Skip to content
David-KopczynskiPublic

About

Proxmox Services on NixOS

Topics

Resources

Stars

2 stars

Watchers

2 watching

Forks

Latest commit

 

History

360 Commits

Folders and files

Repository files navigation

🌐 NixOS on Proxmox

This Nix installation is for multiple VMs running on my Proxmox Home-Lab server with a N100 (Intel 4 Core, Max 3.40 GHz) and 32 GB of RAM.

Installation is done remotely with the following command to build and deploy the new configuration using Colmena.
Also, npins and sops-nix are used to streamline deployment!

# Update dependencies (if required)
npins -d ~/Documents/proxmox/npins update

# 'test', 'boot' or 'switch' configuration
nix-shell -p colmena --run "colmena apply -f ~/Documents/proxmox/hive.nix switch [--on <NODES>]"

# Update Proxmox and PBS
~/Documents/proxmox/ansible/update.sh
🔨 Installation

Setup is done remotely using nixos-anywhere by running ./nixos-anywhere/setup.sh to setup all partitions and deploying a base configuration to begin with.

Make sure the following constraints are met:

  1. The VM is created with the following settings:
    • Memory: 4 GB (4096 MB)
    • BIOS: OVMF (UEFI)
    • Hard Disk (scsi0): 8 GB
    • Hard Disk (scsi1): 1 GB
    • EFI Disk: default
  2. The VM is booted with the NixOS installation ISO.
  3. A password is set with sudo passwd to connect with the VM over SSH.
  4. Install using ./nixos-anywhere/setup.sh.
  5. After installation, a new password should be set with passwd. Apart from that, the VM is ready to be used, while the ISO can be removed. Ideally, the VM should also be renamed to its hostname within the router dashboard.
  6. In order to deploy with Colmena, the initial installation with deployment.targetHost should point to the hostname nixos or the IP address of the VM. Also, (if required) generate an age key for the host machine with nix-shell -p ssh-to-age --run "echo '$(ssh root@nixos "cat /etc/ssh/ssh_host_ed25519_key.pub")' | ssh-to-age" and add it to the .sops.yaml file.

Otherwise, the installation will fail due to a lack of resources in the store or the connection being refused.
During the installation, it is possible for the IP to change. If this happens, run the installation again using the new IP.

At the time of writing, secure boot must be disabled with ESC -> Device Manager -> Secure Boot Configuration -> Disable Secure Boot -> Save & Exit (enter by pressing ESC while booting VM).

🔐 Secrets

Secrets are encrypted with sops-nix using my private SSH key.
Add or edit secrets as shown below.

sops install/$host/secrets.yaml

During creation of the secrets.yaml, you need to cd into this directory to create the file.
Afterwards, you can open the file from anywhere.


Credits to Josh Lee for a great guide while setting up this configuration.

About

Proxmox Services on NixOS

Topics

Resources

Stars

2 stars

Watchers

2 watching

Forks

Contributors

Languages