=${toString sockets} \
66 - -m ${toString memoryInMegs} \
67 - -usb -device usb-kbd -device usb-tablet \
68 - -device isa-applesmc,osk="ourhardworkbythesewordsguardedpleasedontsteal(c)AppleComputerInc" \
69 - -drive if=pflash,format=raw,readonly,file=${ovmfCodeFile} \
70 - -drive if=pflash,format=raw,snapshot=on,file=${ovmfVarsFile} \
71 - -smbios type=2 \
72 - -device ich9-intel-hda -device hda-duplex \
73 - -device ide-hd,bus=ide.2,drive=Clover \
74 - -drive id=Clover,if=none,snapshot=on,format=qcow2,file='${cloverImage}' \
75 - -device ide-hd,bus=ide.1,drive=MacHDD \
76 - -drive id=MacHDD,cache=unsafe,if=none,file=${zvolDevice},format=raw \
77 - -device ide-cd,bus=ide.0,drive=config \
78 - -drive id=config,if=none,snapshot=on,media=cdrom,file=/tmp/config.iso \
79 - -netdev tap,id=net0,ifname=tap0,script=no,downscript=no -device e1000-82545em,netdev=net0,id=net0,mac=${config.macosGuest.guest.MACAddress} \
80 - -vnc 127.0.0.1:0 \
81 - -no-reboot
82 - '';
83 - };
84 -
85 - systemd.timers.healthcheck-macos-vm = {
86 - enable = true;
87 - description = "Verify the macOS VM is listening";
88 - partOf = [ "run-macos-vm.service"];
89 -
90 - timerConfig = {
91 - OnActiveSec = 900;
92 - OnCalendar = "hourly";
93 - Unit = "healthcheck-macos-vm.service";
94 - Persistent = "yes";
95 - };
96 - };
97 -
98 - systemd.services.healthcheck-macos-vm = {
99 - enable = true;
100 -
101 - script = ''
102 - if ${pkgs.curl}/bin/curl ${config.macosGuest.network.interiorNetworkPrefix}.2:9100 > /dev/null; then
103 - echo "Appears to be up!"
104 - else
105 - echo "Appears to be down, restarting run-macos-vm"
106 - systemctl restart run-macos-vm.service
107 - fi
108 - '';
109 - };
110 - };
111 -}
macs/nix-darwin.nix renamed
+32 -13
@@ -1,10 +1,11 @@
1 +# used with https://github.com/DeterminateSystems/macos-ephemeral
2 { config, lib, pkgs, ... }:
3
4 with lib;
5
6 let
7 sshKeys = rec {
7 - hydra-queue-runner = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCyM48VC5fpjJssLI8uolFscP4/iEoMHfkPoT9R3iE3OEjadmwa1XCAiXUoa7HSshw79SgPKF2KbGBPEVCascdAcErZKGHeHUzxj7v3IsNjObouUOBbJfpN4DR7RQT28PZRsh3TvTWjWnA9vIrSY/BvAK1uezFRuObvatqAPMrw4c0DK+JuGuCNkKDGHLXNSxYBc5Pmr1oSU7/BDiHVjjyLIsAMIc20+q8SjWswKqL1mY193mN7FpUMBtZrd0Za9fMFRII9AofEIDTOayvOZM6+/1dwRWZXM6jhE6kaPPF++yromHvDPBnd6FfwODKLvSF9BkA3pO5CqrD8zs7ETmrV hydra-queue-runner@chef";
8 + hydra-queue-runner = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOdxl6gDS7h3oeBBja2RSBxeS51Kp44av8OAJPPJwuU/ hydra-queue-runner@rhea";
9 };
10 environment = concatStringsSep " "
11 [
@@ -16,6 +17,7 @@ let
17 in
18
19 {
20 + environment.darwinConfig = "/nix/home/config.nix";
21 environment.systemPackages =
22 [
23 config.nix.package
@@ -30,13 +32,26 @@ in
32
33 services.nix-daemon.enable = true;
34
33 - nix.maxJobs = 4;
34 - nix.buildCores = 1;
35 + nix.settings = {
36 + "extra-experimental-features" = [ "nix-command" "flakes" ];
37 + max-jobs = 4;
38 + cores = 2;
39 + };
40 +
41 + nix.nixPath = [
42 + "nixpkgs=channel:nixpkgs-unstable"
43 + "darwin=https://github.com/LnL7/nix-darwin/archive/master.tar.gz"
44 + "darwin-config=/nix/home/config.nix"
45 + ];
46 +
47 nix.gc.automatic = true;
48 + nix.gc.user = "";
49 nix.gc.interval = { Minute = 15; };
37 - nix.gc.options = let
50 + nix.gc.options =
51 + let
52 gbFree = 50;
39 - in "--max-freed $((${toString gbFree} * 1024**3 - 1024 * $(df -P -k /nix/store | tail -n 1 | awk '{ print $4 }')))";
53 + in
54 + "--max-freed $((${toString gbFree} * 1024**3 - 1024 * $(df -P -k /nix/store | tail -n 1 | awk '{ print $4 }')))";
55
56 # If we drop below 20GiB during builds, free 20GiB
57 nix.extraOptions = ''
@@ -51,11 +66,6 @@ in
66
67
68 system.activationScripts.postActivation.text = ''
54 - printf "disabling spotlight indexing... "
55 - mdutil -i off -d / &> /dev/null
56 - mdutil -E / &> /dev/null
57 - echo "ok"
58 -
69 printf "configuring ssh keys for hydra on the root account... "
70 mkdir -p ~root/.ssh
71 cp -f /etc/per-user/root/ssh/authorized_keys ~root/.ssh/authorized_keys
@@ -64,12 +74,21 @@ in
74 '';
75
76 launchd.daemons.prometheus-node-exporter = {
67 - script = ''
68 - exec ${pkgs.prometheus-node-exporter}/bin/node_exporter
69 - '';
77 + command = "${pkgs.prometheus-node-exporter}/bin/node_exporter";
78
79 serviceConfig.KeepAlive = true;
80 serviceConfig.StandardErrorPath = "/var/log/prometheus-node-exporter.log";
81 serviceConfig.StandardOutPath = "/var/log/prometheus-node-exporter.log";
82 };
83 +
