build: replace bootstrap script with docker wrapper

This commit is contained in:
Tibo De Peuter 2026-08-18 20:14:56 +02:00
parent e23006d701
commit a1e34e01eb
3 changed files with 42 additions and 112 deletions

View file

@ -1,32 +1,22 @@
# NixOS GitOps Bootstrap Guide
This repository is designed to be fully automated once bootstrapped, but if you are adapting this codebase for **your own infrastructure**, you must modify several deployment-specific variables before running the bootstrap script on a fresh Proxmox host.
This repository is designed to be fully automated once bootstrapped. We separate concerns into two layers:
1. **Host Layer**: Bare-metal hardware setup on Proxmox.
2. **Workload Layer**: VMs and network resources.
## Adapt the Codebase
## 1. Apply the Host Layer
Before bootstrapping your host, fork or clone this repository and make the following changes to match your environment:
Before deploying VMs, you need to prepare the Proxmox host (setup ZFS, disable NIC offloading, etc.).
### Hardware Identifiers
- **Find your NVMe/Disk UUID**: Log into your fresh Proxmox host and run:
1. Clone this repository to your laptop.
2. Run the host-layer apply script using Docker (requires Docker installed):
```bash
ls -l /dev/disk/by-id/
./scripts/apply-host-layer.sh
```
Identify your primary data disk (e.g. `nvme-eui...` or `wwn-0x...`).
- **Update OpenTofu Config**: Open `opentofu/nodes/mikoshi/main.tf` (you may want to rename `mikoshi` to your host's name) and replace the `disk` ID inside the `zpool` resource with your hardware UUID.
3. OpenTofu will prompt you for variables like the target `node_ip`, your `ssh_user`, and the `data_disk_id` (e.g. `nvme-eui...`) to format as ZFS.
### Identity & Access
- **SSH Keys**: The GitOps Control Center needs an SSH key for disaster recovery.
- Update the Cloud-Init SSH key in `opentofu/nodes/mikoshi/main.tf` under the `user_account` block.
- Update the permanent NixOS SSH key in `nixos/users/admin/default.nix`.
- **Secrets (SOPS)**: Replace the placeholder tokens in the Control Center host config (e.g., `nixos/hosts/izanagi/secrets.yaml` if you haven't renamed it) with your actual Proxmox API token and Forgejo token. Encrypt this file with your own `sops` Age key.
## 2. Prepare the Golden Image
### Hostname & Naming Schema
If your Proxmox host or your Control Center has a different name:
- Rename the folders in `opentofu/nodes/` and `nixos/hosts/`.
- Update the `node_name` inside your OpenTofu `main.tf`.
- Update `nixos/flake.nix` to reflect your new host names.
### The Golden Image
Because the GitOps Control Center must be spun up fully configured without human intervention, you need a pre-built NixOS `.qcow2` image.
1. Build the golden image locally (requires Nix/WSL):
```bash
@ -36,25 +26,22 @@ Because the GitOps Control Center must be spun up fully configured without human
3. Create a new VM in Proxmox with **ID 9000**.
4. Import the `.qcow2` as its disk and convert the VM into a **Template**. *(Ensure the template has Cloud-Init configured).*
## Execute the Bootstrap
## 3. Deploy the Workload Layer
Once you have pushed your adapted codebase to your Git server, SSH into your fresh Proxmox node as `root` and run the bootstrap script:
Once the host is prepped and the template exists, you can deploy the base workloads (like the GitOps Control Center).
```bash
curl -fsSL https://git.your-server.com/your-repo/raw/branch/main/scripts/bootstrap.sh | bash
```
### What this script does automatically:
- **Fixes APT Repositories**: Disables enterprise repositories and adds community repositories.
- **Fixes NIC Offloading**: Installs a systemd service to safely disable TSO/GSO/GRO on physical interfaces to prevent network drops.
- **Installs OpenTofu**: Pulls the official binaries.
- **Applies Host State**: Runs `tofu apply` which:
- Formats your specified disk into the `data` ZFS pool.
- Sets laptop lid switch to ignore (if applicable).
- Spins up the GitOps Control Center VM.
1. Change to the workload-layer directory:
```bash
cd opentofu/workload-layer/production
```
2. Initialize and apply:
```bash
tofu init
tofu apply
```
## Post-Bootstrap
Once the bootstrap script completes, the Control Center VM will boot, initialize via Cloud-Init, and automatically start pulling this git repository.
Once the `tofu apply` completes, the Control Center VM will boot, initialize via Cloud-Init, and automatically start pulling this git repository.
From this point on, **you no longer need to log into the Proxmox host.** All future changes to VMs, networks, or applications should be done declaratively via Pull Requests to your repository!
From this point on, **you no longer need to manually run tofu apply.** All future changes to VMs, networks, or applications should be done declaratively via Pull Requests to your repository!