2019-11-06 16:48:07 +01:00
|
|
|
import ../make-test-python.nix ({ lib, ... }:
|
2017-09-18 14:52:07 +02:00
|
|
|
|
2017-11-27 09:14:17 +01:00
|
|
|
{
|
2017-09-18 14:52:07 +02:00
|
|
|
name = "initrd-network-ssh";
|
|
|
|
meta = with lib.maintainers; {
|
2020-03-14 19:29:08 +01:00
|
|
|
maintainers = [ willibutz emily ];
|
2017-09-18 14:52:07 +02:00
|
|
|
};
|
|
|
|
|
2019-08-13 23:52:01 +02:00
|
|
|
nodes = with lib; {
|
2017-09-18 14:52:07 +02:00
|
|
|
server =
|
2018-07-20 22:56:59 +02:00
|
|
|
{ config, ... }:
|
2017-09-18 14:52:07 +02:00
|
|
|
{
|
|
|
|
boot.kernelParams = [
|
2017-12-03 05:14:54 +01:00
|
|
|
"ip=${config.networking.primaryIPAddress}:::255.255.255.0::eth1:none"
|
2017-09-18 14:52:07 +02:00
|
|
|
];
|
|
|
|
boot.initrd.network = {
|
|
|
|
enable = true;
|
|
|
|
ssh = {
|
|
|
|
enable = true;
|
2020-03-14 19:29:08 +01:00
|
|
|
authorizedKeys = [ (readFile ./id_ed25519.pub) ];
|
2017-09-18 14:52:07 +02:00
|
|
|
port = 22;
|
2020-03-14 19:29:08 +01:00
|
|
|
hostKeys = [ ./ssh_host_ed25519_key ];
|
2017-09-18 14:52:07 +02:00
|
|
|
};
|
|
|
|
};
|
2020-11-02 21:18:57 +01:00
|
|
|
boot.initrd.extraUtilsCommands = ''
|
|
|
|
mkdir -p $out/secrets/etc/ssh
|
|
|
|
cat "${./ssh_host_ed25519_key}" > $out/secrets/etc/ssh/sh_host_ed25519_key
|
|
|
|
'';
|
2017-09-18 14:52:07 +02:00
|
|
|
boot.initrd.preLVMCommands = ''
|
|
|
|
while true; do
|
|
|
|
if [ -f fnord ]; then
|
|
|
|
poweroff
|
|
|
|
fi
|
|
|
|
sleep 1
|
|
|
|
done
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
client =
|
2018-07-20 22:56:59 +02:00
|
|
|
{ config, ... }:
|
2017-09-18 14:52:07 +02:00
|
|
|
{
|
2019-11-06 16:48:07 +01:00
|
|
|
environment.etc = {
|
|
|
|
knownHosts = {
|
|
|
|
text = concatStrings [
|
|
|
|
"server,"
|
|
|
|
"${toString (head (splitString " " (
|
|
|
|
toString (elemAt (splitString "\n" config.networking.extraHosts) 2)
|
|
|
|
)))} "
|
2020-03-14 19:29:08 +01:00
|
|
|
"${readFile ./ssh_host_ed25519_key.pub}"
|
2019-11-06 16:48:07 +01:00
|
|
|
];
|
|
|
|
};
|
|
|
|
sshKey = {
|
2020-03-14 19:29:08 +01:00
|
|
|
source = ./id_ed25519;
|
2019-11-06 16:48:07 +01:00
|
|
|
mode = "0600";
|
|
|
|
};
|
2017-09-18 14:52:07 +02:00
|
|
|
};
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
testScript = ''
|
2019-11-06 16:48:07 +01:00
|
|
|
start_all()
|
|
|
|
client.wait_for_unit("network.target")
|
2020-03-14 19:29:08 +01:00
|
|
|
|
|
|
|
|
|
|
|
def ssh_is_up(_) -> bool:
|
|
|
|
status, _ = client.execute("nc -z server 22")
|
|
|
|
return status == 0
|
|
|
|
|
|
|
|
|
|
|
|
with client.nested("waiting for SSH server to come up"):
|
|
|
|
retry(ssh_is_up)
|
|
|
|
|
|
|
|
|
2019-11-06 16:48:07 +01:00
|
|
|
client.succeed(
|
|
|
|
"ssh -i /etc/sshKey -o UserKnownHostsFile=/etc/knownHosts server 'touch /fnord'"
|
|
|
|
)
|
|
|
|
client.shutdown()
|
2017-09-18 14:52:07 +02:00
|
|
|
'';
|
|
|
|
})
|