NixOSConfig/lib/config/custom-build-vm.nix

180 lines
5.6 KiB
Nix
Raw Normal View History

2024-05-01 00:07:12 +00:00
{ config, lib, options, pkgs, ... }:
let
packageName = "custom-nixos-vm";
2024-05-01 02:51:49 +00:00
# Determine `system.build` configuration without this file's influence
2024-05-01 02:42:31 +00:00
mergedBuildOption =
2024-05-01 00:07:12 +00:00
with options.system;
lib.mergeDefinitions
build.loc
build.type
(lib.lists.forEach
(
builtins.filter
(item:
!(lib.path.hasPrefix ./. (/. + item.file)))
build.definitionsWithLocations)
(item: { inherit (item) file value; }));
2024-05-01 02:51:49 +00:00
# Get vanilla `config.system.build.vm`
2024-05-01 02:42:31 +00:00
vanillaVM = mergedBuildOption.mergedValue.vm;
2024-05-01 00:07:12 +00:00
in {
2024-04-30 23:38:03 +00:00
options =
let
2024-05-01 02:51:49 +00:00
# Add new options to `config.virtualisation.vmVariant` and `config.virtualisation.vmVariantWithBootLoader`
2024-04-30 23:38:03 +00:00
vmVariantOptions = {
virtualisation = {
runAsRoot = lib.mkOption {
type = lib.types.bool;
default = false;
};
2024-04-30 22:50:02 +00:00
2024-04-30 23:38:03 +00:00
sharedHostKeys = lib.mkOption {
type = lib.types.bool;
default = false;
};
virt-viewer = lib.mkOption {
type = lib.types.bool;
default = false;
};
2024-05-01 01:07:42 +00:00
qemu = {
runInBackground = lib.mkOption {
type = lib.types.bool;
default = false;
};
spice = {
enable = lib.mkEnableOption "spice";
bindAddress = lib.mkOption {
type = lib.types.str;
default = "127.0.0.1";
};
port = lib.mkOption {
type = lib.types.port;
default = 5900;
};
};
2024-04-30 23:38:03 +00:00
};
2024-04-30 22:50:02 +00:00
};
};
2024-04-30 23:38:03 +00:00
in {
virtualisation = {
vmVariant = vmVariantOptions;
vmVariantWithBootLoader = vmVariantOptions;
};
2024-04-30 22:27:07 +00:00
};
2024-04-30 22:27:07 +00:00
config = {
2024-04-30 22:40:00 +00:00
virtualisation =
let
extendVMConfig =
vmVariant: {
2024-05-01 02:51:49 +00:00
# Prevent GRUB2 errors in `nixos-rebuild build-vm-with-bootloader`
boot.loader.efi.efiSysMountPoint = lib.mkVMOverride "/boot";
2024-04-30 23:38:03 +00:00
virtualisation = {
2024-05-01 02:51:49 +00:00
# Enable root permissions to get access to the `/etc/ssh` directory
2024-04-30 23:38:03 +00:00
runAsRoot = lib.mkIf vmVariant.virtualisation.sharedHostKeys true;
2024-05-01 02:51:49 +00:00
# Enable spice and run QEMU in background to let `remote-viewer` take over
qemu = {
spice.enable = lib.mkIf vmVariant.virtualisation.virt-viewer true;
runInBackground = lib.mkIf vmVariant.virtualisation.virt-viewer true;
options =
with {
inherit (vmVariant.virtualisation.qemu) spice;
};
(
lib.optional (spice.enable)
("-spice " + (
lib.concatStringsSep "," [
"addr=${lib.escapeShellArg spice.bindAddress}"
"port=${toString spice.port}"
"disable-ticketing=on"
])));
};
2024-05-01 01:07:42 +00:00
2024-05-01 02:51:49 +00:00
# Map SSH keys into the vm if necessary
2024-04-30 23:38:03 +00:00
sharedDirectories = lib.optionalAttrs (vmVariant.virtualisation.sharedHostKeys) {
hostKeys =
let
path = "/etc/ssh";
in {
source = path;
target = path;
};
};
};
};
virtualisation = config.virtualisation;
2024-04-30 22:40:00 +00:00
in {
vmVariant = extendVMConfig virtualisation.vmVariant;
vmVariantWithBootLoader = extendVMConfig virtualisation.vmVariantWithBootLoader;
2024-04-30 22:40:00 +00:00
};
2024-04-30 22:27:07 +00:00
system.build =
{
2024-05-01 00:55:42 +00:00
vm = lib.mkForce (
(
vm:
if (vm.name == packageName)
then
vm
else
let
originalCommand = "${vm}/bin/run-${config.system.name}-vm";
2024-05-01 00:55:42 +00:00
2024-05-01 02:51:49 +00:00
# Have the command run in background if requested
2024-05-01 00:55:42 +00:00
suffix =
lib.concatStringsSep " " (
lib.optional config.virtualisation.qemu.runInBackground "&");
2024-05-01 00:55:42 +00:00
shellApp = pkgs.writeShellApplication {
2024-05-01 00:55:42 +00:00
name = "run-${config.system.name}-vm";
text = lib.strings.concatLines (
[
"${originalCommand} ${suffix}"
] ++ (
let
2024-05-01 02:51:49 +00:00
# Run `remote-viewer` as normal user to limit access
viewerPrefix = "sudo -Eu\"#$SUDO_UID\" ";
2024-05-01 02:51:49 +00:00
spice = config.virtualisation.qemu.spice;
in
(
lib.optionals
config.virtualisation.virt-viewer
[
"${viewerPrefix}${pkgs.virt-viewer}/bin/remote-viewer spice://${lib.escapeShellArg spice.bindAddress}:${toString spice.port}"
2024-05-01 02:51:49 +00:00
# Kill QEMU after `remote-viewer` finished running
"kill %1"
])));
2024-05-01 00:55:42 +00:00
};
2024-05-01 02:51:49 +00:00
# Run VM as root if requested
wrapped =
if !config.virtualisation.runAsRoot
then
shellApp
else
pkgs.writeShellApplication {
name = shellApp.name;
text = ''
sudo -E ${shellApp}/bin/${shellApp.name}
'';
};
2024-05-01 00:55:42 +00:00
in
pkgs.symlinkJoin {
name = packageName;
paths = [ wrapped ];
})
vanillaVM);
2024-04-30 22:27:07 +00:00
};
};
}