difftreelog
refactor shell abstraction
in: trunk
6 files changed
cmds/fleet/src/better_nix_eval.rsdiffbeforeafterboth--- a/cmds/fleet/src/better_nix_eval.rs
+++ b/cmds/fleet/src/better_nix_eval.rs
@@ -472,7 +472,7 @@
($field:ident $($tt:tt)*) => {{
use $crate::{better_nix_eval::NixExprBuilder, nix_expr_inner};
#[allow(unused_mut, reason = "might be used if indexed")]
- let mut out = NixExprBuilder::field($field);
+ let mut out = NixExprBuilder::field($field.clone());
nix_expr_inner!(@field(out) $($tt)*);
out
}};
cmds/fleet/src/cmds/build_systems.rsdiffbeforeafterboth--- a/cmds/fleet/src/cmds/build_systems.rs
+++ b/cmds/fleet/src/cmds/build_systems.rs
@@ -291,9 +291,11 @@
info!("building");
let action = Action::from(self.subcommand.clone());
let fleet_field = &config.fleet_field;
- let drv = nix_go!(fleet_field.buildSystems(Obj {
- localSystem: { config.local_system.clone() }
- }));
+ let drv = nix_go!(
+ fleet_field.buildSystems(Obj {
+ localSystem: { config.local_system.clone() }
+ })[{ action.build_attr() }][{ host }]
+ );
let outputs = drv.build().await.map_err(|e| {
if action.build_attr() == "sdImage" {
info!("sd-image build failed");
cmds/fleet/src/cmds/secrets/mod.rsdiffbeforeafterboth--- a/cmds/fleet/src/cmds/secrets/mod.rs
+++ b/cmds/fleet/src/cmds/secrets/mod.rs
@@ -1,4 +1,5 @@
use crate::{
+ command::MyCommand,
fleetdata::{FleetSecret, FleetSharedSecret},
host::Config,
nix_go, nix_go_json,
@@ -12,6 +13,7 @@
collections::HashSet,
io::{self, Cursor, Read},
path::PathBuf,
+ sync::Arc,
};
use tabled::{Table, Tabled};
use tokio::fs::read_to_string;
@@ -97,8 +99,9 @@
Secret::InvokeGenerator => {
let config_field = &config.config_unchecked_field;
- let generate_impure =
- nix_go!(config_field.sharedSecrets["kube-apiserver.pem"].generateImpure);
+ let secret =
+ nix_go!(config_field.configUnchecked.sharedSecrets["kube-apiserver.pem"]);
+ let generate_impure = nix_go!(secret.generateImpure);
let on = nix_go!(generate_impure.on);
let call_package = nix_go!(
config_field.buildableSystems(Obj {
@@ -106,13 +109,62 @@
})[on]
.config
.nixpkgs
- .pkgs
+ .resolvedPkgs
.callPackage
);
- let generator = nix_go!(call_package(generate_impure.generator));
- let built = generator.build().await?;
- // .as_json().await?;
- dbg!(&built);
+ let generator = nix_go!(call_package(generate_impure.generator)(Obj {}));
+ let built = &generator.build().await?["out"];
+ let mut nix = MyCommand::new("nix");
+ let on: String = on.as_json().await?;
+ nix.arg("copy")
+ .arg("--substitute-on-destination")
+ .comparg("--to", format!("ssh-ng://{on}"))
+ .arg(built);
+ nix.run_nix().await?;
+
+ let session = config.host(&on).await?;
+
+ let owners: Vec<String> = nix_go_json!(secret.expectedOwners);
+ dbg!(&owners);
+
+ let mut recipients = String::new();
+ for owner in owners {
+ let key = config.key(&owner).await?;
+ recipients.push_str(&format!("-r \"{key}\" "));
+ }
+ recipients.push_str("-e");
+
+ // FIXME: security: created directory might be accessible to other users
+ // This shouldn't be much of a concern, as data is encrypted right after creation, yet
+ // still better to have.