84 + launchd.daemons.rosetta2-gc = {
85 + script = ''
86 + date
87 + exec /System/Library/Filesystems/apfs.fs/Contents/Resources/apfs.util -P -minsize 0 /System/Volumes/Data
88 + '';
89 + serviceConfig.StartInterval = 3600 * 2;
90 + serviceConfig.RunAtLoad = true;
91 + serviceConfig.StandardErrorPath = "/var/log/rosetta2-gc.log";
92 + serviceConfig.StandardOutPath = "/var/log/rosetta2-gc.log";
93 + };
94 }
macs/nodes/mac1.nix deleted
-43
@@ -1,43 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, ... }:
5 -
6 -{
7 - imports =
8 - [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
9 - ../host/networking.nix
10 - ];
11 -
12 - macosGuest.network.externalInterface = lib.mkForce "ens1";
13 -
14 - boot.loader.systemd-boot.enable = true;
15 - boot.loader.efi.canTouchEfiVariables = false;
16 - boot.loader.grub.efiInstallAsRemovable = true;
17 -
18 - boot.initrd.availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "firewire_ohci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci" "nvme" ];
19 - boot.initrd.kernelModules = [ ];
20 - boot.kernelModules = [ "kvm-intel" "wl" ];
21 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
22 - boot.kernelParams = [ "nomodeset" ];
23 -
24 - fileSystems."/" =
25 - { device = "rpool/root";
26 - fsType = "zfs";
27 - };
28 -
29 - fileSystems."/boot" =
30 - { device = "/dev/disk/by-label/boot";
31 - fsType = "vfat";
32 - };
33 -
34 - swapDevices =
35 - [ { device = "/dev/disk/by-label/swap"; }
36 - ];
37 -
38 - nix.maxJobs = lib.mkDefault 6;
39 -
40 - networking.hostId = "443c1836";
41 - nixpkgs.config.allowUnfree = true;
42 - boot.supportedFilesystems = ["zfs"];
43 -}
macs/nodes/mac2.nix deleted
-33
@@ -1,33 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, ... }:
5 -
6 -{
7 - imports =
8 - [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
9 - ];
10 -
11 - boot.loader.systemd-boot.enable = true;
12 - boot.loader.efi.canTouchEfiVariables = true;
13 -
14 -
15 - boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci" ];
16 - boot.initrd.kernelModules = [ ];
17 - boot.kernelModules = [ "kvm-intel" "wl" ];
18 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
19 -
20 - fileSystems."/" =
21 - { device = "rpool/root";
22 - fsType = "zfs";
23 - };
24 -
25 - nix.maxJobs = lib.mkDefault 4;
26 - #powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
27 -
28 - boot.supportedFilesystems = [ "zfs" ];
29 - networking.hostId = "dbcdda15";
30 - nixpkgs.config.allowUnfree = true;
31 - fileSystems."/boot".device = lib.mkOverride 0 "/dev/disk/by-label/boot";
32 - swapDevices = lib.mkOverride 0 [ { device = "/dev/disk/by-label/swap"; } ];
33 -}
macs/nodes/mac3.nix deleted
-32
@@ -1,32 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, ... }:
5 -
6 -{
7 - imports =
8 - [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
9 - ];
10 -
11 - boot.loader.systemd-boot.enable = true;
12 - boot.loader.efi.canTouchEfiVariables = true;
13 -
14 -
15 - boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci" ];
16 - boot.initrd.kernelModules = [ ];
17 - boot.kernelModules = [ "kvm-intel" "wl" ];
18 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
19 -
20 - fileSystems."/" =
21 - { device = "rpool/root";
22 - fsType = "zfs";
23 - };
24 -
25 - nix.maxJobs = lib.mkDefault 4;
26 - #powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
27 - boot.supportedFilesystems = [ "zfs" ];
28 - networking.hostId = "4a2399ac";
29 - nixpkgs.config.allowUnfree = true;
30 - fileSystems."/boot".device = lib.mkOverride 0 "/dev/disk/by-label/boot";
31 - swapDevices = lib.mkOverride 0 [ { device = "/dev/disk/by-label/swap"; } ];
32 -}
macs/nodes/mac4.nix deleted
-33
@@ -1,33 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, ... }:
5 -
6 -{
7 - imports =
8 - [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
9 - ];
10 -
11 - boot.loader.systemd-boot.enable = true;
12 - boot.loader.efi.canTouchEfiVariables = true;
13 -
14 -
15 - boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci" ];
16 - boot.initrd.kernelModules = [ ];
17 - boot.kernelModules = [ "kvm-intel" "wl" ];
18 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
19 -
20 - fileSystems."/" =
21 - { device = "rpool/root";
22 - fsType = "zfs";
23 - };
24 -
25 - nix.maxJobs = lib.mkDefault 4;
26 - #powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
27 -
28 - boot.supportedFilesystems = [ "zfs" ];
29 - networking.hostId = "cc4f7a7f";
