git.delta.rocks / fleet / refs/commits / 3ddf3ff6da5e

difftreelog

fix explicit systemctl

kzonlluxYaroslav Bolyukin2026-04-22parent: #70a291c.patch.diff

4 files changed

addeddocs/index.adocdiffbeforeafterboth
--- /dev/null
+++ b/docs/index.adoc
@@ -0,0 +1,78 @@
+
+= Fleet
+:slug: index
+:order: 0
+
+An NixOS cluster deployment tool.
+
+== Advantages over existing configuration systems (NixOps/Morph)
+
+- Modules can configure multiple hosts at once (i.e. for wireguard/kubernetes installation)
+- Secrets can be securely stored in Git (no one except target hosts can decrypt them), automatically regenerated, reencrypted, etc.
+- Automatic rollback on deployment failure, which will work as long as system is passing initrd stage
+
+== Flake example
+
+[source,nix]
+----
+{
+  description = "My cluster configuration";
+  inputs = {
+    nixpkgs.url = "github:nixos/nixpkgs";
+    fleet = {
+      url = "github:CertainLach/fleet";
+      inputs.nixpkgs.follows = "nixpkgs";
+    };
+    flake-parts.url = "github:hercules-ci/flake-parts";
+  };
+  outputs = inputs:
+    inputs.flake-parts.lib.mkFlake {inherit inputs;} {
+      imports = [inputs.fleet.flakeModules.default];
+
+      fleetConfigurations.default = {
+        nixos = {
+          # Shared NixOS configuration for all hosts
+        };
+
+        imports = [
+          ./wireguard
+        ];
+
+        hosts.controlplane-1 = {
+          system = "x86_64-linux";
+          nixos = {
+            imports = [
+              ./controlplane-1/hardware-configuration.nix
+              ./controlplane-1/configuration.nix
+            ];
+          };
+        };
+      };
+    };
+}
+----
+
+== Secret generator example
+
+[source,nix]
+----
+{config, ...}: {
+  secrets = {
+    gitlab-initial-root = {
+      generator = {mkPassword}: mkPassword {};
+      owner = "gitlab";
+      group = "gitlab";
+    };
+    gitlab-secret = {
+      generator = {mkPassword}: mkPassword {};
+      owner = "gitlab";
+      group = "gitlab";
+    };
+  };
+  services.gitlab = {
+    enable = true;
+    initialRootPasswordFile = config.secrets.gitlab-initial-root.secretPath;
+    secrets.secretFile = config.secrets.gitlab-secret.secretPath;
+  };
+}
+----
addeddocs/migration.adocdiffbeforeafterboth
after · docs/migration.adoc

fleet.nix <unset> ⇒ 0.1.0

Add version field

Set it to 0.1.0; This field specifies which version of fleet do you use for cluster management, breaking changes will also break this value to make sure you read this guide.

Move every secret part

Before it was only public and private, now it can be any number of parts.

In your fleet.nix file, look at every record like this:

gitlab-initial-root = {
	createdAt = "2024-03-01T15:54:32.983358495Z";
	public = "example";
	secret = "vp%d6wO#0#D2.../dgCA+v4Gf:YG";
};

And modify it as following:

gitlab-initial-root = {
	createdAt = "2024-03-01T15:54:32.983358495Z";
	public.raw = "<PLAINTEXT>example";
	secret.raw = ''
		<ENCRYPTED><Z85-ENCODED>
		vp%d6wO#0#D2.../dgCA+v4Gf:YG
	'';
};

Default encoding was also changed from Z85 to base64. This conversion will be done by fleet automatically.

Update references to secrets in fleet/nixos configurations

Instead of config.secrets.secret-name.secretPath use config.secrets.secret-name.secret.path, instead of config.secrets.secret-name.stableSecretPath use config.secrets.secret-name.secret.stablePath, instead of config.secrets.secret-name.public use config.secrets.secret-name.public.data.

modifieddocs/secrets.adocdiffbeforeafterboth
--- a/docs/secrets.adoc
+++ b/docs/secrets.adoc
@@ -1,4 +1,6 @@
 = Fleet Secrets Management System
+:slug: secrets
+:order: 1
 
 == Overview
 
modifiedmodules/nixos/online.nixdiffbeforeafterboth
--- a/modules/nixos/online.nix
+++ b/modules/nixos/online.nix
@@ -17,6 +17,7 @@
     ;
   inherit (lib.attrsets) mapAttrs;
   inherit (lib.trivial) isString;
+  inherit (lib.meta) getExe';
 in
 {
   options.system.onlineActivationScripts = mkOption {
@@ -81,7 +82,7 @@
         text = ''
           if [ ! -z ''${FLEET_ONLINE_ACTIVATION+x} ]; then
             1>&2 echo "online activation; hello, fleet!"
-            systemctl start online-activation.target
+            ${getExe' config.systemd.package "systemctl"} start online-activation.target
           fi
         '';
         supportsDryActivation = true;