Avoid host mutation for early cache hints

This commit is contained in:
Timothy J. Aveni
2026-07-02 22:14:08 -07:00
parent f8c9ef03bf
commit d5f5fe75bd
2 changed files with 7 additions and 16 deletions
+7 -9
View File
@@ -26,20 +26,18 @@ the AMI:
```nix ```nix
{ {
quixosEarlyBuildNixConfig = { quixosEarlyBuildNixConfig = {
hosts = { substituters = [ "http://[2600:...]/cache" ];
"2600:..." = [ "nix-cache.internal.example.org" ];
};
substituters = [ "http://nix-cache.internal.example.org/cache" ];
trustedPublicKeys = [ "nix-cache.internal.example.org-1:..." ]; trustedPublicKeys = [ "nix-cache.internal.example.org-1:..." ];
}; };
} }
``` ```
The AMI runner evaluates this output after writing `/etc/nixos/flake.nix`, The AMI runner evaluates this output after writing `/etc/nixos/flake.nix` and
appends the host hints to `/etc/hosts`, and passes the substituters and trusted passes the substituters and trusted public keys through `NIX_CONFIG` only for
public keys through `NIX_CONFIG` only for the first `nixos-rebuild switch`. the first `nixos-rebuild switch`. It does not mutate `/etc/hosts`; first-boot
The target NixOS configuration should still declare the same cache in substituters that need private addressing should use a direct address URL. The
`nix.settings` for all later rebuilds. target NixOS configuration should still declare the normal hostname-based cache
in `nix.settings` and `networking.hosts` for all later rebuilds.
## Publish ## Publish
-7
View File
@@ -110,13 +110,6 @@ write_config() {
if nix --extra-experimental-features 'nix-command flakes' \ if nix --extra-experimental-features 'nix-command flakes' \
eval --json /etc/nixos#quixosEarlyBuildNixConfig \ eval --json /etc/nixos#quixosEarlyBuildNixConfig \
> "$early_build_config" 2> "$early_build_error"; then > "$early_build_config" 2> "$early_build_error"; then
jq -r '(.hosts // {}) | to_entries[] | select(.key != "" and (.value | length > 0)) | [.key, (.value | join(" "))] | @tsv' "$early_build_config" |
while IFS="$(printf '\t')" read -r address names; do
if [ -n "$address" ] && [ -n "$names" ]; then
printf '%s %s # quixos early build nix cache\n' "$address" "$names" >> /etc/hosts
fi
done
substituters="$(jq -r '(.substituters // []) | join(" ")' "$early_build_config")" substituters="$(jq -r '(.substituters // []) | join(" ")' "$early_build_config")"
trusted_public_keys="$(jq -r '(.trustedPublicKeys // []) | join(" ")' "$early_build_config")" trusted_public_keys="$(jq -r '(.trustedPublicKeys // []) | join(" ")' "$early_build_config")"
if [ -n "$substituters" ]; then if [ -n "$substituters" ]; then