30 - nixpkgs.config.allowUnfree = true;
31 - fileSystems."/boot".device = lib.mkOverride 0 "/dev/disk/by-label/boot";
32 - swapDevices = lib.mkOverride 0 [ { device = "/dev/disk/by-label/swap"; } ];
33 -}
macs/nodes/mac5.nix deleted
-33
@@ -1,33 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, ... }:
5 -
6 -{
7 - imports =
8 - [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
9 - ];
10 -
11 - boot.loader.systemd-boot.enable = true;
12 - boot.loader.efi.canTouchEfiVariables = true;
13 -
14 -
15 - boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci" ];
16 - boot.initrd.kernelModules = [ ];
17 - boot.kernelModules = [ "kvm-intel" "wl" ];
18 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
19 -
20 - fileSystems."/" =
21 - { device = "rpool/root";
22 - fsType = "zfs";
23 - };
24 -
25 - nix.maxJobs = lib.mkDefault 4;
26 - #powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
27 -
28 - boot.supportedFilesystems = [ "zfs" ];
29 - networking.hostId = "37854b05";
30 - nixpkgs.config.allowUnfree = true;
31 - fileSystems."/boot".device = lib.mkOverride 0 "/dev/disk/by-label/boot";
32 - swapDevices = lib.mkOverride 0 [ { device = "/dev/disk/by-label/swap"; } ];
33 -}
macs/nodes/mac6.nix deleted
-32
@@ -1,32 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, ... }:
5 -
6 -{
7 - imports =
8 - [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
9 - ];
10 -
11 - boot.loader.systemd-boot.enable = true;
12 - boot.loader.efi.canTouchEfiVariables = true;
13 -
14 - boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci" ];
15 - boot.initrd.kernelModules = [ ];
16 - boot.kernelModules = [ "kvm-intel" "wl" ];
17 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
18 -
19 - fileSystems."/" =
20 - { device = "rpool/root";
21 - fsType = "zfs";
22 - };
23 -
24 - nix.maxJobs = lib.mkDefault 4;
25 - #powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
26 -
27 - boot.supportedFilesystems = [ "zfs" ];
28 - networking.hostId = "a38b8b7b";
29 - nixpkgs.config.allowUnfree = true;
30 - fileSystems."/boot".device = lib.mkOverride 0 "/dev/disk/by-label/boot";
31 - swapDevices = lib.mkOverride 0 [ { device = "/dev/disk/by-label/swap"; } ];
32 -}
macs/nodes/mac7.nix deleted
-32
@@ -1,32 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, ... }:
5 -
6 -{
7 - imports =
8 - [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
9 - ];
10 -
11 - boot.loader.systemd-boot.enable = true;
12 - boot.loader.efi.canTouchEfiVariables = true;
13 -
14 - boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci" ];
15 - boot.initrd.kernelModules = [ ];
16 - boot.kernelModules = [ "kvm-intel" "wl" ];
17 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
18 -
19 - fileSystems."/" =
20 - { device = "rpool/root";
21 - fsType = "zfs";
22 - };
23 -
24 - nix.maxJobs = lib.mkDefault 4;
25 - #powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
26 -
27 - boot.supportedFilesystems = [ "zfs" ];
28 - networking.hostId = "83507827";
29 - nixpkgs.config.allowUnfree = true;
30 - fileSystems."/boot".device = lib.mkOverride 0 "/dev/disk/by-label/boot";
31 - swapDevices = lib.mkOverride 0 [ { device = "/dev/disk/by-label/swap"; } ];
32 -}
macs/nodes/mac8.nix deleted
-33
@@ -1,33 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, ... }:
5 -
6 -{
7 - imports =
8 - [ <nixpkgs/nixos/modules/installer/scan/not-detected.nix>
9 - ];
10 -
11 - boot.loader.systemd-boot.enable = true;
12 - boot.loader.efi.canTouchEfiVariables = true;
13 -
14 -
15 - boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "usb_storage" "sd_mod" "sdhci_pci" ];
16 - boot.initrd.kernelModules = [ ];
17 - boot.kernelModules = [ "kvm-intel" "wl" ];
18 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
19 -
20 - fileSystems."/" =
21 - { device = "rpool/root";
22 - fsType = "zfs";
23 - };
24 -
25 - nix.maxJobs = lib.mkDefault 4;
26 - #powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
27 -
28 - boot.supportedFilesystems = [ "zfs" ];
29 - networking.hostId = "dcc9599b";
30 - nixpkgs.config.allowUnfree = true;
31 - fileSystems."/boot".device = lib.mkOverride 0 "/dev/disk/by-label/boot";
32 - swapDevices = lib.mkOverride 0 [ { device = "/dev/disk/by-label/swap"; } ];
33 -}
macs/nodes/macofborg1.nix deleted
-40
@@ -1,40 +0,0 @@
1 -# Do not modify this file! It was generated by ‘nixos-generate-config’
2 -# and may be overwritten by future invocations. Please make changes
3 -# to /etc/nixos/configuration.nix instead.