+ let tempdir = session.mktemp_dir().await?;
+
+ let mut gen = session.cmd(built).await?;
+ gen.env("rageArgs", recipients).env("out", &tempdir);
+ gen.run().await?;
+
+ {
+ let marker = session.read_file_text(format!("{tempdir}/marker")).await?;
+ ensure!(marker == "SUCCESS", "generation not succeeded");
+ }
+
+ let public = session
+ .read_file_bin(format!("{tempdir}/public"))
+ .await
+ .ok();
+ let secret = session
+ .read_file_bin(format!("{tempdir}/secret"))
+ .await
+ .ok();
+ if let Some(secret) = &secret {
+ ensure!(
+ age::Decryptor::new(Cursor::new(&secret)).is_ok(),
+ "builder produced non-encrypted value as secret, this is highly insecure"
+ );
+ }
+ dbg!(&secret);
+ // // .as_json().await?;
+ // dbg!(&built);
}
Secret::ForceKeys => {
for host in config.list_hosts().await? {
@@ -249,7 +301,8 @@
if secret.secret.is_empty() {
bail!("no secret {name}");
}
- let data = config.decrypt_on_host(&machine, secret.secret).await?;
+ let host = config.host(&machine).await?;
+ let data = host.decrypt(secret.secret).await?;
if plaintext {
let s = String::from_utf8(data).context("output is not utf8")?;
print!("{s}");
cmds/fleet/src/command.rsdiffbeforeafterboth--- a/cmds/fleet/src/command.rs
+++ b/cmds/fleet/src/command.rs
@@ -1,6 +1,7 @@
use std::{
collections::HashMap,
ffi::OsStr,
+ pin,
process::Stdio,
sync::{Arc, Mutex},
task::Poll,
@@ -10,7 +11,7 @@
use futures::StreamExt;
use itertools::Either;
use once_cell::sync::Lazy;
-use openssh::{OverSsh, Session};
+use openssh::{OverSsh, OwningCommand, Session};
use regex::Regex;
use serde::{de::Visitor, Deserialize};
use tokio::{io::AsyncRead, process::Command, select};
@@ -44,6 +45,15 @@
ssh_session: Option<Arc<Session>>,
}
impl MyCommand {
+ pub fn new_on(cmd: impl AsRef<OsStr>, session: Arc<Session>) -> Self {
+ assert!(!cmd.as_ref().is_empty());
+ Self {
+ command: ostoutf8(cmd),
+ args: vec![],
+ env: vec![],
+ ssh_session: Some(session),
+ }
+ }
pub fn new(cmd: impl AsRef<OsStr>) -> Self {
assert!(!cmd.as_ref().is_empty());
Self {
@@ -66,6 +76,29 @@
out.extend(self.args);
out
}
+
+ /// Translates environment variables into env command execution.
+ /// Required for ssh, as ssh don't allow to send environment variables (at least by default).
+ ///
+ /// FIXME: Insecure, as arguments might be seen by other users on the same machine.
+ /// Figure out some way to transfer environment using stdio?
+ fn translate_env_into_env(self) -> Self {
+ if self.env.is_empty() {
+ return self;
+ }
+ let mut out = Self::new("env");
+ if let Some(session) = self.ssh_session {
+ out = out.ssh_session(session);
+ }
+ for (k, v) in self.env {
+ assert!(!k.contains('='));
+ out.arg(format!("{k}={v}"));
+ }
+ out.arg(self.command);
+ out.args(self.args);
+
+ out
+ }
fn into_string(self) -> String {
let mut out = String::new();
if !self.env.is_empty() {
@@ -98,7 +131,7 @@
}
fn into_command_new(self) -> Result<Either<Command, openssh::OwningCommand<Arc<Session>>>> {
Ok(if let Some(session) = self.ssh_session.clone() {
- let cmd = self.into_command();
+ let cmd = self.translate_env_into_env().into_command();
Either::Right(
cmd.over_ssh(session)
.map_err(|e| anyhow!("ssh error: {e}"))?,
@@ -126,6 +159,11 @@
self.arg(value);
self
}
+ pub fn env(&mut self, name: impl AsRef<str>, value: impl AsRef<str>) -> &mut Self {
+ self.env
+ .push((name.as_ref().to_owned(), value.as_ref().to_owned()));
