This commit is contained in:
2025-08-13 12:26:29 +02:00
parent c33d90fa3f
commit adaa7b29d2

609
flake.nix
View File

@@ -1,333 +1,364 @@
{ {
description = "Workshop VM with Participant Containers + USB ISO"; description = "Workshop VM with Participant Containers + USB ISO";
inputs = { inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.05"; nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.05";
nixos-generators = { nixos-generators = {
url = "github:nix-community/nixos-generators"; url = "github:nix-community/nixos-generators";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
}; };
outputs = { self, nixpkgs, nixos-generators }: outputs = { self, nixpkgs, nixos-generators }:
let let
system = "x86_64-linux"; system = "x86_64-linux";
pkgs = nixpkgs.legacyPackages.${system}; pkgs = nixpkgs.legacyPackages.${system};
participantNames = [ "hopper" "curie" ]; participantNames = [ "hopper" "curie" ];
fullParticipantNames = [ fullParticipantNames = [
"hopper" "curie" "lovelace" "noether" "hamilton" "hopper"
"franklin" "johnson" "clarke" "goldberg" "liskov" "curie"
"wing" "rosen" "shaw" "karp" "rich" "lovelace"
]; "noether"
in "hamilton"
{ "franklin"
packages.${system} = { "johnson"
local-vm = self.nixosConfigurations.workshop-vm.config.system.build.vm; "clarke"
"goldberg"
"liskov"
"wing"
"rosen"
"shaw"
"karp"
"rich"
];
in
{
packages.${system} = {
local-vm = self.nixosConfigurations.workshop-vm.config.system.build.vm;
live-iso = nixos-generators.nixosGenerate { live-iso = nixos-generators.nixosGenerate {
inherit system; inherit system;
format = "iso"; format = "iso";
modules = [ modules = [
({ pkgs, ... }: { ({ pkgs, ... }: {
system.stateVersion = "25.05"; system.stateVersion = "25.05";
isoImage.makeEfiBootable = true; isoImage.makeEfiBootable = true;
isoImage.makeUsbBootable = true; isoImage.makeUsbBootable = true;
networking.wireless.enable = true; networking.wireless.enable = true;
networking.networkmanager.enable = true; networking.networkmanager.enable = true;
networking.hostName = "workshop-live"; networking.hostName = "workshop-live";
services.getty.autologinUser = "workshop"; services.getty.autologinUser = "workshop";
users.users.workshop = { users.users.workshop = {
isNormalUser = true; isNormalUser = true;
shell = pkgs.zsh; shell = pkgs.zsh;
extraGroups = [ "networkmanager" "wheel" ]; extraGroups = [ "networkmanager" "wheel" ];
password = ""; password = "";
}; };
security.sudo.wheelNeedsPassword = false; security.sudo.wheelNeedsPassword = false;
environment.systemPackages = with pkgs; [ environment.systemPackages = with pkgs; [
openssh curl git networkmanager firefox xterm openssh
]; curl
git
networkmanager
firefox
xterm
];
programs.zsh = { programs.zsh = {
enable = true; enable = true;
interactiveShellInit = '' interactiveShellInit = ''
echo "CODE CRISPIES Workshop Environment" echo "CODE CRISPIES Workshop Environment"
echo "Available servers:" echo "Available servers:"
${builtins.concatStringsSep "\n" (map (name: ${builtins.concatStringsSep "\n" (map (name:
"echo \" - ${name}.codecrispi.es\"" "echo \" - ${name}.codecrispi.es\""
) fullParticipantNames)} ) fullParticipantNames)}
echo "" echo ""
echo "Commands: connect <name> | recipes | help" echo "Commands: connect <name> | recipes | help"
connect() { connect() {
[ -z "$1" ] && { echo "Usage: connect <name>"; return 1; } [ -z "$1" ] && { echo "Usage: connect <name>"; return 1; }
echo "Connecting to $1.codecrispi.es..." echo "Connecting to $1.codecrispi.es..."
