@cryptotaxi247 / infra / commits / b6361c77

rhea: Add terraform

Eelco Dolstra committed Aug 24, 2023 at 14:58 UTC b6361c772490ee42c34290b0468585a573db2fc9
7 files changed +266 -28
delft/flake.nix
-23
@@ -31,28 +31,5 @@
31 ];
32 }) self.nixopsConfigurations.default) ["defaults"];
33 */
34 -
35 - nixosConfigurations.rhea = nixpkgs.lib.nixosSystem {
36 - system = "x86_64-linux";
37 -
38 - modules = [
39 - self.nixosModules.common
40 - ./rhea
41 - hydra.nixosModules.hydra
42 - hydra-scale-equinix-metal.nixosModules.default
43 - ];
44 - };
45 -
46 - nixosModules.common =
47 - { config, pkgs, lib, ... }:
48 - {
49 - system.configurationRevision = self.rev
50 - or (throw "Cannot deploy from an unclean source tree!");
51 - #nix.registry.nixpkgs.flake = nixpkgs;
52 - #nix.nixPath = [ "nixpkgs=${nixpkgs}" ];
53 - nixpkgs.overlays = [
54 - nix.overlays.default
55 - ];
56 - };
34 };
35 }
delft/network.nix
-5
@@ -21,9 +21,4 @@ in
21 haumea = {
22 imports = [ ./haumea.nix ];
23 };
24 -
25 - rhea = {
26 - imports = [
27 - ];
28 - };
24 }
delft/rhea/.terraform.lock.hcl new
+23
@@ -0,0 +1,23 @@
1 +# This file is maintained automatically by "terraform init".
2 +# Manual edits may be lost in future updates.
3 +
4 +provider "registry.terraform.io/hashicorp/aws" {
5 + version = "4.67.0"
6 + hashes = [
7 + "h1:pCGXG/u7M45bMT9Lhl+/AZXR8W9OKC7rqmhX3MRleIA=",
8 + ]
9 +}
10 +
11 +provider "registry.terraform.io/hashicorp/external" {
12 + version = "2.3.1"
13 + hashes = [
14 + "h1:ZYhI0/Y84RduL4iUp+aLZLnxYn4VtrkCA7PvKCUHH8Y=",
15 + ]
16 +}
17 +
18 +provider "registry.terraform.io/hashicorp/null" {
19 + version = "3.2.1"
20 + hashes = [
21 + "h1:k3cEf/GT9dmraVYPKhFvEzjYIyEpeepn+Lm3JFQ4z6c=",
22 + ]
23 +}
delft/rhea/configuration.nix renamed
delft/rhea/flake.lock new
+174
@@ -0,0 +1,174 @@
1 +{
2 + "nodes": {
3 + "flake-compat": {
4 + "flake": false,
5 + "locked": {
6 + "lastModified": 1673956053,
7 + "narHash": "sha256-4gtG9iQuiKITOjNQQeQIpoIB6b16fm+504Ch3sNKLd8=",
8 + "owner": "edolstra",
9 + "repo": "flake-compat",
10 + "rev": "35bb57c0c8d8b62bbfd284272c928ceb64ddbde9",
11 + "type": "github"
12 + },
13 + "original": {
14 + "owner": "edolstra",
15 + "repo": "flake-compat",
16 + "type": "github"
17 + }
18 + },
19 + "hydra": {
20 + "inputs": {
21 + "nix": "nix",
22 + "nixpkgs": "nixpkgs"
23 + },
24 + "locked": {
25 + "lastModified": 1692805994,
26 + "narHash": "sha256-e+68WCN1e1h2rf1pmwNNukTt5EBtF9KQNXhqJtoyJzo=",
27 + "owner": "NixOS",
28 + "repo": "hydra",
29 + "rev": "00d30874da759eb0f44f446415b2469920ff41b5",
30 + "type": "github"
31 + },
32 + "original": {
33 + "owner": "NixOS",
34 + "repo": "hydra",
35 + "type": "github"