+ self
+ }
pub fn args<V: AsRef<OsStr>>(&mut self, args: impl IntoIterator<Item = V>) -> &mut Self {
for arg in args.into_iter() {
let arg = arg.as_ref();
@@ -133,9 +171,10 @@
}
self
}
- pub fn sudo(self) -> Self {
+ pub fn sudo(mut self) -> Self {
if std::env::var_os("NO_SUDO").is_some() {
let mut out = Self::new("su");
+ out.ssh_session = self.ssh_session.take();
out.arg("-c").arg(self.into_string());
out
} else {
@@ -144,27 +183,38 @@
out
}
}
- pub fn ssh(self, on: impl AsRef<OsStr>) -> Self {
+ pub fn ssh_session(mut self, on: Arc<Session>) -> Self {
+ self.ssh_session = Some(on);
+ self
+ }
+ pub fn ssh(mut self, on: impl AsRef<OsStr>) -> Self {
let mut out = Self::new("ssh");
+ out.ssh_session = self.ssh_session.take();
out.arg(on).arg("--");
out.arg(self.into_string());
out
}
- pub fn over_ssh(mut self, session: Arc<Session>) -> Self {
- self.ssh_session = Some(session);
- self
- }
pub async fn run(self) -> Result<()> {
let str = self.clone().into_string();
- let cmd = self.into_command();
- run_nix_inner(str, cmd, &mut PlainHandler).await?;
+ let cmd = self.into_command_new()?;
+ match cmd {
+ Either::Left(cmd) => run_nix_inner(str, cmd, &mut PlainHandler).await?,
+ Either::Right(cmd) => run_nix_inner_ssh(str, cmd, &mut PlainHandler).await?,
+ };
Ok(())
}
pub async fn run_string(self) -> Result<String> {
+ let bytes = self.run_bytes().await?;
+ Ok(String::from_utf8(bytes)?)
+ }
+ pub async fn run_bytes(self) -> Result<Vec<u8>> {
let str = self.clone().into_string();
- let cmd = self.into_command();
- let v = run_nix_inner_stdout(str, cmd, &mut PlainHandler).await?;
+ let cmd = self.into_command_new()?;
+ let v = match cmd {
+ Either::Left(cmd) => run_nix_inner_stdout(str, cmd, &mut PlainHandler).await?,
+ Either::Right(cmd) => run_nix_inner_stdout_ssh(str, cmd, &mut PlainHandler).await?,
+ };
Ok(v)
}
@@ -172,7 +222,8 @@
let str = self.clone().into_string();
let mut cmd = self.into_command();
cmd.arg("--log-format").arg("internal-json");
- run_nix_inner_stdout(str, cmd, &mut NixHandler::default()).await
+ let bytes = run_nix_inner_stdout(str, cmd, &mut NixHandler::default()).await?;
+ Ok(String::from_utf8(bytes)?)
}
pub async fn run_nix(self) -> Result<()> {
let str = self.clone().into_string();
@@ -198,7 +249,7 @@
str: String,
cmd: Command,
handler: &mut dyn Handler,
-) -> Result<String> {
+) -> Result<Vec<u8>> {
Ok(run_nix_inner_raw(str, cmd, true, handler, None)
.await?
.expect("has out"))
@@ -208,6 +259,24 @@
assert!(v.is_none());
Ok(())
}
+async fn run_nix_inner_stdout_ssh(
+ str: String,
+ cmd: OwningCommand<Arc<Session>>,
+ handler: &mut dyn Handler,
+) -> Result<Vec<u8>> {
+ Ok(run_nix_inner_raw_ssh(str, cmd, true, handler, None)
+ .await?
+ .expect("has out"))
+}
+async fn run_nix_inner_ssh(
+ str: String,
+ cmd: OwningCommand<Arc<Session>>,
+ handler: &mut dyn Handler,
+) -> Result<()> {
+ let v = run_nix_inner_raw_ssh(str, cmd, false, handler, None).await?;
+ assert!(v.is_none());
+ Ok(())
+}
pub trait Handler: Send {
fn handle_line(&mut self, e: &str);
@@ -468,7 +537,7 @@
want_stdout: bool,
err_handler: &mut dyn Handler,
mut out_handler: Option<&mut dyn Handler>,
-) -> Result<Option<String>> {
+) -> Result<Option<Vec<u8>>> {
cmd.stderr(Stdio::piped());
cmd.stdout(Stdio::piped());
let mut child = cmd.spawn()?;
@@ -522,7 +591,71 @@
}
}
- Ok(out_buf.map(String::from_utf8).transpose()?)
+ Ok(out_buf)
+}
+async fn run_nix_inner_raw_ssh(
+ str: String,
+ mut cmd: OwningCommand<Arc<Session>>,
+ want_stdout: bool,
+ err_handler: &mut dyn Handler,
+ mut out_handler: Option<&mut dyn Handler>,
+) -> Result<Option<Vec<u8>>> {
+ cmd.stderr(openssh::Stdio::piped());
+ cmd.stdout(openssh::Stdio::piped());
+ let mut child = cmd.spawn().await?;
+ let mut stderr = child.stderr().take().unwrap();
+ let stdout = child.stdout().take().unwrap();
+ let mut err = FramedRead::new(&mut stderr, LinesCodec::new());
+ let mut out: Option<Box<dyn AsyncRead + Unpin>> = Some(Box::new(stdout));
+ let mut ob = want_stdout
+ .then(|| out.take().unwrap())
+ .unwrap_or_else(|| Box::new(EmptyAsyncRead));
+ let mut ol = (!want_stdout)
+ .then(|| out.take().unwrap())
+ .unwrap_or_else(|| Box::new(EmptyAsyncRead));
+ let mut ob = FramedRead::new(&mut ob, BytesCodec::new());
+ let mut ol = FramedRead::new(&mut ol, LinesCodec::new());
+
+ // while let Some(line) = read.next().await? {}
+
+ let mut out_buf = if want_stdout { Some(vec![]) } else { None };
+
+ let mut wait_future = pin::pin!(child.wait());
+ loop {
+ select! {
+ e = err.next() => {
+ if let Some(e) = e {
+ let e = e?;
+ err_handler.handle_line(&e);
+ }
+ },
+ o = ob.next() => {
+ if let Some(o) = o {
+ out_buf.as_mut().expect("stdout == wants_stdout").extend_from_slice(&o?);
+ }
+ },
+ o = ol.next() => {
+ if let Some(o) = o {
+ let o = o?;
+ if let Some(out) = out_handler.as_mut() {
+ out.handle_line(&o)
+ } else {
+ err_handler.handle_line(&o)
+ }
+ // out_handler.handle_info(&o);
+ }
+ },
+ code = &mut wait_future => {
+ let code = code?;
+ if !code.success() {
+ anyhow::bail!("command '{str}' failed with status {}", code);
+ }
+ break;
+ }
+ }
+ }
+
+ Ok(out_buf)
}
pub trait ErrorRecorder: Send {
cmds/fleet/src/host.rsdiffbeforeafterboth1use std::{2 env::current_dir,3 ffi::OsString,4 io::Write,5 ops::Deref,6 path::PathBuf,7 sync::{Arc, Mutex, MutexGuard},8};910use anyhow::{anyhow, bail, Context, Result};11use clap::{ArgGroup, Parser};12use openssh::SessionBuilder;13use tempfile::NamedTempFile;1415use crate::{16 better_nix_eval::{Field, NixSessionPool},17 command::MyCommand,18 fleetdata::{FleetData, FleetSecret, FleetSharedSecret},19 nix_go, nix_go_json,20};2122pub struct FleetConfigInternals {23 pub local_system: String,24 pub directory: PathBuf,25 pub opts: FleetOpts,26 pub data: Mutex<FleetData>,27 pub nix_args: Vec<OsString>,28 /// fleetConfigurations.<name>.<localSystem>29 pub fleet_field: Field,30 /// fleet_config.configUnchecked31 pub config_field: Field,32 /// fleet_config.unchecked33 pub config_unchecked_field: Field,34}3536#[derive(Clone)]37pub struct Config(Arc<FleetConfigInternals>);3839impl Deref for Config {40 type Target = FleetConfigInternals;4142 fn deref(&self) -> &Self::Target {43 &self.044 }45}4647pub struct ConfigHost {48 pub name: String,49}50impl ConfigHost {51 async fn open_session(&self) -> Result<openssh::Session> {52 let mut session = SessionBuilder::default();5354 session55 .connect(&self.name)56 .await57 .map_err(|e| anyhow!("ssh error: {e}"))58 }59}6061impl Config {62 pub fn should_skip(&self, host: &str) -> bool {63 if !self.opts.skip.is_empty() {64 self.opts.skip.iter().any(|h| h as &str == host)65 } else if !self.opts.only.is_empty() {66 !self.opts.only.iter().any(|h| h as &str == host)67 } else {68 false69 }70 }71 pub fn is_local(&self, host: &str) -> bool {72 self.opts.localhost.as_ref().map(|s| s as &str) == Some(host)73 }7475 pub async fn run_on(&self, host: &str, mut command: MyCommand, sudo: bool) -> Result<()> {76 if sudo {77 command = command.sudo();78 }79 if !self.is_local(host) {80 command = command.ssh(host);81 }82 command.run().await83 }84 pub async fn run_string_on(85 &self,86 host: &str,87 mut command: MyCommand,88 sudo: bool,89 ) -> Result<String> {90 if sudo {91 command = command.sudo();92 }93 if !self.is_local(host) {94 command = command.ssh(host);95 }96 command.run_string().await97 }9899 pub async fn list_hosts(&self) -> Result<Vec<ConfigHost>> {100 let fleet_field = &self.fleet_field;101 let names = nix_go!