fix(thin-client): deep-build fixes + Snipe-IT/Alloy real impl
Tiefen-Validierung via 'nix build .#nixosConfigurations.AZ-TC-NN.config.
system.build.toplevel' hat mehrere reale Bugs gefunden, die 'nix flake
check' nicht sah. Alle drei Pilot-Hosts bauen jetzt sauber durch.
Gefixst:
- freerdp3 → freerdp (umbenannt in nixpkgs-unstable)
- SDDM Theme.Logo will INI-Atom (string), nicht Nix-path → '${path}'
- security.pam.mount.extraVolumes will list-of-string, nicht ein String
- sudoers: 'domain admins' muss als 'domain\ admins' escaped werden
- agenix file-Pfade: ../../secrets/ → ../../../secrets/ (Tiefe korrigiert)
- snapper: config.services.snapper.package gibt es nicht → pkgs.snapper
- samba4Full entfernt (blockiert durch ceph-common python metadata issue
in nixpkgs-unstable; Thin Clients brauchen es nicht — cifs-utils reicht)
- corp-wifi-ca.pem durch gültiges Dummy-PEM ersetzt (openssl-generiert,
mit明显 REPLACE-MARKER; build kann PEM parsen)
Functional gemacht:
- Alloy: echtes River-Config mit loki.source.journal + loki.write statt
barem logging-stub. Journal-Logs mit host/unit/severity-Labels nach
Loki.
- Snipe-IT: echte Check-in-Logik via curl + jq. Lookup by asset_tag,
PATCH falls exists, POST falls neu. startAt täglich 03:30. API-Token
via agenix (snipeit-api-token.age).
- node_exporter push: realer curl-Push alle 60s mit retry on failure.
Safety:
- Placeholder-Assertions in roles/thin-client/default.nix: build schlägt
fehl, wenn wifi.ssid/hotline/company noch Placeholder sind (außer
site='staging'). Pilot-Hosts haben site='staging' bis echte Werte da.
- assets/corp-wifi-ca.pem hat deutlich sichtbaren REPLACE-Hinweis.
Neue Options:
- az.tc.monitoring.snipeItUrl (default: snipeit.az-group.local)
Neue Secrets (Placeholder .age-Files zum Ausfüllen):
- snipeit-api-token.age (fleet-wide shared)
This commit is contained in:
@@ -33,7 +33,7 @@ Quick reference:
|
||||
| Printers | Single Pull-Print queue, direct IPPS, Avahi off |
|
||||
| Branding | Light: corporate wallpaper + SDDM logo + property footer, no banner |
|
||||
| Updates | `system.autoUpgrade` daily at 03:00, reboot window 03:00-05:00 |
|
||||
| Monitoring | node_exporter → Pushgateway, promtail → Loki, Snipe-IT asset check-in |
|
||||
| Monitoring | node_exporter → Pushgateway, Alloy → Loki (journal), Snipe-IT asset check-in (daily 03:30) |
|
||||
| Rollout | Pilot: 3 hosts, 2 weeks; then 5 → 10 → rest |
|
||||
|
||||
## Provisioning workflow for a new Fleet Host
|
||||
@@ -171,6 +171,7 @@ All tunable parameters live under `az.tc.*`:
|
||||
| `az.tc.branding.company` | `AzIntec GmbH` | Company name |
|
||||
| `az.tc.monitoring.prometheusPushGateway` | `pushgateway.az-group.local:9091` | Pushgateway URL |
|
||||
| `az.tc.monitoring.lokiUrl` | `http://loki.az-group.local:3100` | Loki URL |
|
||||
| `az.tc.monitoring.snipeItUrl` | `https://snipeit.az-group.local` | Snipe-IT base URL |
|
||||
| `az.tc.monitoring.assetTool` | `snipe-it` | Asset tool integration |
|
||||
| `az.tc.deployment.diskDevice` | `/dev/sda` | Disko target disk |
|
||||
| `az.tc.deployment.swapSizeGB` | `4` | Swap size in GB |
|
||||
@@ -206,9 +207,25 @@ To validate the config without deploying:
|
||||
# Eval-check all hosts
|
||||
nix flake check
|
||||
|
||||
# Build a pilot host closure
|
||||
nix build .#nixosConfigurations.AZ-TC-01.config.system.build.toplevel
|
||||
# Build a pilot host closure (full closure, takes ~20 min uncached)
|
||||
nix build --no-link .#nixosConfigurations.AZ-TC-01.config.system.build.toplevel
|
||||
|
||||
# Try a VM boot
|
||||
nix run .#nixosConfigurations.AZ-TC-01.config.system.build.vm
|
||||
```
|
||||
|
||||
All three pilot hosts pass both `nix flake check` and full closure build.
|
||||
|
||||
## Placeholder assertions
|
||||
|
||||
The role ships with **placeholder assertions** that fire at build time if
|
||||
operator-relevant values are still defaults. To silence for lab/staging
|
||||
hosts, set `az.tc.site = "staging"` (see `hosts/AZ-TC-01/default.nix`).
|
||||
|
||||
Currently asserted:
|
||||
|
||||
- `az.tc.wifi.ssid != "AZ-CORP"` — real Corp SSID must be set
|
||||
- `az.tc.branding.hotline != "+49 30 1234567"` — real hotline must be set
|
||||
- `az.tc.branding.company != "AzIntec GmbH"` — real company name must be set
|
||||
|
||||
Add more assertions as customer-specific values firm up.
|
||||
|
||||
Reference in New Issue
Block a user