diff --git a/flake.lock b/flake.lock index cccbd38..7170cee 100644 --- a/flake.lock +++ b/flake.lock @@ -7,11 +7,11 @@ "nixpkgs": "nixpkgs" }, "locked": { - "lastModified": 1690228878, - "narHash": "sha256-9Xe7JV0krp4RJC9W9W9WutZVlw6BlHTFMiUP/k48LQY=", + "lastModified": 1701216516, + "narHash": "sha256-jKSeJn+7hZ1dZdiH1L+NWUGT2i/BGomKAJ54B9kT06Q=", "owner": "ryantm", "repo": "agenix", - "rev": "d8c973fd228949736dedf61b7f8cc1ece3236792", + "rev": "13ac9ac6d68b9a0896e3d43a082947233189e247", "type": "github" }, "original": { diff --git a/home/hosts/jude/default.nix b/home/hosts/jude/default.nix index a2a4498..304492a 100644 --- a/home/hosts/jude/default.nix +++ b/home/hosts/jude/default.nix @@ -4,7 +4,8 @@ imports = [ ../../vscodium.nix ]; - home.packages = [ - (pkgs.mumble.override { pulseSupport = true; }) + home.packages = with pkgs; [ + (mumble.override { pulseSupport = true; }) + fluffychat ]; } diff --git a/hosts/jude/virt.nix b/hosts/jude/virt.nix index a5cbeda..1f456bb 100644 --- a/hosts/jude/virt.nix +++ b/hosts/jude/virt.nix @@ -33,4 +33,15 @@ users.extraGroups.vboxusers.members = [ "greg" ]; boot.extraModprobeConfig = "options kvm_amd nested=1"; + + greg.ci-runner = { + qemu = { + labels = [ + "qemu:host" + ]; + packages = with pkgs; [ + qemu + ]; + }; + }; } diff --git a/modules-all/ci-runner.nix b/modules-all/ci-runner.nix new file mode 100644 index 0000000..d067986 --- /dev/null +++ b/modules-all/ci-runner.nix @@ -0,0 +1,84 @@ +{ config, pkgs, lib, ... }: + +let + cfg = config.greg.ci-runner; + runnerNames = (builtins.attrNames cfg); + makeRunner = name: value: { + enable = true; + hostPackages = with pkgs; [ + bashInteractive + podman + git + nodejs + ] ++ value.packages; + labels = lib.mkIf ( builtins.hasAttr "labels" value) value.labels; + name = config.networking.hostName; + tokenFile = config.age.secrets.forgejo-runner.path; + url = "https://src.thehellings.com"; + settings.runner.capacity = value.parallel; + }; + + userName = "gitea-runner"; + +in with lib; { + options = { + greg.ci-runner = mkOption { + default = {}; + description = "List of gitea/forgejo runners to configure"; + example = '' + ``` + greg.ci-runner.snarfblatt = { + labels = [ "ubuntu-latest:docker://ubuntu:latest" ]; + }; + ``` + ''; + + type = with types; attrsOf ( submodule ( + { name, config, options, ... }: + { + options.labels = mkOption { + type = (types.listOf types.str); + default = []; + description = ''List of labels. The syntax is + more or less going to be something along the lines + of `:docker://` or + `native:host` for a system that will support running + commands directly on the server.''; + }; + + options.packages = mkOption { + type = (types.listOf types.package); + default = []; + description = ''List of extra packages that will be needed + in the running environment for this worker.''; + }; + + options.parallel = mkOption { + type = types.int; + default = 3; + description = "The maximum number of parallel jobs this runner will support."; + }; + }) + ); + }; + }; + + config = mkIf ( runnerNames != [] ) { + services.gitea-actions-runner.instances = ( mapAttrs makeRunner cfg); + + age.secrets.forgejo-runner = let + aName = builtins.elemAt runnerNames 0; + target = "gitea-runner-${aName}"; + in { + file = ../secrets/${config.networking.hostName}-forgejo-runner.age; + owner = userName; + group = userName; + }; + + users.users."${userName}" = { + isSystemUser = true; + group = "${userName}"; + }; + users.groups."${userName}" = {}; + }; +} diff --git a/modules-all/default.nix b/modules-all/default.nix index ce97e9e..68a1f9b 100644 --- a/modules-all/default.nix +++ b/modules-all/default.nix @@ -1,6 +1,10 @@ { pkgs, lib, ... }: { + imports = [ + ./ci-runner.nix + ]; + # Enable flakes nix = { package = pkgs.nixFlakes; diff --git a/secrets/jude-forgejo-runner.age b/secrets/jude-forgejo-runner.age new file mode 100644 index 0000000..3db24a3 --- /dev/null +++ b/secrets/jude-forgejo-runner.age @@ -0,0 +1,17 @@ +age-encryption.org/v1 +-> ssh-ed25519 mOmPfg 1Q/zfHlucVlB8FkxpOSYnWgFBJre3KeW+uANvUC/PFU +/uuW2lV2SwdekZPeJsCXK4T+msMtBFVio5fvFPOlcCI +-> ssh-ed25519 YJiRbw 4s8W7hOd8/kxQ4lImUYmF0DhXCuUZeCWXE+ueAFRbzg +el12BcxbsdyDHHalcucjqZz/Hzegg1J+Nvr0BFXXpu8 +-> ssh-ed25519 Nl/5yA CP6ofzQfDKGGv2yFhjBx58xHPOaTazZ0jW0R6WXRiX8 ++jOI7EIa0O1qh4ARyctAr8NHvp8Y8HSkA9tT8ybNrUg +-> ssh-ed25519 tOH/HQ oI1ltqtnlvl5WUrebrdy8LErHleiNHQJVc9FXuUwZ28 +FNeE2F6tM6CWXiFwJnguL/0BGMz1oejyV+vX25UN3cY +-> ssh-ed25519 FpzvfQ XeYdcSTqUtY6mNwzZ9vfohJ/4y17OdoaYCNpGZxWrjw +3qA8Wsik3/JH+JVOr8T9ue2Y9wDzwrf6rWsfwbGTJAE +-> ssh-ed25519 GdLgCQ dAfetOmfUR4G4qcS4mjw2Z1h0iFt22Yh4GioqpJpimo +HQ5auu9P454fqMgCeYu5ynMXqyM35kvzlK4DFozhcC0 +-> FilBs@/-grease %U4V^CDH 6'KK:"` +dirZXZvJaCxTTtTT +--- qvxgsWakIV8/n+LxUXw9WQ1nkKEfEBRv6oBSsc6KFJ4 +DpY֤ӜIp)>N dՐr~x'`~+UWF $.2%9>ʺ