(fleet_field.configuredHosts).list_fields().await?;102 let mut out = vec![];103 for name in names {104 out.push(ConfigHost { name })105 }106 Ok(out)107 }108 pub async fn system_config(&self, host: &str) -> Result<Field> {109 let fleet_field = &self.fleet_field;110 Ok(nix_go!(fleet_field.configuredSystems[{ host }].config))111 }112113 pub(super) fn data(&self) -> MutexGuard<FleetData> {114 self.data.lock().unwrap()115 }116 pub(super) fn data_mut(&self) -> MutexGuard<FleetData> {117 self.data.lock().unwrap()118 }119 /// Shared secrets configured in fleet.nix or in flake120 pub async fn list_configured_shared(&self) -> Result<Vec<String>> {121 let config_field = &self.config_field;122 nix_go!(config_field.sharedSecrets).list_fields().await123 }124 /// Shared secrets configured in fleet.nix125 pub fn list_shared(&self) -> Vec<String> {126 let data = self.data();127 data.shared_secrets.keys().cloned().collect()128 }129 pub fn has_shared(&self, name: &str) -> bool {130 let data = self.data();131 data.shared_secrets.contains_key(name)132 }133 pub fn replace_shared(&self, name: String, shared: FleetSharedSecret) {134 let mut data = self.data_mut();135 data.shared_secrets.insert(name.to_owned(), shared);136 }137 pub fn remove_shared(&self, secret: &str) {138 let mut data = self.data_mut();139 data.shared_secrets.remove(secret);140 }141142 pub fn has_secret(&self, host: &str, secret: &str) -> bool {143 let data = self.data();144 let Some(host_secrets) = data.host_secrets.get(host) else {145 return false;146 };147 host_secrets.contains_key(secret)148 }149 pub fn insert_secret(&self, host: &str, secret: String, value: FleetSecret) {150 let mut data = self.data_mut();151 let host_secrets = data.host_secrets.entry(host.to_owned()).or_default();152 host_secrets.insert(secret, value);153 }154155 pub async fn decrypt_on_host(&self, host: &str, data: Vec<u8>) -> Result<Vec<u8>> {156 let data = z85::encode(&data);157 let mut cmd = MyCommand::new("fleet-install-secrets");158 cmd.arg("decrypt").eqarg("--secret", data);159 cmd = cmd.sudo().ssh(host);160 let encoded = cmd161 .run_string()162 .await163 .context("failed to call remote host for decrypt")?164 .trim()165 .to_owned();166 z85::decode(encoded).context("bad encoded data? outdated host?")167 }168 pub async fn reencrypt_on_host(169 &self,170 host: &str,171 data: Vec<u8>,172 targets: Vec<String>,173 ) -> Result<Vec<u8>> {174 let data = z85::encode(&data);175 let mut recmd = MyCommand::new("fleet-install-secrets");176 recmd.arg("reencrypt").eqarg("--secret", data);177 for target in targets {178 recmd.eqarg("--targets", target);179 }180 recmd = recmd.sudo().ssh(host);181 let encoded = recmd182 .run_string()183 .await184 .context("failed to call remote host for decrypt")?185 .trim()186 .to_owned();187 z85::decode(encoded).context("bad encoded data? outdated host?")188 }189190 pub fn host_secret(&self, host: &str, secret: &str) -> Result<FleetSecret> {191 let data = self.data();192 let Some(host_secrets) = data.host_secrets.get(host) else {193 bail!("no secrets for machine {host}");194 };195 let Some(secret) = host_secrets.get(secret) else {196 bail!("machine {host} has no secret {secret}");197 };198 Ok(secret.clone())199 }200 pub fn shared_secret(&self, secret: &str) -> Result<FleetSharedSecret> {201 let data = self.data();202 let Some(secret) = data.shared_secrets.get(secret) else {203 bail!