feat: migrated users over to new persistence structure
This commit is contained in:
parent
37f5e65bd6
commit
d06c25f33f
29 changed files with 57 additions and 99 deletions
|
|
@ -400,74 +400,60 @@ in {
|
|||
};
|
||||
}
|
||||
(lib.mkIf config.storage.impermanence.enable (lib.mkMerge [
|
||||
(lib.mkIf config.storage.zfs.enable {
|
||||
storage.zfs.datasets."persist/system/sops" = {
|
||||
type = "zfs_fs";
|
||||
mount = {
|
||||
enable = true;
|
||||
mountPoint = SOPS_AGE_KEY_DIRECTORY;
|
||||
(lib.mkIf config.storage.zfs.enable (lib.mkMerge [
|
||||
{
|
||||
# sops age key needs to be available to pre persist for user generation
|
||||
storage.zfs.datasets = lib.mkMerge [
|
||||
{
|
||||
"local/system/sops" = {
|
||||
type = "zfs_fs";
|
||||
mount = {
|
||||
enable = true;
|
||||
mountPoint = SOPS_AGE_KEY_DIRECTORY;
|
||||
};
|
||||
atime = "off";
|
||||
relatime = "off";
|
||||
};
|
||||
}
|
||||
# Create ZFS datasets for each normal user
|
||||
(lib.mkMerge (
|
||||
builtins.map (user: {
|
||||
"local/home/${user.name}" = {
|
||||
type = "zfs_fs";
|
||||
mount = {
|
||||
enable = true;
|
||||
mountPoint = "/home/${user.name}";
|
||||
};
|
||||
snapshot.blankSnapshot = true;
|
||||
};
|
||||
"persist/home/${user.name}" = {
|
||||
type = "zfs_fs";
|
||||
mount = {
|
||||
enable = true;
|
||||
mountPoint = "/persist/home/${user.name}";
|
||||
};
|
||||
};
|
||||
})
|
||||
normalUsers
|
||||
))
|
||||
];
|
||||
|
||||
# Post resume commands to rollback user home datasets to blank snapshots
|
||||
boot.initrd.postResumeCommands = lib.mkAfter (
|
||||
lib.strings.concatLines (builtins.map (user: "zfs rollback -r rpool/local/home/${user.name}@blank")
|
||||
normalUsers)
|
||||
);
|
||||
|
||||
# Create persist home directories with proper permissions
|
||||
systemd = {
|
||||
tmpfiles.rules =
|
||||
builtins.map (
|
||||
user: "d /persist/home/${user.name} 700 ${user.name} ${user.name} -"
|
||||
)
|
||||
normalUsers;
|
||||
};
|
||||
atime = "off";
|
||||
relatime = "off";
|
||||
};
|
||||
})
|
||||
}
|
||||
]))
|
||||
]))
|
||||
# (lib.mkIf config.host.impermanence.enable {
|
||||
# boot.initrd.postResumeCommands = lib.mkAfter (
|
||||
# lib.strings.concatLines (builtins.map (user: "zfs rollback -r rpool/local/home/${user.name}@blank")
|
||||
# normalUsers)
|
||||
# );
|
||||
|
||||
# systemd = {
|
||||
# tmpfiles.rules =
|
||||
# builtins.map (
|
||||
# user: "d /persist/home/${user.name} 700 ${user.name} ${user.name} -"
|
||||
# )
|
||||
# normalUsers;
|
||||
# };
|
||||
|
||||
# fileSystems = lib.mkMerge [
|
||||
# (
|
||||
# builtins.listToAttrs (
|
||||
# builtins.map (user:
|
||||
# lib.attrsets.nameValuePair "/persist/home/${user.name}" {
|
||||
# neededForBoot = true;
|
||||
# })
|
||||
# normalUsers
|
||||
# )
|
||||
# )
|
||||
# (
|
||||
# builtins.listToAttrs (
|
||||
# builtins.map (user:
|
||||
# lib.attrsets.nameValuePair "/home/${user.name}" {
|
||||
# neededForBoot = true;
|
||||
# })
|
||||
# normalUsers
|
||||
# )
|
||||
# )
|
||||
# ];
|
||||
|
||||
# host.storage.pool.extraDatasets = lib.mkMerge (
|
||||
# (
|
||||
# builtins.map (user: {
|
||||
# "local/home/${user.name}" = {
|
||||
# type = "zfs_fs";
|
||||
# mountpoint = "/home/${user.name}";
|
||||
# options = {
|
||||
# canmount = "on";
|
||||
# };
|
||||
# postCreateHook = ''
|
||||
# zfs snapshot rpool/local/home/${user.name}@blank
|
||||
# '';
|
||||
# };
|
||||
# "persist/home/${user.name}" = {
|
||||
# type = "zfs_fs";
|
||||
# mountpoint = "/persist/home/${user.name}";
|
||||
# };
|
||||
# })
|
||||
# normalUsers
|
||||
# )
|
||||
# );
|
||||
# })
|
||||
];
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue