5 ms·
Yes, although later I learned I could do it in a one-liner. Here nixconfig is a folder with all my nix files: tar -czf - nixconfig | ssh 192.168.1.1 \ 't
by euroclydon 4y ago
Yes, although later I learned I could do it in a one-liner. Here nixconfig is a folder with all my nix files:
tar -czf - nixconfig | ssh 192.168.1.1 \
'tar -zxf - && sudo cp -r ./nixconfig/* /etc/nixos/ && sudo nixos-rebuild --show-trace '"${rebuild_flag} ${name_flag}"
- yencabulator 4y agoIf you're ok with building locally and not on the target host, this is simpler: nixos-rebuild --flake .#foo --target-host root@foo --build-host localhost switch
- VTimofeenko 4y agoDeploy-rs is a great alternative. It works as wrapper on top of flakes, local (optionally, cross-) building and copying closures to target machine with activation: https://github.com/serokell/deploy-rs https://github.com/serokell/deploy-rs
- yencabulator 4y agoThese days, that's all included in nixos-rebuild itself, not much need for wrappers anymore. I migrated from Colmena to just nixos-rebuild.
- VTimofeenko 4y agoHuh, I guess I was woefully behind on changes to nixos-rebuild. Thanks for the pointer, I will check it out
- yencabulator 4y agoOne thing nixos-rebuild doesn't get you is a secrets transmission mechanism. I've been dabbling to build something independent of NixOS/Nix that would still do that neatly...
- VTimofeenko 4y agoMay I suggest agenix? It dovetails into my deploy-rs flake setup very nicely and I can track the encrypted secrets in the flake repo. I keep the "master" key encrypted in pass passing it in a zsh's "=" subshell to agenix.