Files
infra-nix/Makefile
T
danlin c4938a6c05 Remove plaintext secrets, update SSH key, and upgrade to NixOS 25.11
Replace initialPassword with hashedPassword for danlin user, move
FileBrowser admin password to external environmentFile with restricted
secrets directory, update SSH authorized key, and bump nixpkgs to 25.11.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-19 17:44:03 +01:00

154 lines
6.5 KiB
Makefile

.PHONY: help deploy deploy-gateway deploy-fileserver deploy-k8s-server install-gateway install-fileserver install-k8s-server fetch-hwconfig-gateway fetch-hwconfig-fileserver fetch-hwconfig-k8s-server all
# Hosts
GATEWAY_HOST := danlin@10.202.82.3
FILESERVER_HOST := danlin@10.202.82.6
K8S_HOST := danlin@10.202.82.7
# Default target
all: deploy
help:
@echo "NixOS Infrastructure Management"
@echo ""
@echo "Targets:"
@echo " make deploy Deploy to gateway and fileserver"
@echo " make deploy-gateway Deploy to gateway only"
@echo " make deploy-fileserver Deploy to fileserver only"
@echo " make deploy-k8s-server Deploy to k8s-server only"
@echo " make install-gateway Run installation script for gateway"
@echo " make install-fileserver Run installation script for fileserver"
@echo " make install-k8s-server Run installation script for k8s-server"
@echo " make fetch-hwconfig-gateway Fetch hardware config from gateway"
@echo " make fetch-hwconfig-fileserver Fetch hardware config from fileserver"
@echo " make fetch-hwconfig-k8s-server Fetch hardware config from k8s-server"
@echo ""
# Deployment targets
deploy: deploy-gateway deploy-fileserver
deploy-k8s-server:
@echo "======================================"
@echo "Deploying k8s-server..."
@echo "======================================"
@echo "Syncing files to k8s-server..."
rsync -av --delete --exclude '.git' ./ $(K8S_HOST):/tmp/infra-nix/
@echo "Building and switching on k8s-server..."
ssh -tt $(K8S_HOST) "cd /tmp/infra-nix && sudo nixos-rebuild switch --flake '.#k8s-server'"
@echo "✓ k8s-server deployed successfully"
@echo ""
deploy-gateway:
@echo "======================================"
@echo "Deploying gateway..."
@echo "======================================"
@echo "Syncing files to gateway..."
rsync -av --delete --exclude '.git' ./ $(GATEWAY_HOST):/tmp/infra-nix/
@echo "Building and switching on gateway..."
ssh -tt $(GATEWAY_HOST) "cd /tmp/infra-nix && sudo nixos-rebuild switch --flake '.#gateway'"
@echo "✓ Gateway deployed successfully"
@echo ""
deploy-fileserver:
@echo "======================================"
@echo "Deploying fileserver..."
@echo "======================================"
@echo "Syncing files to fileserver..."
rsync -av --delete --exclude '.git' --exclude 'src/dj-beets/poetry.lock' ./ $(FILESERVER_HOST):/tmp/infra-nix/
@echo "Copying dj-beets project to /opt/dj-beets..."
ssh $(FILESERVER_HOST) "sudo mkdir -p /opt/dj-beets"
rsync -av --delete src/dj-beets/ $(FILESERVER_HOST):/tmp/dj-beets-tmp/
ssh $(FILESERVER_HOST) "sudo rsync -a --delete /tmp/dj-beets-tmp/ /opt/dj-beets/ && sudo rm -rf /tmp/dj-beets-tmp"
@echo "Building and switching on fileserver..."
ssh -tt $(FILESERVER_HOST) "cd /tmp/infra-nix && sudo nixos-rebuild switch --flake '.#fileserver'"
@echo "✓ Fileserver deployed successfully"
@echo ""
# Installation targets
install-gateway:
@echo "======================================"
@echo "Installing gateway..."
