diff --git a/hosts/exodus/default.nix b/hosts/exodus/default.nix index e6fcf01..065bc22 100644 --- a/hosts/exodus/default.nix +++ b/hosts/exodus/default.nix @@ -33,10 +33,9 @@ podman.enable = true; print.enable = true; tailscale.enable = true; - runner.enable = true; - vmdev = { - enable = false; - system = "intel"; + runner = { + enable = true; + qemu = true; }; }; diff --git a/hosts/isaiah/default.nix b/hosts/isaiah/default.nix index 400184c..ce81a7b 100644 --- a/hosts/isaiah/default.nix +++ b/hosts/isaiah/default.nix @@ -41,7 +41,10 @@ }; tailscale.enable = true; remote-builder.enable = true; - runner.enable = true; + runner = { + enable = true; + qemu = true; + }; }; fileSystems = { diff --git a/hosts/jeremiah/default.nix b/hosts/jeremiah/default.nix index 8094977..495dfca 100644 --- a/hosts/jeremiah/default.nix +++ b/hosts/jeremiah/default.nix @@ -85,6 +85,7 @@ in runner = { enable = true; threads = 3; + qemu = true; }; }; diff --git a/hosts/zeke/default.nix b/hosts/zeke/default.nix index f1a8908..0d94afb 100644 --- a/hosts/zeke/default.nix +++ b/hosts/zeke/default.nix @@ -22,7 +22,10 @@ priority = 253; }; remote-builder.enable = true; - runner.enable = true; + runner = { + enable = true; + vbox = true; + }; tailscale.enable = true; }; @@ -86,4 +89,10 @@ "kvm" "podman" ]; + + virtualisation.virtualbox.host = { + enableExtensionPack = true; + headless = true; + enableWebService = true; + }; } diff --git a/modules/nixos/gitlab-runner.nix b/modules/nixos/gitlab-runner.nix index 40f2d88..49b32e7 100644 --- a/modules/nixos/gitlab-runner.nix +++ b/modules/nixos/gitlab-runner.nix @@ -10,7 +10,14 @@ let EFI_DIR = "${pkgs.OVMF.fd}/FV/"; STORAGE_URL = "s3.thehellings.lan:9000"; }; + runnerCfg = file: { + inherit environmentVariables; + authenticationTokenConfigFile = file; + executor = "shell"; + limit = cfg.threads; + }; in +# We want exactly one of these to be true, but not both. Neither can both be false { options.greg.runner = { enable = lib.mkEnableOption "Enable as a gitlab-runner with both libvirt and virtualbox"; @@ -20,24 +27,30 @@ in type = lib.types.int; description = "The maximum number of concurrent jobs"; }; + + qemu = lib.mkEnableOption "Enable the qemu host (mutually exclusive with vbox)"; + vbox = lib.mkEnableOption "Enable the vbox host (mutually exclusive with qemu)"; }; - config = lib.mkIf cfg.enable { + config = lib.mkIf cfg.enable ({ + # assertions = [ + # { + # assertion = cfg.qemu || cfg.vbox && (cfg.qemu != cfg.vbox); + # message = "You must enable exactly one of qemu or vbox"; + # } + # ]; # Shared configurations age.secrets = { qemu.file = ../../secrets/gitlab/nixos-qemu-shell.age; vbox.file = ../../secrets/gitlab/nixos-vbox-shell.age; }; - # Defaults to running libvirt support services.gitlab-runner = { enable = true; settings.concurrent = cfg.threads; - services.qemu = { - inherit environmentVariables; - executor = "shell"; - limit = cfg.threads; - authenticationTokenConfigFile = config.age.secrets.qemu.path; + services = { + qemu = lib.mkIf cfg.qemu (runnerCfg config.age.secrets.qemu.path); + vbox = lib.mkIf cfg.vbox (runnerCfg config.age.secrets.vbox.path); }; }; @@ -49,9 +62,11 @@ in }; }; + users.extraGroups.vboxusers.members = lib.optional cfg.vbox "greg"; + virtualisation = { - libvirtd = { - enable = lib.mkDefault true; + libvirtd = lib.mkIf cfg.qemu { + enable = true; allowedBridges = [ "br0" "virbr0" @@ -59,39 +74,10 @@ in onBoot = "ignore"; # only restart VMs labeled 'autostart' qemu.ovmf.enable = true; }; - }; - # Boot into this specialisation if you want to build vbox hosts - # with this box at that time - specialisation = { - vbox.configuration = { - users.extraGroups.vboxusers.members = [ "greg" ]; - - virtualisation = { - libvirtd.enable = false; - virtualbox.host = { - enable = true; - enableExtensionPack = true; - }; - }; - - services.gitlab-runner.services = lib.mkForce { - vbox = { - inherit environmentVariables; - authenticationTokenConfigFile = config.age.secrets.vbox.path; - executor = "shell"; - limit = 5; - }; - }; - - systemd.services.gitlab-runner = { - serviceConfig = { - DevicePolicy = lib.mkForce "auto"; - User = "root"; - DynamicUser = lib.mkForce false; - }; - }; + virtualbox.host = lib.mkIf cfg.vbox { + enable = true; + enableExtensionPack = true; }; }; - - }; + }); }