ssh -o StrictHostKeyChecking=no workshop@$1.codecrispi.es ssh -o StrictHostKeyChecking=no workshop@$1.codecrispi.es
} }
recipes() { recipes() {
echo "Available Co-op Cloud Recipes:" echo "Available Co-op Cloud Recipes:"
echo "" echo ""
echo "Content Management:" echo "Content Management:"
echo " wordpress ghost hedgedoc dokuwiki mediawiki" echo " wordpress ghost hedgedoc dokuwiki mediawiki"
echo "" echo ""
echo "File & Collaboration:" echo "File & Collaboration:"
echo " nextcloud seafile collabora onlyoffice" echo " nextcloud seafile collabora onlyoffice"
echo "" echo ""
echo "Communication:" echo "Communication:"
echo " jitsi-meet matrix-synapse rocketchat mattermost" echo " jitsi-meet matrix-synapse rocketchat mattermost"
echo "" echo ""
echo "E-commerce & Business:" echo "E-commerce & Business:"
echo " prestashop invoiceninja kimai pretix" echo " prestashop invoiceninja kimai pretix"
echo "" echo ""
echo "Development & Tools:" echo "Development & Tools:"
echo " gitea drone n8n gitlab jupyter-lab" echo " gitea drone n8n gitlab jupyter-lab"
echo "" echo ""
echo "Analytics & Monitoring:" echo "Analytics & Monitoring:"
echo " plausible matomo uptime-kuma grafana" echo " plausible matomo uptime-kuma grafana"
echo "" echo ""
echo "Media & Social:" echo "Media & Social:"
echo " peertube funkwhale mastodon pixelfed jellyfin" echo " peertube funkwhale mastodon pixelfed jellyfin"
echo "" echo ""
echo "Deploy: abra app new <recipe> -S --domain=myapp.<name>.codecrispi.es" echo "Deploy: abra app new <recipe> -S --domain=myapp.<name>.codecrispi.es"
echo "Browse all: https://recipes.coopcloud.tech" echo "Browse all: https://recipes.coopcloud.tech"
} }
help() { help() {
echo "CODE CRISPIES Workshop Commands:" echo "CODE CRISPIES Workshop Commands:"
echo "" echo ""
echo "connect <name> - SSH to your assigned server" echo "connect <name> - SSH to your assigned server"
echo "recipes - Show available app recipes" echo "recipes - Show available app recipes"
echo "sudo nmcli dev wifi connect SSID password PASSWORD" echo "sudo nmcli dev wifi connect SSID password PASSWORD"
echo "" echo ""
echo "Examples:" echo "Examples:"
echo " connect hopper" echo " connect hopper"
echo " sudo nmcli dev wifi connect CODE_CRISPIES_GUEST password workshop2024" echo " sudo nmcli dev wifi connect CODE_CRISPIES_GUEST password workshop2024"
} }
export -f connect recipes help export -f connect recipes help
''; '';
}; };
services.xserver = { services.xserver = {
enable = true; enable = true;
desktopManager.xfce.enable = true; desktopManager.xfce.enable = true;
displayManager = { displayManager = {
lightdm.enable = true; lightdm.enable = true;
autoLogin.enable = true; autoLogin.enable = true;
autoLogin.user = "workshop"; autoLogin.user = "workshop";
}; };
}; };
systemd.user.services.workshop-welcome = { systemd.user.services.workshop-welcome = {
wantedBy = [ "graphical-session.target" ]; wantedBy = [ "graphical-session.target" ];
after = [ "graphical-session.target" ]; after = [ "graphical-session.target" ];
script = "${pkgs.xterm}/bin/xterm -title 'CODE CRISPIES Workshop' -e 'zsh' &"; script = "${pkgs.xterm}/bin/xterm -title 'CODE CRISPIES Workshop' -e 'zsh' &";
serviceConfig.Type = "forking"; serviceConfig.Type = "forking";
}; };
}) })
]; ];
}; };
}; };
devShells.${system}.default = pkgs.mkShell { devShells.${system}.default = pkgs.mkShell {
packages = with pkgs; [ packages = with pkgs; [
markdownlint-cli markdownlint-cli
jq jq
nixpkgs-fmt nixpkgs-fmt
]; ];
}; };
nixosConfigurations.workshop-vm = nixpkgs.lib.nixosSystem { nixosConfigurations.workshop-vm = nixpkgs.lib.nixosSystem {
inherit system; inherit system;
modules = [ modules = [
({ config, pkgs, ... }: { ({ config, pkgs, ... }: {
system.stateVersion = "25.05"; system.stateVersion = "25.05";
boot.loader.grub.enable = false; boot.loader.grub.enable = false;
boot.loader.generic-extlinux-compatible.enable = true; boot.loader.generic-extlinux-compatible.enable = true;
