Skip to content
Snippets Groups Projects
grid.nix 2.19 KiB
Newer Older
# See morph/grid/local/grid.nix for additional commentary.
let
  pkgs = import <nixpkgs> { };
  rawConfig = pkgs.lib.trivial.importJSON ./config.json;
  config = rawConfig // {
    sshUsers = import ./public-keys/users.nix;
Florian Sesser's avatar
Florian Sesser committed

    # Convert relative paths to absolute so library code can resolve names
    # correctly.
    publicKeyPath = toString ./. + "/${rawConfig.publicKeyPath}";
    privateKeyPath = toString ./. + "/${rawConfig.privateKeyPath}";
Florian Sesser's avatar
Florian Sesser committed

  # Configure deployment management authorization for all systems in the grid.
  deployment = {
    services.private-storage.deployment = {
      authorizedKey = builtins.readFile "${config.publicKeyPath}/deploy_key.pub";
      gridName = "testing";
    };
  };

  payments = {
    imports = [
      (gridlib.customize-issuer (config // {
        monitoringvpnIPv4 = "172.23.23.11";
      }))
      ./testing001-hardware.nix
      (gridlib.customize-storage (config // {
        monitoringvpnIPv4 = "172.23.23.12";
        stateVersion = "19.03";
      }))
      gridlib.monitoring
      gridlib.hardware-aws
Florian Sesser's avatar
Florian Sesser committed
        inherit hostsMap vpnClientIPs nodeExporterTargets paymentExporterTargets;
        inherit (config) domain publicKeyPath privateKeyPath letsEncryptAdminEmail;
        googleOAuthClientID = config.monitoringGoogleOAuthClientID;
        monitoringvpnIPv4 = "172.23.23.1";
        stateVersion = "19.09";
      })
    ];
  };

  # TBD: derive these automatically:
  hostsMap = {
    "172.23.23.1"  = [ "monitoring" "monitoring.monitoringvpn" ];
    "172.23.23.11" = [ "payments"   "payments.monitoringvpn"   ];
    "172.23.23.12" = [ "storage001" "storage001.monitoringvpn" ];
  };
  vpnClientIPs = [ "172.23.23.11" "172.23.23.12" ];
  nodeExporterTargets = [ "monitoring" "payments" "storage001" ];
Florian Sesser's avatar
Florian Sesser committed
  paymentExporterTargets = [ "payments" ];
Florian Sesser's avatar
Florian Sesser committed

in {
  network = {
    description = "PrivateStorage.io Testing Grid";
  inherit payments monitoring storage001;