Skip to content
Snippets Groups Projects
grid.nix 3.85 KiB
Newer Older
  • Learn to ignore specific revisions
  • # See morph/grid/local/grid.nix for additional commentary.
    let lib = import ../../lib;
    in lib.make-grid {
    
          sshUsers = import ./secrets/users.nix;
    
    Florian Sesser's avatar
    Florian Sesser committed
          # Get absolute vpn key directory path, as a string:
          monitoringvpnKeyDir = toString ./. + "/${cfg.monitoringvpnKeyDir}";
    
    
          # TBD: derive these automatically:
          hostsMap = {
            "172.23.23.1"  = [ "monitoring" "monitoring.monitoringvpn" ];
    
            "172.23.23.11" = [   "payments"   "payments.monitoringvpn" ];
    
            "172.23.23.21" = [ "storage001" "storage001.monitoringvpn" ];
            "172.23.23.22" = [ "storage002" "storage002.monitoringvpn" ];
            "172.23.23.23" = [ "storage003" "storage003.monitoringvpn" ];
            "172.23.23.24" = [ "storage004" "storage004.monitoringvpn" ];
            "172.23.23.25" = [ "storage005" "storage005.monitoringvpn" ];
          };
          vpnClientIPs = [
            "172.23.23.11"
            "172.23.23.21"
            "172.23.23.22"
            "172.23.23.23"
            "172.23.23.24"
            "172.23.23.25"
          ];
          nodeExporterTargets = [
            "monitoring"
            "payments"
            "storage001"
            "storage002"
            "storage003"
            "storage004"
            "storage005"
          ];
    
    
        # Here are the hosts that are in this morph network.  This is sort of like
        # a server manifest.  We try to keep as many of the specific details as
        # possible out of *this* file so that this file only grows as server count
        # grows.  If it grows too much, we can load servers by listing contents of
        # a directory or reading from another JSON file or some such.  For now,
        # I'm just manually maintaining these entries.
        #
        # The name on the left of the `=` is mostly irrelevant but it does provide
        # a default hostname for the server if the configuration on the right side
        # doesn't specify one.
        #
        # The names must be unique!
    
        "payments.privatestorage.io" = rec {
          imports = [
            lib.issuer
            lib.hardware-aws
            (lib.customize-issuer cfg sshUsers monitoringvpnKeyDir "172.23.23.11" "19.03")
          ];
        };
    
        "storage001" = lib.make-storage (cfg // {
    
            cfg = import ./storage001-config.nix;
    
            hardware = ./storage001-hardware.nix;
    
            stateVersion = "19.09";
    
            monitoringvpnIPv4 = "172.23.23.21";
    
        "storage002" = lib.make-storage (cfg // {
    
            cfg = import ./storage002-config.nix;
    
            hardware = ./storage002-hardware.nix;
    
            stateVersion = "19.09";
    
            monitoringvpnIPv4 = "172.23.23.22";
    
        "storage003" = lib.make-storage (cfg // {
    
            cfg = import ./storage003-config.nix;
    
            hardware = ./storage003-hardware.nix;
    
            stateVersion = "19.09";
    
            monitoringvpnIPv4 = "172.23.23.23";
    
        "storage004" = lib.make-storage (cfg // {
    
            cfg = import ./storage004-config.nix;
    
            hardware = ./storage004-hardware.nix;
    
            stateVersion = "19.09";
    
            monitoringvpnIPv4 = "172.23.23.24";
    
        "storage005" = lib.make-storage (cfg // {
    
            cfg = import ./storage005-config.nix;
    
            hardware = ./storage005-hardware.nix;
    
            stateVersion = "19.03";
    
            monitoringvpnIPv4 = "172.23.23.25";
    
        "monitoring" = lib.make-monitoring (cfg // {
    
          publicIPv4 = "monitoring.private.storage";
    
          monitoringvpnIPv4 = "172.23.23.1";
    
          inherit vpnClientIPs;
          inherit hostsMap;
          inherit nodeExporterTargets;
    
          hardware = lib.hardware-aws;
    
          stateVersion = "19.09";
          inherit sshUsers;