summary refs log tree commit diff
path: root/nixos/modules/virtualisation/nova-config.nix
blob: cecf2a3f144c1ae5ad2dca91479ed8f06c6e1f46 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
{ lib, ... }:

with lib;

{
  imports = [
    ../profiles/qemu-guest.nix
    ../profiles/headless.nix
  ];

  config = {
    fileSystems."/" = {
      device = "/dev/disk/by-label/nixos";
      autoResize = true;
    };

    boot.growPartition = true;
    boot.kernelParams = [ "console=ttyS0" ];
    boot.loader.grub.device = "/dev/vda";
    boot.loader.timeout = 0;

    # Allow root logins
    services.openssh = {
      enable = true;
      permitRootLogin = "prohibit-password";
      passwordAuthentication = mkDefault false;
    };

    services.cloud-init.enable = true;

    # Put /tmp and /var on /ephemeral0, which has a lot more space.
    # Unfortunately we can't do this with the `fileSystems' option
    # because it has no support for creating the source of a bind
    # mount.  Also, "move" /nix to /ephemeral0 by layering a unionfs-fuse
    # mount on top of it so we have a lot more space for Nix operations.

    /*
    boot.initrd.postMountCommands =
      ''
        mkdir -m 1777 -p $targetRoot/ephemeral0/tmp
        mkdir -m 1777 -p $targetRoot/tmp
        mount --bind $targetRoot/ephemeral0/tmp $targetRoot/tmp

        mkdir -m 755 -p $targetRoot/ephemeral0/var
        mkdir -m 755 -p $targetRoot/var
        mount --bind $targetRoot/ephemeral0/var $targetRoot/var

        mkdir -p /unionfs-chroot/ro-nix
        mount --rbind $targetRoot/nix /unionfs-chroot/ro-nix

        mkdir -p /unionfs-chroot/rw-nix
        mkdir -m 755 -p $targetRoot/ephemeral0/nix
        mount --rbind $targetRoot/ephemeral0/nix /unionfs-chroot/rw-nix
        unionfs -o allow_other,cow,nonempty,chroot=/unionfs-chroot,max_files=32768 /rw-nix=RW:/ro-nix=RO $targetRoot/nix
      '';

      boot.initrd.supportedFilesystems = [ "unionfs-fuse" ];
    */
  };
}