4 -{ config, lib, pkgs, modulesPath, ... }:
5 -
6 -{
7 - imports =
8 - [ (modulesPath + "/installer/scan/not-detected.nix")
9 - ];
10 -
11 - boot.initrd.availableKernelModules = [ "xhci_pci" "nvme" "usbhid" "usb_storage" "sd_mod" ];
12 - boot.initrd.kernelModules = [ ];
13 - boot.kernelModules = [ "kvm-intel" ];
14 - boot.extraModulePackages = [ config.boot.kernelPackages.broadcom_sta ];
15 - boot.supportedFilesystems = [ "zfs" ];
16 - boot.kernelParams = [ "nomodeset" ];
17 -
18 - boot.loader.systemd-boot.enable = true;
19 - boot.loader.efi.canTouchEfiVariables = false;
20 - boot.loader.grub.efiInstallAsRemovable = true;
21 -
22 - fileSystems."/" =
23 - { device = "rpool/root";
24 - fsType = "zfs";
25 - };
26 -
27 - fileSystems."/boot" =
28 - { device = "/dev/disk/by-label/boot";
29 - fsType = "vfat";
30 - };
31 -
32 - swapDevices =
33 - [ { device = "/dev/disk/by-label/swap"; }
34 - ];
35 -
36 - hardware.video.hidpi.enable = lib.mkDefault true;
37 -
38 - networking.hostId = "d0dce459";
39 - nixpkgs.config.allowUnfree = true;
40 -}
macs/notes.md deleted
-399
@@ -1,399 +0,0 @@
1 -
2 -## Generating a new macOS disk image
3 -
4 -This is less practiced since it is only done rarely. These steps will
5 -likely require changes every time, as the OS upgrades happen.
6 -
7 -The following are just notes I took during this process.
8 -
9 -generate a disk image and clover image from
10 -https://github.com/kholia/OSX-KVM/tree/master/HighSierra
11 -
12 -I was at commit `3d995ed38ba72955c9355324ab92bd56d8bcf879` and
13 -downloaded `CloverISO-4699.tar.lzma` from SourceForge with sha256sum
14 -`d85ae93ef3aa3ef6e5b7074778cd3dbc2d74b4bdc5f6d4f6214ea213e0644602`
15 -and my High Sierra ISO was `macos-high-sierra-10.13.6-cdr.iso`
16 -
17 -I applied the following patch to OSX-KVM:
18 -
19 -```diff
20 -commit 223e3ebff7501219cf5ced8422ee2726a117a6aa
21 -Author: Graham Christensen <graham@grahamc.com>
22 -Date: Mon Oct 8 20:09:44 2018 +0000
23 -
24 - NixOS patches
25 -
26 -diff --git a/Clover.qcow2 b/Clover.qcow2
27 -index 8527b16..51e049c 100644
28 -Binary files a/Clover.qcow2 and b/Clover.qcow2 differ
29 -diff --git a/HighSierra/clover-image.sh b/HighSierra/clover-image.sh
30 -index 9300f7e..8dd1e32 100755
31 ---- a/HighSierra/clover-image.sh
32 -+++ b/HighSierra/clover-image.sh
33 -@@ -1,4 +1,5 @@
34 --#!/bin/bash
35 -+#!/usr/bin/env nix-shell
36 -+#!nix-shell -i bash -p libguestfs
37 -
38 - # https://github.com/kraxel/imagefish
39 -
40 -diff --git a/HighSierra/clover/config.plist.stripped.qemu b/HighSierra/clover/config.plist.stripped.qemu
41 -index 79f7d7b..2159d89 100644
42 ---- a/HighSierra/clover/config.plist.stripped.qemu
43 -+++ b/HighSierra/clover/config.plist.stripped.qemu
44 -@@ -7,7 +7,7 @@
45 - <key>Arguments</key>
46 - <string></string>
47 - <key>DefaultVolume</key>
48 -- <string>clover</string>
49 -+ <string>system</string>
50 - <key>Log</key>
51 - <true/>
52 - <key>Secure</key>
53 -diff --git a/boot-macOS-HS.sh b/boot-macOS-HS.sh
54 -index 7e39eb8..b2f26d8 100755
55 ---- a/boot-macOS-HS.sh
56 -+++ b/boot-macOS-HS.sh
57 -@@ -1,4 +1,5 @@
58 --#!/bin/bash
59 -+#!/usr/bin/env nix-shell
60 -+#!nix-shell -i bash -p qemu
61 -
62 - # See https://www.mail-archive.com/qemu-devel@nongnu.org/msg471657.html thread.