@echo "======================================"
@read -p "Enter gateway IP address: " IP; \
if [ -z "$$IP" ]; then \
echo "Error: IP address required"; \
exit 1; \
fi; \
echo "Copying install script to $$IP..."; \
scp install/install-gateway.sh root@$$IP:/tmp/; \
echo "Connecting to $$IP..."; \
ssh root@$$IP "bash /tmp/install-gateway.sh"; \
echo ""; \
echo "Fetching hardware config from $$IP..."; \
scp root@$$IP:/mnt/etc/nixos/hardware-configuration.nix hosts/gateway/hardware-configuration.nix; \
echo "✓ Hardware config saved to hosts/gateway/hardware-configuration.nix"; \
echo "✓ Update hosts/gateway/configuration.nix with the correct IP if needed"
@echo ""
install-fileserver:
@echo "======================================"
@echo "Installing fileserver..."
@echo "======================================"
@read -p "Enter fileserver IP address: " IP; \
if [ -z "$$IP" ]; then \
echo "Error: IP address required"; \
exit 1; \
fi; \
echo "Copying install script to $$IP..."; \
scp install/install-fileserver.sh root@$$IP:/tmp/; \
echo "Connecting to $$IP..."; \
ssh root@$$IP "bash /tmp/install-fileserver.sh"; \
echo ""; \
echo "Fetching hardware config from $$IP..."; \
scp root@$$IP:/mnt/etc/nixos/hardware-configuration.nix hosts/fileserver/hardware-configuration.nix; \
echo "✓ Hardware config saved to hosts/fileserver/hardware-configuration.nix"; \
echo "✓ Update hosts/fileserver/configuration.nix with the correct IP if needed"
@echo ""
install-k8s-server:
@echo "======================================"
@echo "Installing k8s-server..."
@echo "======================================"
@read -p "Enter k8s-server IP address: " IP; \
if [ -z "$$IP" ]; then \
echo "Error: IP address required"; \
exit 1; \
fi; \
echo "Copying install script to $$IP..."; \
scp install/install-k8s-server.sh root@$$IP:/tmp/; \
echo "Connecting to $$IP..."; \
ssh root@$$IP "bash /tmp/install-k8s-server.sh"; \
echo ""; \
echo "Fetching hardware config from $$IP..."; \
scp root@$$IP:/mnt/etc/nixos/hardware-configuration.nix hosts/k8s-server/hardware-configuration.nix; \
echo "✓ Hardware config saved to hosts/k8s-server/hardware-configuration.nix"; \
scp root@$$IP:/mnt/etc/nixos/configuration.nix hosts/k8s-server/configuration.installer.nix; \
echo "✓ Installer config saved to hosts/k8s-server/configuration.installer.nix"; \
echo "✓ Update hosts/k8s-server/configuration.nix with the correct IP if needed"
@echo ""
# Fetch hardware configuration targets
fetch-hwconfig-gateway:
@echo "======================================"
@echo "Fetching hardware config from gateway..."
@echo "======================================"
scp $(GATEWAY_HOST):/etc/nixos/hardware-configuration.nix hosts/gateway/
@echo "✓ Hardware config saved to hosts/gateway/hardware-configuration.nix"
@echo ""
fetch-hwconfig-fileserver:
@echo "======================================"
@echo "Fetching hardware config from fileserver..."
@echo "======================================"
scp $(FILESERVER_HOST):/etc/nixos/hardware-configuration.nix hosts/fileserver/
@echo "✓ Hardware config saved to hosts/fileserver/hardware-configuration.nix"
@echo ""
fetch-hwconfig-k8s-server:
@echo "======================================"
@echo "Fetching hardware config from k8s-server..."
@echo "======================================"
scp $(K8S_HOST):/etc/nixos/hardware-configuration.nix hosts/k8s-server/
@echo "✓ Hardware config saved to hosts/k8s-server/hardware-configuration.nix"
@echo ""