("no shared secret {secret}");204 };205 Ok(secret.clone())206 }207 pub async fn shared_secret_expected_owners(&self, secret: &str) -> Result<Vec<String>> {208 let config_field = &self.config_field;209 Ok(nix_go_json!(210 config_field.sharedSecrets[{ secret }].expectedOwners211 ))212 }213214 pub fn save(&self) -> Result<()> {215 let mut tempfile = NamedTempFile::new_in(self.directory.clone())?;216 let data = nixlike::serialize(&self.data() as &FleetData)?;217 tempfile.write_all(218 format!(219 "# This file contains fleet state and shouldn't be edited by hand\n\n{}\n\n# vim: ts=2 et nowrap\n",220 data221 )222 .as_bytes(),223 )?;224 let mut fleet_data_path = self.directory.clone();225 fleet_data_path.push("fleet.nix");226 tempfile.persist(fleet_data_path)?;227 Ok(())228 }229}230231#[derive(Parser, Clone)]232#[clap(group = ArgGroup::new("target_hosts"))]233pub struct FleetOpts {234 /// All hosts except those would be skipped235 #[clap(long, number_of_values = 1, group = "target_hosts")]236 only: Vec<String>,237238 /// Hosts to skip239 #[clap(long, number_of_values = 1, group = "target_hosts")]240 skip: Vec<String>,241242 /// Host, which should be threaten as current machine243 #[clap(long)]244 pub localhost: Option<String>,245246 /// Override detected system for host, to perform builds via247 /// binfmt-declared qemu instead of trying to crosscompile248 #[clap(long, default_value = "detect")]249 pub local_system: String,250}251252impl FleetOpts {253 pub async fn build(mut self, nix_args: Vec<OsString>) -> Result<Config> {254 if self.localhost.is_none() {255 self.localhost256 .replace(hostname::get().unwrap().to_str().unwrap().to_owned());257 }258 let directory = current_dir()?;259260 let pool = NixSessionPool::new(directory.as_os_str().to_owned(), nix_args.clone()).await?;261 let root_field = pool.get().await?;262263 if self.local_system == "detect" {264 let builtins_field = Field::field(root_field.clone(), "builtins").await?;265 self.local_system = nix_go_json!(builtins_field.currentSystem);266 }267 let local_system = self.local_system.clone();268269 let fleet_root = Field::field(root_field, "fleetConfigurations").await?;270271 let fleet_field = nix_go!(fleet_root.default);272 let config_field = nix_go!(fleet_field.configUnchecked);273 let config_unchecked_field = nix_go!(fleet_field.unchecked);274275 let mut fleet_data_path = directory.clone();276 fleet_data_path.push("fleet.nix");277 let bytes = std::fs::read_to_string(fleet_data_path)?;278 let data = nixlike::parse_str(&bytes)?;279280 Ok(Config(Arc::new(FleetConfigInternals {281 opts: self,282 directory,283 data,284 local_system,285 nix_args,286 fleet_field,287 config_field,288 config_unchecked_field,289 })))290 }291}nixos/meta.nixdiffbeforeafterboth--- a/nixos/meta.nix
+++ b/nixos/meta.nix
@@ -1,11 +1,18 @@
-{ lib, ... }:
-with lib;
{
+ lib,
+ pkgs,
+ ...
+}:
+with lib; {
options = with types; {
+ nixpkgs.resolvedPkgs = mkOption {
+ type = types.pkgs // {description = "nixpkgs.pkgs";};
+ description = "Value of pkgs";
+ };
tags = mkOption {
type = listOf str;
description = "Host tags";
- default = [ ];
+ default = [];
};
network = mkOption {
type = submodule {
@@ -13,12 +20,12 @@
internalIps = mkOption {
type = listOf str;
description = "Internal ips";
- default = [ ];
+ default = [];
};
externalIps = mkOption {
type = listOf str;
description = "External ips";
- default = [ ];
+ default = [];
};
};
};
@@ -29,7 +36,8 @@
};
};
config = {
- tags = [ "all" ];
- network = { };
+ tags = ["all"];
+ network = {};
+ nixpkgs.resolvedPkgs = pkgs;
};
}