boot.kernel.sysctl."net.ipv4.ip_forward" = 1; boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
users.users.workshop = { users.users.workshop = {
isNormalUser = true; isNormalUser = true;
extraGroups = [ "wheel" ]; extraGroups = [ "wheel" ];
password = ""; password = "";
shell = pkgs.bash; shell = pkgs.bash;
}; };
security.pam.services.login.allowNullPassword = true; security.pam.services.login.allowNullPassword = true;
security.sudo.wheelNeedsPassword = false; security.sudo.wheelNeedsPassword = false;
services.xserver = { services.xserver = {
enable = true; enable = true;
desktopManager.xfce.enable = true; desktopManager.xfce.enable = true;
displayManager.lightdm.enable = true; displayManager.lightdm.enable = true;
}; };
services.displayManager = { services.displayManager = {
autoLogin.enable = true; autoLogin.enable = true;
autoLogin.user = "workshop"; autoLogin.user = "workshop";
}; };
services.xserver.displayManager.sessionCommands = '' services.xserver.displayManager.sessionCommands = ''
${pkgs.xfce.xfce4-terminal}/bin/xfce4-terminal --title="Workshop Terminal" \ ${pkgs.xfce.xfce4-terminal}/bin/xfce4-terminal --title="Workshop Terminal" \
--command="bash -c ' --command="bash -c '
echo \"Workshop VM Ready!\"; echo \"Workshop VM Ready!\";
echo \"\"; echo \"\";
echo \"SSH into containers:\"; echo \"SSH into containers:\";
echo \" sudo connect hopper # Container login\"; echo \" sudo connect hopper # Container login\";
echo \" sudo connect curie # Container login\"; echo \" sudo connect curie # Container login\";
echo \" ssh root@192.168.100.11 # Direct SSH to hopper\"; echo \" ssh root@192.168.100.11 # Direct SSH to hopper\";
echo \" ssh root@192.168.100.12 # Direct SSH to curie\"; echo \" ssh root@192.168.100.12 # Direct SSH to curie\";
echo \"\"; echo \"\";
echo \"Container management:\"; echo \"Container management:\";
echo \" sudo containers # List all containers\"; echo \" sudo containers # List all containers\";
echo \" sudo logs # Show setup logs\"; echo \" sudo logs # Show setup logs\";
echo \"\"; echo \"\";
echo \"Abra is pre-installed in containers!\"; echo \"Abra is pre-installed in containers!\";
echo \"\"; echo \"\";
bash bash
'" & '" &
''; '';
environment.systemPackages = with pkgs; [ environment.systemPackages = with pkgs; [
firefox curl git jq nano tree nixos-container firefox
(pkgs.writeScriptBin "connect" '' curl
#!/bin/bash git
if [ -z "$1" ]; then jq
echo "Usage: connect <container-name>" nano
echo "Available: hopper curie" tree
exit 1 nixos-container
fi (pkgs.writeScriptBin "connect" ''
exec nixos-container root-login "$1" #!/bin/bash
'') if [ -z "$1" ]; then
(pkgs.writeScriptBin "containers" '' echo "Usage: connect <container-name>"
#!/bin/bash echo "Available: hopper curie"
exec nixos-container list exit 1
'') fi
(pkgs.writeScriptBin "logs" '' exec nixos-container root-login "$1"
#!/bin/bash '')
exec journalctl -u container@hopper -u container@curie -f (pkgs.writeScriptBin "containers" ''
'') #!/bin/bash
]; exec nixos-container list
'')
(pkgs.writeScriptBin "logs" ''
#!/bin/bash
exec journalctl -u container@hopper -u container@curie -f
'')
];
networking = { networking = {
hostName = "workshop-vm"; hostName = "workshop-vm";
firewall.enable = false; firewall.enable = false;
nat = { nat = {
enable = true; enable = true;
internalInterfaces = ["ve-+"]; internalInterfaces = [ "ve-+" ];
externalInterface = "eth0"; externalInterface = "eth0";
}; };
}; };
containers = builtins.listToAttrs (builtins.genList (i: containers = builtins.listToAttrs (builtins.genList
let (i:
name = builtins.elemAt participantNames i; let
ip = "192.168.100.${toString (11 + i)}"; name = builtins.elemAt participantNames i;
in { ip = "192.168.100.${toString (11 + i)}";
inherit name; in
value = { {
autoStart = true; inherit name;
privateNetwork = true; value = {
hostAddress = "192.168.100.1"; autoStart = true;
localAddress = ip; privateNetwork = true;