63 - #
64 -@@ -15,7 +16,7 @@ MY_OPTIONS="+aes,+xsave,+avx,+xsaveopt,avx2,+smep"
65 -
66 - qemu-system-x86_64 -enable-kvm -m 3072 -cpu Penryn,kvm=on,vendor=GenuineIntel,+invtsc,vmware-cpuid-freq=on,$MY_OPTIONS\
67 - -machine pc-q35-2.9 \
68 -- -smp 4,cores=2 \
69 -+ -smp cpus=8,cores=4,threads=2,sockets=1 -m 14336 \
70 - -usb -device usb-kbd -device usb-tablet \
71 - -device isa-applesmc,osk="ourhardworkbythesewordsguardedpleasedontsteal(c)AppleComputerInc" \
72 - -drive if=pflash,format=raw,readonly,file=OVMF_CODE.fd \
73 -@@ -29,4 +30,6 @@ qemu-system-x86_64 -enable-kvm -m 3072 -cpu Penryn,kvm=on,vendor=GenuineIntel,+i
74 - -device ide-drive,bus=ide.0,drive=MacDVD \
75 - -drive id=MacDVD,if=none,snapshot=on,media=cdrom,file=./'HighSierra-10.13.6.iso' \
76 - -netdev tap,id=net0,ifname=tap0,script=no,downscript=no -device e1000-82545em,netdev=net0,id=net0,mac=52:54:00:c9:18:27 \
77 -- -monitor stdio
78 -+ -monitor stdio \
79 -+ -vnc 127.0.0.1:0
80 -+
81 -```
82 -
83 -plus the patch
84 -
85 -```diff
86 -commit cee4519beb23a015f39116e178b3e0f642df6ed2
87 -Author: Graham Christensen <graham@grahamc.com>
88 -Date: Mon Oct 8 22:08:51 2018 +0000
89 -
90 - provision / ephemeral
91 -
92 -diff --git a/boot-macOS-HS-ephemeral.sh b/boot-macOS-HS-ephemeral.sh
93 -new file mode 100755
94 -index 0000000..1101977
95 ---- /dev/null
96 -+++ b/boot-macOS-HS-ephemeral.sh
97 -@@ -0,0 +1,35 @@
98 -+#!/usr/bin/env nix-shell
99 -+#!nix-shell -i bash -p qemu
100 -+
101 -+# See https://www.mail-archive.com/qemu-devel@nongnu.org/msg471657.html thread.
102 -+#
103 -+# The "pc-q35-2.4" machine type was changed to "pc-q35-2.9" on 06-August-2017.
104 -+#
105 -+# The "media=cdrom" part is needed to make Clover recognize the bootable ISO
106 -+# image.
107 -+
108 -+##################################################################################
109 -+# NOTE: Comment out the "MY_OPTIONS" line in case you are having booting problems!
110 -+##################################################################################
111 -+
112 -+MY_OPTIONS="+aes,+xsave,+avx,+xsaveopt,avx2,+smep"
113 -+
114 -+qemu-system-x86_64 -enable-kvm -m 3072 -cpu Penryn,kvm=on,vendor=GenuineIntel,+invtsc,vmware-cpuid-freq=on,$MY_OPTIONS\
115 -+ -machine pc-q35-2.9 \
116 -+ -smp cpus=8,cores=4,threads=2,sockets=1 -m 14336 \
117 -+ -usb -device usb-kbd -device usb-tablet \
118 -+ -device isa-applesmc,osk="ourhardworkbythesewordsguardedpleasedontsteal(c)AppleComputerInc" \
119 -+ -drive if=pflash,format=raw,readonly,file=OVMF_CODE.fd \
120 -+ -drive if=pflash,format=raw,file=OVMF_VARS-1024x768.fd \
121 -+ -smbios type=2 \
122 -+ -snapshot \
123 -+ -device ich9-intel-hda -device hda-duplex \
124 -+ -device ide-drive,bus=ide.2,drive=Clover \
125 -+ -drive id=Clover,if=none,snapshot=on,format=qcow2,file=./'Clover.qcow2' \
126 -+ -device ide-drive,bus=ide.1,drive=MacHDD \
127 -+ -drive id=MacHDD,if=none,snapshot=on,file=./mac_hdd.img,format=qcow2 \
128 -+ -device ide-drive,bus=ide.0,drive=MacDVD \
129 -+ -drive id=MacDVD,if=none,snapshot=on,media=cdrom,file=./'HighSierra-10.13.6.iso' \
130 -+ -netdev tap,id=net0,ifname=tap0,script=no,downscript=no -device e1000-82545em,netdev=net0,id=net0,mac=52:54:00:c9:18:27 \
131 -+ -vnc 127.0.0.1:0
132 -+
133 -diff --git a/boot-macOS-HS.sh b/boot-macOS-HS-provision.sh
134 -similarity index 100%
135 -rename from boot-macOS-HS.sh
136 -rename to boot-macOS-HS-provision.sh
137 -```
138 -
139 -calculate your own `-smp` line like this:
140 -
141 - - cores: # of cores per socket
142 - - threads: # of threads per core, ie: hyperthreading? set to 2, none? set to 1
