- LUKS2 is the installer default; in exchange the generated config sets
the new nomarchy.system.greeter.autoLogin (greetd initial_session) —
the disk passphrase already gates the machine.
- @snapshots subvolume + nomarchy.system.snapper.enable: hourly/daily
timeline snapshots of / and the nixos-rebuild-snap helper, ported from
the previous iteration (3bdfc35), guarded to no-op on non-BTRFS roots.
- @swap subvolume with a swapfile sized to RAM by default (disko
mkswapfile handles NOCOW); the installer computes the resume offset
and wires boot.resumeDevice + resume_offset for hibernation.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
73 lines
2.6 KiB
Nix
73 lines
2.6 KiB
Nix
{ lib
|
|
, stdenvNoCC
|
|
, makeWrapper
|
|
, bash
|
|
, gum
|
|
, disko
|
|
, whois # mkpasswd
|
|
, git
|
|
, python3
|
|
, util-linux # lsblk, wipefs, swapoff, lscpu
|
|
, gptfdisk # sgdisk
|
|
, parted # partprobe
|
|
, cryptsetup
|
|
, lvm2 # dmsetup
|
|
, pciutils # lspci
|
|
, btrfs-progs # inspect-internal map-swapfile (hibernation offset)
|
|
# Baked metadata — what this installer installs and where it came from.
|
|
, templateDir # templates/downstream (home.nix, theme-state.json)
|
|
, nomarchyLock # the distro's flake.lock (for offline lock composition)
|
|
, hardwareModuleNames # newline-separated nixos-hardware module names
|
|
, flakeUrl # flake-style URL written into the generated flake.nix
|
|
, lockedNode # attrset: the flake.lock "locked" node for nomarchy
|
|
# (rev = null when the ISO was built from a dirty tree)
|
|
, originalNode # attrset: the flake.lock "original" node
|
|
}:
|
|
|
|
stdenvNoCC.mkDerivation {
|
|
pname = "nomarchy-install";
|
|
version = "0.1.0";
|
|
|
|
src = ./.;
|
|
|
|
nativeBuildInputs = [ makeWrapper ];
|
|
|
|
installPhase = ''
|
|
runHook preInstall
|
|
|
|
install -Dm755 nomarchy-install.sh $out/bin/nomarchy-install
|
|
patchShebangs $out/bin/nomarchy-install
|
|
|
|
share=$out/share/nomarchy-install
|
|
install -Dm644 disko-config.nix "$share/disko-config.nix"
|
|
install -Dm644 hardware-db.sh "$share/hardware-db.sh"
|
|
install -Dm644 compose-lock.py "$share/compose-lock.py"
|
|
install -Dm644 ${nomarchyLock} "$share/flake.lock"
|
|
install -Dm644 ${hardwareModuleNames} "$share/hardware-modules.txt"
|
|
mkdir -p "$share/template"
|
|
cp ${templateDir}/home.nix ${templateDir}/theme-state.json "$share/template/"
|
|
|
|
# nixos-install / nixos-generate-config / nixos-enter / nix / systemd
|
|
# tools come from the live system on purpose — they must match it.
|
|
wrapProgram $out/bin/nomarchy-install \
|
|
--prefix PATH : ${lib.makeBinPath [
|
|
bash gum disko whois git python3
|
|
util-linux gptfdisk parted cryptsetup lvm2 pciutils btrfs-progs
|
|
]} \
|
|
--set NOMARCHY_INSTALL_SHARE "$share" \
|
|
--set NOMARCHY_FLAKE_URL ${lib.escapeShellArg flakeUrl} \
|
|
--set NOMARCHY_REV ${lib.escapeShellArg (toString (lockedNode.rev or ""))} \
|
|
--set NOMARCHY_LOCKED_JSON ${lib.escapeShellArg (builtins.toJSON lockedNode)} \
|
|
--set NOMARCHY_ORIGINAL_JSON ${lib.escapeShellArg (builtins.toJSON originalNode)}
|
|
|
|
runHook postInstall
|
|
'';
|
|
|
|
meta = {
|
|
description = "Nomarchy guided installer (disko + mkFlake + nixos-install)";
|
|
license = lib.licenses.mit;
|
|
mainProgram = "nomarchy-install";
|
|
platforms = lib.platforms.linux;
|
|
};
|
|
}
|