diff options
Diffstat (limited to 'scripts')
| -rwxr-xr-x | scripts/build.sh | 7 | ||||
| -rwxr-xr-x | scripts/check.sh | 38 | ||||
| -rw-r--r-- | scripts/check_get_tests.nix | 16 | ||||
| -rwxr-xr-x | scripts/ping_hosts.sh | 12 | ||||
| -rwxr-xr-x | scripts/test.sh | 12 | ||||
| -rw-r--r-- | scripts/update_hosts.remote | 41 | ||||
| -rwxr-xr-x | scripts/update_hosts.sh | 27 |
7 files changed, 153 insertions, 0 deletions
diff --git a/scripts/build.sh b/scripts/build.sh new file mode 100755 index 0000000..a3ff064 --- /dev/null +++ b/scripts/build.sh @@ -0,0 +1,7 @@ +#! /usr/bin/env sh + +for host in "server2" "server3"; do + nix build ".#nixosConfigurations.$host.config.system.build.toplevel" --print-out-paths --no-link --option max-jobs 1 +done + +# vim: ft=sh diff --git a/scripts/check.sh b/scripts/check.sh new file mode 100755 index 0000000..dbfa67d --- /dev/null +++ b/scripts/check.sh @@ -0,0 +1,38 @@ +#! /usr/bin/env sh + +git_root="$(git rev-parse --show-toplevel)" + +fmt_check() { + echo ".#checks.x86_64-linux.$1" +} + +failed="$(mktemp -t server_check_XXXXX)" +trap 'rm -f "$failed"' EXIT +trap 'exit 4' HUP INT QUIT TERM + +# We want word-splitting for the arg +# shellcheck disable=SC2046 +set -- $(nix eval --file "$git_root/scripts/check_get_tests.nix" --raw) + +while [ "$#" -ne 0 ]; do + test="$1" + shift 1 + + echo "Building test '$test'..." + fmt_test="$(fmt_check "$test")" + + if ! nix build \ + --option max-jobs 1 \ + --print-out-paths \ + --no-link \ + "$fmt_test"; then + echo "$test" >>"$failed" + fi +done + +if [ "$(cat "$failed" | wc -l)" -ne 0 ]; then + echo "Failed tests:" + while read -r test; do + echo " - $test" + done <"$failed" +fi diff --git a/scripts/check_get_tests.nix b/scripts/check_get_tests.nix new file mode 100644 index 0000000..a39d300 --- /dev/null +++ b/scripts/check_get_tests.nix @@ -0,0 +1,16 @@ +let + get = input: (builtins.fetchTree input.locked).outPath; + + lock = (builtins.fromJSON (builtins.readFile ../flake.lock)).nodes; + + flake-compat = import (get lock.flake-compat) {src = ../.;}; + pkgs = import (get lock.nixpkgs) {}; + inherit (pkgs) lib; + + inherit (flake-compat) outputs; +in + lib.strings.concatStringsSep "\n" + (builtins.attrNames + (lib.filterAttrs + (name: test: test.meta.broken == false) + outputs.checks.x86_64-linux)) diff --git a/scripts/ping_hosts.sh b/scripts/ping_hosts.sh new file mode 100755 index 0000000..fba2490 --- /dev/null +++ b/scripts/ping_hosts.sh @@ -0,0 +1,12 @@ +#! /usr/bin/env sh + +user="${1-$USER}" +hosts="${2-server2 server3}" + +for host in $hosts; do + echo "Checking status of '$user@$host.vhack.eu' ..." + + ssh "$user@$host.vhack.eu" "set -x; systemctl --failed" +done + +# vim: ft=sh diff --git a/scripts/test.sh b/scripts/test.sh new file mode 100755 index 0000000..58c3343 --- /dev/null +++ b/scripts/test.sh @@ -0,0 +1,12 @@ +#!/usr/bin/env sh + +test_target="$1" + +[ -z "$test_target" ] && { + echo "You need to select a test target!" 1>&2 + echo "Usage: test_interactive TEST_TARGET" 1>&2 + exit 1 +} + +nix build --log-format multiline-with-logs .#checks.x86_64-linux."$test_target" +# vim: ft=sh diff --git a/scripts/update_hosts.remote b/scripts/update_hosts.remote new file mode 100644 index 0000000..249b24e --- /dev/null +++ b/scripts/update_hosts.remote @@ -0,0 +1,41 @@ +#! /usr/bin/env sh + +# This is the remote side of `update_hosts.sh`, it will be copied to the remote host +# and is responsible for performing the update. + +set -e + +PATH_add() { + nix_expr="$1" + what="$(nix build "nixpkgs#$nix_expr.out" --print-out-paths --no-link)" + + printf "Adding '%s' (%s/bin) to PATH..\n" "$nix_expr" "$what" + + PATH="$what/bin:$PATH" + export PATH +} + +branch="$1" + +# We don't have access to git by default, so evaluate it here +PATH_add git + +# By-default these systems use cppnix, which can't build our config. So let's switch to +# lix. +PATH_add lixPackageSets.latest.lix + +# We might or might not have python, and we need it, because we use the unwrapped +# `nixos-update`. +PATH_add python3 +PATH_add nixos-rebuild + +set -x +cd /etc/nixos + +sudo git fetch --all --prune +sudo git switch "$branch" +sudo git pull --rebase + +PYTHONNOUSERSITE='true' sudo --preserve-env=PATH --preserve-env=PYTHONNOUSERSITE ".nixos-rebuild-wrapped" --no-reexec boot + +sudo reboot diff --git a/scripts/update_hosts.sh b/scripts/update_hosts.sh new file mode 100755 index 0000000..cc459ed --- /dev/null +++ b/scripts/update_hosts.sh @@ -0,0 +1,27 @@ +#! /usr/bin/env sh +set -e + +base_dir="$(git rev-parse --show-toplevel)" + +user="${1-$USER}" +hosts="${2-server2 server3}" +branch="${3-main}" + +for host in $hosts; do + echo "Updating '$user@$host.vhack.eu' ..." + + printf "Copying closure ..\n" + nix copy --substitute-on-destination --to "ssh://$user@$host.vhack.eu" ".#nixosConfigurations.$host.config.system.build.toplevel" + + printf "Deploying remote side script ..\n" + scp "$base_dir/scripts/update_hosts.remote" "$user@$host.vhack.eu:update_host.remote" + + printf "Executing remote side script ..\n" + ssh -t "$user@$host.vhack.eu" "chmod +x update_host.remote; ./update_host.remote '$branch'" +done + +# Give the servers some time to reboot +sleep 5 +ping_hosts.sh + +# vim: ft=sh |