143 - - sockets: # of physical sockets in the system
144 - - cpus = * cores * threads * sockets
145 -
146 -
147 -generate your own Clover.qcow2:
148 -
149 -```
150 -[nix-shell:~/OSX-KVM/HighSierra]# ./clover-image.sh --iso ./clover-ext/Clover-v2.4k-4699-X64.iso --cfg clover/config.plist.stripped.qemu --img Clover.qcow2
151 -### copy files from iso
152 -### creating and adding disk image
153 -# disk-create Clover.qcow2 qcow2 256M
154 -# add Clover.qcow2
155 -# run
156 -### partition disk image
157 -# part-init /dev/sda gpt
158 -# part-add /dev/sda p 2048 200000
159 -# part-add /dev/sda p 202048 -2048
160 -# part-set-gpt-type /dev/sda 1 C12A7328-F81F-11D2-BA4B-00A0C93EC93B
161 -# part-set-bootable /dev/sda 1 true
162 -# mkfs vfat /dev/sda1 label:EFI
163 -# mkfs vfat /dev/sda2 label:clover
164 -# mount /dev/sda2 /
165 -# mkdir /ESP
166 -# mount /dev/sda1 /ESP
167 -### copy files to disk image
168 -'clover/config.plist.stripped.qemu' -> '/run/user/0/clover-image.sh-2833/config.plist'
169 -# mkdir /ESP/EFI
170 -# mkdir /ESP/EFI/CLOVER
171 -# copy-in /run/user/0/clover-image.sh-2833/EFI/BOOT /ESP/EFI
172 -# copy-in /run/user/0/clover-image.sh-2833/EFI/CLOVER/CLOVERX64.efi /ESP/EFI/CLOVER
173 -# copy-in /run/user/0/clover-image.sh-2833/EFI/CLOVER/drivers64UEFI /ESP/EFI/CLOVER
174 -# copy-in /run/user/0/clover-image.sh-2833/EFI/CLOVER/drivers-Off/drivers64UEFI/PartitionDxe-64.efi /ESP/EFI/CLOVER/drivers64UEFI
175 -# copy-in apfs.efi /ESP/EFI/CLOVER/drivers64UEFI
176 -# copy-in /run/user/0/clover-image.sh-2833/EFI/CLOVER/tools /ESP/EFI/CLOVER
177 -# copy-in /run/user/0/clover-image.sh-2833/config.plist /ESP/EFI/CLOVER
178 -# -*- OsxAptioFix v3 -*-
179 -# copy-in /run/user/0/clover-image.sh-2833/EFI/CLOVER/drivers-Off/drivers64UEFI/OsxAptioFix3Drv-64.efi /ESP/EFI/CLOVER/drivers64UEFI
180 -# ls /ESP/EFI/CLOVER/drivers64UEFI
181 -DataHubDxe-64.efi
182 -FSInject-64.efi
183 -OsxAptioFix3Drv-64.efi
184 -PartitionDxe-64.efi
185 -SMCHelper-64.efi
186 -VBoxHfs-64.efi
187 -apfs.efi
188 -# umount-all
189 -### cleaning up ...
190 -```
191 -
192 -[nix-shell:~/OSX-KVM/HighSierra]# cp Clover.qcow2 ../
193 -
194 -
195 -then:
196 -
197 -[root@nixos:~/OSX-KVM]# nix-shell -p qemu
198 -
199 -[nix-shell:~/OSX-KVM]# qemu-img create -f qcow2 mac_hdd.img 128G
200 -Formatting 'mac_hdd.img', fmt=qcow2 size=137438953472 cluster_size=65536 lazy_refcounts=off refcount_bits=16
201 -
202 -then:
203 -
204 -[root@nixos:~/OSX-KVM]# ./boot-macOS-HS.sh
205 -QEMU 3.0.0 monitor - type 'help' for more information
206 -(qemu)
207 -
208 -
209 -then, use tigervnc's vncviewer. If you're running this on a remote
210 -machine you can port-forward the VNC port via
211 -`ssh -L 5900:localhost:5900 root@10.5.3.153`.
212 -
213 -1. boot the install disk (only option)
214 -2. select "English" langage
215 -3. select "Disk Utility"
216 -4. Find the "QEMU HARDDISK Media" disk which is about 130GB
217 -5. click Erase, name: system (exactly `system`), format: Mac OS Extended (Journaled), scheme: GUID Partition Map, click Done
218 -6. exit Disk Utility
219 -7. select "Install macOS"
220 -8. select "system" as the target disk
221 -9. install will proceed and automatically reboot to the new root disk
222 -and continue installation. this takes about 20-30 minutes.
223 -10. Once the install process gets to the "Welcome" screen where you
224 -select a physical location, Ctrl-C the QEMU process, copy the disk
225 -image to another location for safe keeping. This duplicated image will
226 -be used for future fresh re-setting-up like major upgrades:
227 -`cp mac_hdd.img mac-hdd-1-installed-not-set-up.img` save this
228 -somewhere for long-term storage.