36 + }
37 + },
38 + "hydra-scale-equinix-metal": {
39 + "inputs": {
40 + "nixpkgs": "nixpkgs_2"
41 + },
42 + "locked": {
43 + "lastModified": 1680536851,
44 + "narHash": "sha256-I8jHYivqyFz1JuUFAIGcYznNlv35Shr3oKBsQFaoBrY=",
45 + "owner": "DeterminateSystems",
46 + "repo": "hydra-scale-equinix-metal",
47 + "rev": "6166086b234334ea242c6d9958b6c3e594867382",
48 + "type": "github"
49 + },
50 + "original": {
51 + "owner": "DeterminateSystems",
52 + "repo": "hydra-scale-equinix-metal",
53 + "type": "github"
54 + }
55 + },
56 + "lowdown-src": {
57 + "flake": false,
58 + "locked": {
59 + "lastModified": 1633514407,
60 + "narHash": "sha256-Dw32tiMjdK9t3ETl5fzGrutQTzh2rufgZV4A/BbxuD4=",
61 + "owner": "kristapsdz",
62 + "repo": "lowdown",
63 + "rev": "d2c2b44ff6c27b936ec27358a2653caaef8f73b8",
64 + "type": "github"
65 + },
66 + "original": {
67 + "owner": "kristapsdz",
68 + "repo": "lowdown",
69 + "type": "github"
70 + }
71 + },
72 + "nix": {
73 + "inputs": {
74 + "flake-compat": "flake-compat",
75 + "lowdown-src": "lowdown-src",
76 + "nixpkgs": [
77 + "hydra",
78 + "nixpkgs"
79 + ],
80 + "nixpkgs-regression": "nixpkgs-regression"
81 + },
82 + "locked": {
83 + "lastModified": 1690219894,
84 + "narHash": "sha256-QMYAkdtU+g9HlZKtoJ+AI6TbWzzovKGnPZJHfZdclc8=",
85 + "owner": "NixOS",
86 + "repo": "nix",
87 + "rev": "a212300a1d9f9c7b0daf19c00c87fc50480f54f4",
88 + "type": "github"
89 + },
90 + "original": {
91 + "owner": "NixOS",
92 + "ref": "2.17.0",
93 + "repo": "nix",
94 + "type": "github"
95 + }
96 + },
97 + "nixpkgs": {
98 + "locked": {
99 + "lastModified": 1687379288,
100 + "narHash": "sha256-cSuwfiqYfeVyqzCRkU9AvLTysmEuSal8nh6CYr+xWog=",
101 + "owner": "NixOS",
102 + "repo": "nixpkgs",
103 + "rev": "ef0bc3976340dab9a4e087a0bcff661a8b2e87f3",
104 + "type": "github"
105 + },
106 + "original": {
107 + "owner": "NixOS",
108 + "ref": "nixos-23.05",
109 + "repo": "nixpkgs",
110 + "type": "github"
111 + }
112 + },
113 + "nixpkgs-regression": {
114 + "locked": {
115 + "lastModified": 1643052045,
116 + "narHash": "sha256-uGJ0VXIhWKGXxkeNnq4TvV3CIOkUJ3PAoLZ3HMzNVMw=",
117 + "owner": "NixOS",
118 + "repo": "nixpkgs",
119 + "rev": "215d4d0fd80ca5163643b03a33fde804a29cc1e2",
120 + "type": "github"
121 + },
122 + "original": {
123 + "owner": "NixOS",
124 + "repo": "nixpkgs",
125 + "rev": "215d4d0fd80ca5163643b03a33fde804a29cc1e2",
126 + "type": "github"
127 + }
128 + },
129 + "nixpkgs_2": {
130 + "locked": {
131 + "lastModified": 1680213900,
132 + "narHash": "sha256-cIDr5WZIj3EkKyCgj/6j3HBH4Jj1W296z7HTcWj1aMA=",
133 + "owner": "nixos",
134 + "repo": "nixpkgs",
135 + "rev": "e3652e0735fbec227f342712f180f4f21f0594f2",
