feat(nixos): add impermanence module for ephemeral roots

This commit is contained in:
Mohammad Rafiq 2025-07-07 12:16:14 +08:00
parent 714c3b8940
commit 9abcb6c85b
No known key found for this signature in database
4 changed files with 62 additions and 0 deletions

View file

@ -0,0 +1,44 @@
{
config,
lib,
inputs,
...
}:
let
inherit (lib) mkMerge mkIf mkAfter;
in
{
flake.modules.nixos.default =
{ hostName, ... }:
let
inherit (config.flake.manifest.hosts.nixos.${hostName}.machine) root;
in
{
imports = [ inputs.impermanence.nixosModules.impermanence ];
config = mkMerge [
# Ephemeral by default - assumes btrfs
(mkIf (root.ephemeral or true) {
boot.initrd.postDeviceCommands = mkAfter ''
mkdir /btrfs_tmp
mount /dev/root_vg/root /btrfs_tmp
if [[ -e /btrfs_tmp/root ]]; then
btrfs subvolume delete "/btrfs_tmp/root"
fi
'';
programs.fuse.userAllowOther = true;
fileSystems."/persist".neededForBoot = true;
environment.persistence."/persist" = {
hideMounts = true;
files = [
"/etc/ssh/ssh_host_ed25519_key"
"/etc/ssh/ssh_host_ed25519_key.pub"
"/etc/ssh/ssh_host_rsa_key"
"/etc/ssh/ssh_host_rsa_key.pub"
"/etc/machine-id"
];
};
})
];
};
}