Impermanence.

This commit is contained in:
Lorenzo Good 2025-02-03 17:19:22 -06:00
parent 859556d0e6
commit abeef2cb58
Signed by: lorenzo
GPG key ID: 7FCD64BD81180ED0
5 changed files with 105 additions and 1 deletions

View file

@ -17,6 +17,31 @@
boot.extraModulePackages = [];
boot.supportedFilesystems = ["btrfs"];
boot.initrd.postDeviceCommands = lib.mkAfter ''
mkdir /btrfs_tmp
mount /dev/disk/by-label/NIXROOT /btrfs_tmp
if [[ -e /btrfs_tmp/root ]]; then
mkdir -p /btrfs_tmp/old_roots
timestamp=$(date --date="@$(stat -c %Y /btrfs_tmp/root)" "+%Y-%m-%-d_%H:%M:%S")
mv /btrfs_tmp/root "/btrfs_tmp/old_roots/$timestamp"
fi
delete_subvolume_recursively() {
IFS=$'\n'
for i in $(btrfs subvolume list -o "$1" | cut -f 9- -d ' '); do
delete_subvolume_recursively "/btrfs_tmp/$i"
done
btrfs subvolume delete "$1"
}
for i in $(find /btrfs_tmp/old_roots/ -maxdepth 1 -mtime +30); do
delete_subvolume_recursively "$i"
done
btrfs subvolume create /btrfs_tmp/root
umount /btrfs_tmp
'';
fileSystems."/" = {
device = "/dev/disk/by-label/NIXROOT";
fsType = "btrfs";

View file

@ -0,0 +1,24 @@
{config, ...}: {
sops.age.sshKeyPaths = ["/persist/etc/ssh/ssh_host_ed25519_key"];
environment.persistence."/persist" = {
directories =
[
"/var/lib/tailscale"
"/var/log"
"/var/lib/nixos"
"/var/lib/docker"
]
++ config.foehammer.backups.paths;
files = [
"/etc/machine-id"
"/etc/ssh/ssh_host_rsa_key.pub"
"/etc/ssh/ssh_host_rsa_key"
"/etc/ssh/ssh_host_ed25519_key"
"/etc/ssh/ssh_host_ed25519_key.pub"
"/var/lib/systemd/random-seed"
"/var/lib/logrotate.status"
];
};
}

View file

@ -34,6 +34,21 @@
"type": "github"
}
},
"impermanence": {
"locked": {
"lastModified": 1737831083,
"narHash": "sha256-LJggUHbpyeDvNagTUrdhe/pRVp4pnS6wVKALS782gRI=",
"owner": "nix-community",
"repo": "impermanence",
"rev": "4b3e914cdf97a5b536a889e939fb2fd2b043a170",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "impermanence",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1737672001,
@ -97,6 +112,7 @@
"root": {
"inputs": {
"common": "common",
"impermanence": "impermanence",
"nixpkgs": "nixpkgs_2",
"sops-nix": "sops-nix"
}

View file

@ -7,6 +7,10 @@
sops-nix = {
url = "github:Mic92/sops-nix";
};
impermanence = {
url = "github:nix-community/impermanence";
};
};
outputs = inputs @ {common, ...}: let
supportedSystems = ["x86_64-linux" "aarch64-linux" "x86_64-darwin" "aarch64-darwin"];
@ -19,7 +23,11 @@
in {
nixosConfigurations.default = let
config = common.lib.utils.findNixFiles ./config;
modules = [inputs.sops-nix.nixosModules.sops inputs.common.nixosModules.default];
modules = [
inputs.sops-nix.nixosModules.sops
inputs.common.nixosModules.default
inputs.impermanence.nixosModules.impermanence
];
in
common.lib.mkSystem "lebesgue" "x86_64-linux" (config ++ modules);

View file

@ -0,0 +1,31 @@
#!/usr/bin/env bash
# fs-diff.sh
# run on server.
set -euo pipefail
if [[ -f /mnt ]]; then
mkdir /mnt
fi
if ! mountpoint /mnt > /dev/null; then
mount -t btrfs /dev/disk/by-label/NIXROOT /mnt
fi
OLD_TRANSID=$(sudo btrfs subvolume find-new /mnt/root-blank 9999999)
OLD_TRANSID=${OLD_TRANSID#transid marker was }
sudo btrfs subvolume find-new "/mnt/root" "$OLD_TRANSID" |
sed '$d' |
cut -f17- -d' ' |
sort |
uniq |
while read path; do
path="/$path"
if [ -L "$path" ]; then
: # The path is a symbolic link, so is probably handled by NixOS already
elif [ -d "$path" ]; then
: # The path is a directory, ignore
else
echo "$path"
fi
done