229 -11. re-run:
230 -
231 -[root@nixos:~/OSX-KVM]# ./boot-macOS-HS-provision.sh
232 -QEMU 3.0.0 monitor - type 'help' for more information
233 -(qemu)
234 -(qemu) usb_desc_get_descriptor: 2 unknown type 33 (len 10)
235 -usb_desc_get_descriptor: 1 unknown type 33 (len 10)
236 -qemu-system-x86_64: terminating on signal 2
237 -
238 -[root@nixos:~/OSX-KVM]# cp mac_hdd.img mac-hdd-1-installed-not-set-up.img
239 -
240 -[root@nixos:~/OSX-KVM]# ./boot-macOS-HS-provision.sh
241 -QEMU 3.0.0 monitor - type 'help' for more information
242 -(qemu)
243 -
244 -and reconnect over vnc
245 -
246 -12. Select "United States"
247 -13. Select "US" Keyboard
248 -14. When asked to sign in with an Apple ID, click "Set Up Later"
249 -which is probably near the top
250 -15. create a user:
251 - full name: nixos
252 - account name: nixos
253 - password: generate a new one each time, note: nixos is not a good password =)
254 - hint: set no hint
255 -16. select "customize setup"
256 -17. don't enable location services
257 -18. select your timezone: UTC - United Kingdom
258 -19. untick "share mac analytics" and "share crash data"
259 -20. You'll get to the desktop and it'll try to config the keyboard,
260 -press `z` then `/` then select `ANSI` and click Done
261 -21. Click the magnifying glass in the top bar
262 -22. Type "term" and press enter on Terminal
263 -23. Run `sudo systemsetup -setremotelogin on` to turn on SSH. On Catalina,
264 - you may first need to go to the Apple menu > System Preferences >
265 - Security & Privacy > Privacy tab, choose "Full Disk Access" and add the
266 - "Terminal" application.
267 - IMPORTANT: DO NOT TEST SSH AT THIS STAGE!
268 -Testing SSH now would cause the image to generate an SSH host key, and
269 -cause it to be fixed in a generic disk image too soon.
270 -24. Disable the protections preventing you from running unsigned
271 -software: `sudo spctl --master-disable`
272 -25. Enable automaticly mounting ISOs even before users log in,
273 - (should be one line):
274 - `sudo defaults write
275 - /Library/Preferences/SystemConfiguration/autodiskmount
276 - AutomountDisksWithoutUserLogin -bool YES`
277 -26. Load the auto-run script, add the following to
278 - /Library/LaunchDaemons/org.nixos.bootup.plist:
279 -
280 -```
281 -<?xml version="1.0" encoding="UTF-8"?>
282 -<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
283 -<plist version="1.0">
284 -<dict>
285 - <key>Label</key>
286 - <string>org.nixos.bootup</string>
287 - <key>ProgramArguments</key>
288 - <array>
289 - <string>bash</string>
290 - <string>/Volumes/CONFIG/apply.sh</string>
291 - </array>
292 - <key>StandardOutPath</key>
293 - <string>/tmp/apply.stdout</string>
294 - <key>StandardErrorPath</key>
295 - <string>/tmp/apply.stderr</string>
296 - <key>RunAtLoad</key>
297 - <true/>
298 - <key>StartOnMount</key>
299 - <true/>
300 -</dict>
301 -</plist>
302 -```
303 -
304 -Copy-paste it, or if that doesn't work (it doesn't for me,) use a
305 -pastebin. It is annoying to get this wrong, so be careful.
306 -
307 -It might be here already:
308 -https://gist.github.com/grahamc/126b1a28d50d99db315fb5b6fce551c7
309 -
310 -27. Via the apple menu, select Shut Down
311 -28. untick "Reopen windowsn when logging back in"
312 -29. shut down
313 -30. When the computer is shut down, duplicate mac_hd.img again:
314 -`cp mac_hdd.img mac-hdd-2-initial-setup.img` and back this image up
315 -as well. This image is used as the basis for ofborg and hydra
316 -builders.
317 -
318 ----
319 -
320 -Specializing the image
321 -
322 -Try to minimize specialization here
323 -
324 -1. Run `./boot-macOS-HS-provision.sh`
325 -2.
326 -
327 -From now on, we'll be running ./boot-macOS-HS-ephemeral.sh which will
328 -not write to mac_hdd.img. This means that the OS can update the disk
329 -and even persist data across reboots, however all changes go away when
330 -qemu restarts.
331 -
332 -You can now SSH to the host running `./boot-macOS-HS-ephemeral.sh` via
333 -`ssh -p 2200 nixos@10.5.3.153` for provisioning.