hostAddress = "192.168.100.1";
localAddress = ip;
config = { config = {
system.stateVersion = "25.05"; system.stateVersion = "25.05";
users.users.root.password = "root"; users.users.root.password = "root";
users.users.workshop = { users.users.workshop = {
isNormalUser = true; isNormalUser = true;
password = "workshop"; password = "workshop";
extraGroups = [ "wheel" "docker" ]; extraGroups = [ "wheel" "docker" ];
}; };
services.openssh = { services.openssh = {
enable = true; enable = true;
settings = { settings = {
PasswordAuthentication = true; PasswordAuthentication = true;
PermitRootLogin = "yes"; PermitRootLogin = "yes";
}; };
}; };
networking = { networking = {
hostName = name; hostName = name;
nameservers = [ "8.8.8.8" ]; nameservers = [ "8.8.8.8" ];
firewall.enable = false; firewall.enable = false;
}; };
security.sudo.wheelNeedsPassword = false; security.sudo.wheelNeedsPassword = false;
virtualisation.docker.enable = true; virtualisation.docker.enable = true;
environment.systemPackages = with pkgs; [ environment.systemPackages = with pkgs; [
docker curl git wget jq bash docker
]; curl
git
wget
jq
bash
];
systemd.services.workshop-setup = { systemd.services.workshop-setup = {
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];
after = [ "network-online.target" "docker.service" ]; after = [ "network-online.target" "docker.service" ];
wants = [ "network-online.target" ]; wants = [ "network-online.target" ];
script = '' script = ''
echo "Setting up ${name} container..." echo "Setting up ${name} container..."
for i in {1..10}; do for i in {1..10}; do
if ${pkgs.curl}/bin/curl -s --max-time 5 google.com >/dev/null 2>&1; then if ${pkgs.curl}/bin/curl -s --max-time 5 google.com >/dev/null 2>&1; then
echo "Network ready" echo "Network ready"
break break
fi fi
echo "Waiting for network... ($i/10)" echo "Waiting for network... ($i/10)"
sleep 2 sleep 2
done done
${pkgs.docker}/bin/docker swarm init --advertise-addr ${ip} || true ${pkgs.docker}/bin/docker swarm init --advertise-addr ${ip} || true
export HOME=/root export HOME=/root
if [ ! -f /root/.local/bin/abra ]; then if [ ! -f /root/.local/bin/abra ]; then
echo "Installing abra..." echo "Installing abra..."
${pkgs.curl}/bin/curl -fsSL https://install.abra.coopcloud.tech | ${pkgs.bash}/bin/bash ${pkgs.curl}/bin/curl -fsSL https://install.abra.coopcloud.tech | ${pkgs.bash}/bin/bash
echo "Abra installed" echo "Abra installed"
fi fi
if ! grep -q "/.local/bin" /root/.bashrc 2>/dev/null; then if ! grep -q "/.local/bin" /root/.bashrc 2>/dev/null; then
echo 'export PATH="$HOME/.local/bin:$PATH"' >> /root/.bashrc echo 'export PATH="$HOME/.local/bin:$PATH"' >> /root/.bashrc
fi fi
if [ -f /root/.local/bin/abra ]; then if [ -f /root/.local/bin/abra ]; then
ln -sf /root/.local/bin/abra /usr/local/bin/abra 2>/dev/null || true ln -sf /root/.local/bin/abra /usr/local/bin/abra 2>/dev/null || true
fi fi
if [ -f /root/.local/bin/abra ]; then if [ -f /root/.local/bin/abra ]; then
export PATH="/root/.local/bin:$PATH" export PATH="/root/.local/bin:$PATH"
/root/.local/bin/abra server add ${name}.local 2>/dev/null || true /root/.local/bin/abra server add ${name}.local 2>/dev/null || true
fi fi
echo "${name} container ready!" echo "${name} container ready!"
echo "SSH: ssh root@${ip} (password: root)" echo "SSH: ssh root@${ip} (password: root)"
echo "Abra: Available via 'abra' command" echo "Abra: Available via 'abra' command"
''; '';
serviceConfig = { serviceConfig = {
Type = "oneshot"; Type = "oneshot";
RemainAfterExit = true; RemainAfterExit = true;
StandardOutput = "journal"; StandardOutput = "journal";
StandardError = "journal"; StandardError = "journal";
}; };
}; };
environment.sessionVariables = { environment.sessionVariables = {
PATH = [ "/root/.local/bin" ]; PATH = [ "/root/.local/bin" ];
}; };
}; };
}; };
} }
) (builtins.length participantNames)); )
}) (builtins.length participantNames));
]; })
}; ];
}; };
};
} }