136 + "type": "github"
137 + },
138 + "original": {
139 + "owner": "nixos",
140 + "ref": "nixos-unstable",
141 + "repo": "nixpkgs",
142 + "type": "github"
143 + }
144 + },
145 + "nixpkgs_3": {
146 + "locked": {
147 + "lastModified": 1692543165,
148 + "narHash": "sha256-3Zar2aWrNbzSCnN2Q5A05zX1W9tvAqyibNkVJryID+c=",
149 + "owner": "NixOS",
150 + "repo": "nixpkgs",
151 + "rev": "52e3c9e18f8ff4a930b444675b6325552f12d104",
152 + "type": "github"
153 + },
154 + "original": {
155 + "id": "nixpkgs",
156 + "ref": "nixos-23.05-small",
157 + "type": "indirect"
158 + }
159 + },
160 + "root": {
161 + "inputs": {
162 + "hydra": "hydra",
163 + "hydra-scale-equinix-metal": "hydra-scale-equinix-metal",
164 + "nix": [
165 + "hydra",
166 + "nix"
167 + ],
168 + "nixpkgs": "nixpkgs_3"
169 + }
170 + }
171 + },
172 + "root": "root",
173 + "version": 7
174 +}
delft/rhea/flake.nix new
+43
@@ -0,0 +1,43 @@
1 +{
2 + inputs.nixpkgs.url = "nixpkgs/nixos-23.05-small";
3 + inputs.nix.follows = "hydra/nix";
4 + inputs.hydra.url = "github:NixOS/hydra";
5 + inputs.hydra-scale-equinix-metal.url = "github:DeterminateSystems/hydra-scale-equinix-metal";
6 +
7 + outputs = flakes @ { self, nixpkgs, nix, hydra, hydra-scale-equinix-metal }: {
8 + nixosConfigurations.rhea = nixpkgs.lib.nixosSystem {
9 + system = "x86_64-linux";
10 +
11 + modules = [
12 + self.nixosModules.common
13 + ./configuration.nix
14 + hydra.nixosModules.hydra
15 + hydra-scale-equinix-metal.nixosModules.default
16 + ];
17 + };
18 +
19 + nixosModules.common =
20 + { config, pkgs, lib, ... }:
21 + {
22 + system.configurationRevision = self.rev
23 + or (throw "Cannot deploy from an unclean source tree!");
24 + #nix.registry.nixpkgs.flake = nixpkgs;
25 + #nix.nixPath = [ "nixpkgs=${nixpkgs}" ];
26 + nixpkgs.overlays = [
27 + nix.overlays.default
28 + ];
29 + };
30 +
31 + devShell.x86_64-linux =
32 + with nixpkgs.legacyPackages.x86_64-linux;
33 + mkShell {
34 + nativeBuildInputs = [
35 + (terraform.withPlugins (p: with p; [ aws p.null external ]))
36 + ];
37 +
38 + shellHook = ''
39 + alias tf=terraform
40 + '';
41 + };
42 + };
43 +}
delft/rhea/terraform.tf new
+26
@@ -0,0 +1,26 @@
1 +terraform {
2 + backend "s3" {
3 + bucket = "nixos-terraform-state"
4 + encrypt = true
5 + key = "targets/rhea"
6 + region = "eu-west-1"
7 + }
8 +
9 + required_providers {
10 + aws = {
11 + source = "hashicorp/aws"
12 + }
13 + }
14 +}
15 +
16 +module "rhea_deploy" {
17 + source = "github.com/numtide/terraform-deploy-nixos-flakes"
18 +
19 + target_host = "5.9.122.43"
20 + target_user = "root"
21 +
22 + flake = path.module
23 + flake_host = "rhea"
24 +
25 + ssh_agent = true
26 +}