Skip to content
Snippets Groups Projects
grid.nix 2.58 KiB
Newer Older
# See morph/grid/local/grid.nix for additional commentary.
let
  pkgs = import <nixpkgs> { };
  grid-config = pkgs.lib.trivial.importJSON ./config.json;
Florian Sesser's avatar
Florian Sesser committed

  # Module with per-grid configuration
  grid-module = {config, ...}: {
      # Allow us to remotely trigger updates to this system.
      ../../../nixos/modules/deployment.nix
      # Give it a good SSH configuration.
      ../../../nixos/modules/ssh.nix
    ];
    services.private-storage.sshUsers = import ./public-keys/users.nix;
    networking.domain = grid-config.domain;
    # Convert relative paths to absolute so library code can resolve names
    # correctly.
    grid = {
      publicKeyPath = toString ./. + "/${grid-config.publicKeyPath}";
      privateKeyPath = toString ./. + "/${grid-config.privateKeyPath}";
    };
    # Configure deployment management authorization for all systems in the grid.
    services.private-storage.deployment = {
      authorizedKey = builtins.readFile "${config.grid.publicKeyPath}/deploy_key.pub";
  payments = {
    imports = [
      (gridlib.customize-issuer (grid-config // {
        monitoringvpnIPv4 = "172.23.23.11";
      }))
      ./testing001-hardware.nix
      (gridlib.customize-storage (grid-config // {
        monitoringvpnIPv4 = "172.23.23.12";
        stateVersion = "19.03";
      }))
      gridlib.monitoring
      gridlib.hardware-aws
Florian Sesser's avatar
Florian Sesser committed
        inherit hostsMap vpnClientIPs nodeExporterTargets paymentExporterTargets;
        inherit (grid-config) letsEncryptAdminEmail;
        googleOAuthClientID = grid-config.monitoringGoogleOAuthClientID;
        enableSlackAlert = true;
        monitoringvpnIPv4 = "172.23.23.1";
        stateVersion = "19.09";
      })
    ];
  };

  # TBD: derive these automatically:
  hostsMap = {
    "172.23.23.1"  = [ "monitoring" "monitoring.monitoringvpn" ];
    "172.23.23.11" = [ "payments"   "payments.monitoringvpn"   ];
    "172.23.23.12" = [ "storage001" "storage001.monitoringvpn" ];
  };
  vpnClientIPs = [ "172.23.23.11" "172.23.23.12" ];
  nodeExporterTargets = [ "monitoring" "payments" "storage001" ];
Florian Sesser's avatar
Florian Sesser committed
  paymentExporterTargets = [ "payments" ];
Florian Sesser's avatar
Florian Sesser committed

in {
  network = {
    description = "PrivateStorage.io Testing Grid";
    inherit (gridlib) pkgs;
  inherit payments monitoring storage001;