334 -
335 -
336 ----
337 -
338 -nixos module for running:
339 -
340 -
341 -activation-time import:
342 -
343 -1. create a zvol for the disk image based on the `import/hash-name` of the
344 - image file in the store
345 -
346 - [nix-shell:~]# zfs create -V $(qemu-img info ./OSX-KVM/mac-hdd-2-initial-setup.img --output=json | jq '."virtual-size"') rpool/imported-disk
347 -
348 -2. qemu-img dd the data from the `.qcow2` to the zvol
349 -
350 - qemu-img dd if=./OSX-KVM/mac-hdd-2-initial-setup.img -f qcow2 of=/dev/zvol/rpool/imported-disk CoC-O raw bs=250000000
351 -
352 - ^ takes ~5min
353 -
354 -3. snapshot zvol to `import/hash-name:import`
355 -
356 -[nix-shell:~]# zfs snapshot rpool/imported-disk@import
357 -
358 -[nix-shell:~]# zfs list -t snapshot
359 -NAME USED AVAIL REFER MOUNTPOINT
360 -rpool/imported-disk@import 0B - 14.5G -
361 -
362 -
363 -
364 -
365 -4. For each `import/*` see if their path is live, if not: delete the
366 - snapshot and zvol (via: `nix-store --query --roots /nix/store/hash-name`
367 -
368 -
369 -run-time code:
370 -
371 -pre-start: roll-back `execute/hash-name` to the snapshot for
372 - `import/hash-name:import`
373 - gene
374 -
375 - zfs rollback rpool/imported-disk@import
376 -
377 - start: execute qemu with the parameters like this:
378 -
379 -<disk type='block' device='disk'>
380 - <driver name='qemu' type='raw' cache='none'/>
381 - <source dev='/dev/zd0'/>
382 - <target dev='vda' bus='virtio'/>
383 - <alias name='virtio-disk0'/>
384 - <address type='pci' domain='0x0000' bus='0x00' slot='0x05' function='0x0'/>
385 -</disk>
386 -
387 -
388 -sudo cp /Volumes/CONFIG/etc/ssh/ssh_host_* /etc/ssh/
389 -sudo chown root:root /etc/ssh/ssh_host_*_key
390 -sudo umount /Volumes/CONFIG
391 -
392 -
393 ----
394 -
395 -Sending a snapshot from macA to macB:
396 -
397 -[nix-shell]$ nixops ssh mac3 -- -A
398 -
399 -[root@mac3:~]# zfs send -cv rpool/mac-hdd-2-initial-setup-startup-script.img@pristine | ssh root@192.168.2.104 zfs recv -sv rpool/mac-hdd-2-initial-setup-startup-script.img
modules/wireguard-hosts.toml
+9 -32
@@ -21,6 +21,15 @@ publicKey = "nG7I9gegJIynKOZ6tzpvmLdCZ/xScTgRZeFvYLFyil4="
21
22 # tombstone: 10.254.1.2 chef
23 # tomstone: 10.254.1.3 ceres
24 +# tombstone: 10.254.2.1 mac1 (host/guest)
25 +# tombstone: 10.254.2.2 mac2 (host/guest)
26 +# tombstone: 10.254.2.3 mac3 (host/guest)
27 +# tombstone: 10.254.2.4 mac4 (host/guest)
28 +# tombstone: 10.254.2.5 mac5 (host/guest)
29 +# tombstone: 10.254.2.6 mac6 (host/guest)
30 +# tombstone: 10.254.2.7 mac7 (host/guest)
31 +# tombstone: 10.254.2.8 mac8 (host/guest)
32 +# tombstone: 10.254.2.9 mac9 (host/guest)
33
34 [hosts.eris]
35 endpoint = "138.201.32.77"
@@ -40,38 +49,6 @@ ip = "10.254.1.9"
49 port = 51820
50 publicKey = "Fb41wGKT1TdC4MG5i2NRx6yduddmqm+N+UOtqtDuBG4="
51
43 -[hosts.mac1]
44 -ip = "10.254.2.1"
45 -publicKey = "ZIzROtHaFWjrhhdXAE8Tq+EhUsSIURLcwsISfudndTk="
46 -
47 -[hosts.mac2]
48 -ip = "10.254.2.2"
49 -publicKey = "m0xJg1OBZIqPu8maxpldLQ1Y39aPS3cnj7hqpVUSuFg="
50 -
51 -[hosts.mac3]
52 -ip = "10.254.2.3"
53 -publicKey = "6urTLKp3ihXw0fy4ImhpiQu/sOxrJYewtg2cbT3jv3g="
54 -
55 -[hosts.mac4]
56 -ip = "10.254.2.4"
57 -publicKey = "ojkldeD0xJw54nAeGSHQw7BMSXnc6c2e6GP4nJ/1xEo="
58 -
59 -[hosts.mac5]
60 -ip = "10.254.2.5"
61 -publicKey = "UgbjJz7BPlD5oDNPr1Bpr4XqeuoL9G5+oUDyU9EVYgg="
62 -
63 -[hosts.mac6]
64 -ip = "10.254.2.6"
65 -publicKey = "5t67sluyRwuDXeY17CG7sbpt0gZNybHzvJYd7NAESis="
66 -
67 -[hosts.mac7]
68 -ip = "10.254.2.7"
69 -publicKey = "q/8YvHa/M0Epyqflp+fEXvBmJuOBaBJPcaAkScCYvHA="
70 -
71 -[hosts.mac8]
72 -ip = "10.254.2.8"
73 -publicKey = "aw/8/5oEn0cZa/WnUE7E7MEukDvzUzaAUEL6PMhLFmE="
74 -
52 [hosts.macofborg1]
53 ip = "10.254.2.51"
54 publicKey = "RPD07xoZYB3aq9hS4pX+qnCHwSbNunK69HGdf8pRtCQ="