aboutsummaryrefslogtreecommitdiffstats
path: root/scripts
diff options
context:
space:
mode:
Diffstat (limited to 'scripts')
-rwxr-xr-xscripts/build.sh7
-rwxr-xr-xscripts/check.sh38
-rw-r--r--scripts/check_get_tests.nix16
-rwxr-xr-xscripts/ping_hosts.sh12
-rwxr-xr-xscripts/test.sh12
-rw-r--r--scripts/update_hosts.remote41
-rwxr-xr-xscripts/update_hosts.sh27
7 files changed, 153 insertions, 0 deletions
diff --git a/scripts/build.sh b/scripts/build.sh
new file mode 100755
index 0000000..a3ff064
--- /dev/null
+++ b/scripts/build.sh
@@ -0,0 +1,7 @@
+#! /usr/bin/env sh
+
+for host in "server2" "server3"; do
+ nix build ".#nixosConfigurations.$host.config.system.build.toplevel" --print-out-paths --no-link --option max-jobs 1
+done
+
+# vim: ft=sh
diff --git a/scripts/check.sh b/scripts/check.sh
new file mode 100755
index 0000000..dbfa67d
--- /dev/null
+++ b/scripts/check.sh
@@ -0,0 +1,38 @@
+#! /usr/bin/env sh
+
+git_root="$(git rev-parse --show-toplevel)"
+
+fmt_check() {
+ echo ".#checks.x86_64-linux.$1"
+}
+
+failed="$(mktemp -t server_check_XXXXX)"
+trap 'rm -f "$failed"' EXIT
+trap 'exit 4' HUP INT QUIT TERM
+
+# We want word-splitting for the arg
+# shellcheck disable=SC2046
+set -- $(nix eval --file "$git_root/scripts/check_get_tests.nix" --raw)
+
+while [ "$#" -ne 0 ]; do
+ test="$1"
+ shift 1
+
+ echo "Building test '$test'..."
+ fmt_test="$(fmt_check "$test")"
+
+ if ! nix build \
+ --option max-jobs 1 \
+ --print-out-paths \
+ --no-link \
+ "$fmt_test"; then
+ echo "$test" >>"$failed"
+ fi
+done
+
+if [ "$(cat "$failed" | wc -l)" -ne 0 ]; then
+ echo "Failed tests:"
+ while read -r test; do
+ echo " - $test"
+ done <"$failed"
+fi
diff --git a/scripts/check_get_tests.nix b/scripts/check_get_tests.nix
new file mode 100644
index 0000000..a39d300
--- /dev/null
+++ b/scripts/check_get_tests.nix
@@ -0,0 +1,16 @@
+let
+ get = input: (builtins.fetchTree input.locked).outPath;
+
+ lock = (builtins.fromJSON (builtins.readFile ../flake.lock)).nodes;
+
+ flake-compat = import (get lock.flake-compat) {src = ../.;};
+ pkgs = import (get lock.nixpkgs) {};
+ inherit (pkgs) lib;
+
+ inherit (flake-compat) outputs;
+in
+ lib.strings.concatStringsSep "\n"
+ (builtins.attrNames
+ (lib.filterAttrs
+ (name: test: test.meta.broken == false)
+ outputs.checks.x86_64-linux))
diff --git a/scripts/ping_hosts.sh b/scripts/ping_hosts.sh
new file mode 100755
index 0000000..fba2490
--- /dev/null
+++ b/scripts/ping_hosts.sh
@@ -0,0 +1,12 @@
+#! /usr/bin/env sh
+
+user="${1-$USER}"
+hosts="${2-server2 server3}"
+
+for host in $hosts; do
+ echo "Checking status of '$user@$host.vhack.eu' ..."
+
+ ssh "$user@$host.vhack.eu" "set -x; systemctl --failed"
+done
+
+# vim: ft=sh
diff --git a/scripts/test.sh b/scripts/test.sh
new file mode 100755
index 0000000..58c3343
--- /dev/null
+++ b/scripts/test.sh
@@ -0,0 +1,12 @@
+#!/usr/bin/env sh
+
+test_target="$1"
+
+[ -z "$test_target" ] && {
+ echo "You need to select a test target!" 1>&2
+ echo "Usage: test_interactive TEST_TARGET" 1>&2
+ exit 1
+}
+
+nix build --log-format multiline-with-logs .#checks.x86_64-linux."$test_target"
+# vim: ft=sh
diff --git a/scripts/update_hosts.remote b/scripts/update_hosts.remote
new file mode 100644
index 0000000..249b24e
--- /dev/null
+++ b/scripts/update_hosts.remote
@@ -0,0 +1,41 @@
+#! /usr/bin/env sh
+
+# This is the remote side of `update_hosts.sh`, it will be copied to the remote host
+# and is responsible for performing the update.
+
+set -e
+
+PATH_add() {
+ nix_expr="$1"
+ what="$(nix build "nixpkgs#$nix_expr.out" --print-out-paths --no-link)"
+
+ printf "Adding '%s' (%s/bin) to PATH..\n" "$nix_expr" "$what"
+
+ PATH="$what/bin:$PATH"
+ export PATH
+}
+
+branch="$1"
+
+# We don't have access to git by default, so evaluate it here
+PATH_add git
+
+# By-default these systems use cppnix, which can't build our config. So let's switch to
+# lix.
+PATH_add lixPackageSets.latest.lix
+
+# We might or might not have python, and we need it, because we use the unwrapped
+# `nixos-update`.
+PATH_add python3
+PATH_add nixos-rebuild
+
+set -x
+cd /etc/nixos
+
+sudo git fetch --all --prune
+sudo git switch "$branch"
+sudo git pull --rebase
+
+PYTHONNOUSERSITE='true' sudo --preserve-env=PATH --preserve-env=PYTHONNOUSERSITE ".nixos-rebuild-wrapped" --no-reexec boot
+
+sudo reboot
diff --git a/scripts/update_hosts.sh b/scripts/update_hosts.sh
new file mode 100755
index 0000000..cc459ed
--- /dev/null
+++ b/scripts/update_hosts.sh
@@ -0,0 +1,27 @@
+#! /usr/bin/env sh
+set -e
+
+base_dir="$(git rev-parse --show-toplevel)"
+
+user="${1-$USER}"
+hosts="${2-server2 server3}"
+branch="${3-main}"
+
+for host in $hosts; do
+ echo "Updating '$user@$host.vhack.eu' ..."
+
+ printf "Copying closure ..\n"
+ nix copy --substitute-on-destination --to "ssh://$user@$host.vhack.eu" ".#nixosConfigurations.$host.config.system.build.toplevel"
+
+ printf "Deploying remote side script ..\n"
+ scp "$base_dir/scripts/update_hosts.remote" "$user@$host.vhack.eu:update_host.remote"
+
+ printf "Executing remote side script ..\n"
+ ssh -t "$user@$host.vhack.eu" "chmod +x update_host.remote; ./update_host.remote '$branch'"
+done
+
+# Give the servers some time to reboot
+sleep 5
+ping_hosts.sh
+
+# vim: ft=sh