ci.nix 10.9 KB
Newer Older
Valentin Reis's avatar
stub ci    
Valentin Reis committed
1
{
Valentin Reis's avatar
ci fix    
Valentin Reis committed
2
  pkgs ? import ../pin.nix {jsonpath=../nixpkgs-18.03.json;}
Valentin Reis's avatar
stub ci    
Valentin Reis committed
3
4
5
6
}:
let
  keys = [ (pkgs.lib.readFile keys/id_rsa_vrg.pub) ];
  argopkgs = import ../pkgs {};
Valentin Reis's avatar
Valentin Reis committed
7
  hydraSrc = builtins.fetchTarball https://github.com/nixos/hydra/archive/master.tar.gz;
Valentin Reis's avatar
Valentin Reis committed
8
  argomodules = import ../modules/module-list.nix;
Valentin Reis's avatar
stub ci    
Valentin Reis committed
9
10
11
12
13
in
  {
    network.description = "argo-ci";
    network.enableRollback = false;

Valentin Reis's avatar
Valentin Reis committed
14
    hydra-tacc =
Valentin Reis's avatar
ci fix    
Valentin Reis committed
15
    { config, ... }:
Valentin Reis's avatar
Valentin Reis committed
16
    {
Valentin Reis's avatar
Valentin Reis committed
17
18
19
20
21
22
23
24
25
26
27
      deployment.targetEnv = "none";
      deployment.targetHost = "argo.freux.fr";

      deployment.keys."id_buildfarm"     =   {
        destDir = "/run";
        keyFile = ./id_buildfarm.secret;
        user = "hydra-queue-runner";
        group = "hydra";
        permissions = "600";
      };

Valentin Reis's avatar
Valentin Reis committed
28
29
      time.timeZone = "America/Chicago";

Valentin Reis's avatar
Valentin Reis committed
30
      require=argomodules;
31
      environment.argo.known-hosts.enable=true;
Valentin Reis's avatar
Valentin Reis committed
32
      environment.argo.provider-tacc.enable=true;
33
      environment.argo.root-access.enable=true;
Valentin Reis's avatar
Valentin Reis committed
34
      environment.argo.ssh-config.enable=true;
Valentin Reis's avatar
Valentin Reis committed
35

Valentin Reis's avatar
Valentin Reis committed
36
37
      environment.variables.TERM = "xterm";

38
      imports = [ "${hydraSrc}/hydra-module.nix" ];
Valentin Reis's avatar
Valentin Reis committed
39
40


Valentin Reis's avatar
Valentin Reis committed
41
42
43
44
45
46
47
48
49
50
      i18n.defaultLocale = "en_US.UTF-8";
      services.ntp.enable = false;
      services.openssh.allowSFTP = false;

      assertions = pkgs.lib.singleton {
        assertion = pkgs.system == "x86_64-linux";
        message = "unsupported system ${pkgs.system}";
      };

      nix = {
51
52
        sshServe= { inherit keys; enable=true;};
        package = pkgs.nixUnstable; trustedUsers = [ "hydra" ]; binaryCaches = [ "https://cache.nixos.org" ];
Valentin Reis's avatar
Valentin Reis committed
53
54
55
56
        useChroot = true;
        nrBuildUsers = 30;
        distributedBuilds = true;
        buildMachines = [
Valentin Reis's avatar
Valentin Reis committed
57
          {
Valentin Reis's avatar
Valentin Reis committed
58
            hostName = "slave-desktop-tunnel";
Valentin Reis's avatar
Valentin Reis committed
59
            maxJobs = 40;
60
            speedFactor = 1;
Valentin Reis's avatar
Valentin Reis committed
61
            sshKey = "/run/id_buildfarm";
Valentin Reis's avatar
Valentin Reis committed
62
            sshUser = "fre";
Valentin Reis's avatar
ci fix    
Valentin Reis committed
63
            systems = ["builtin" "x86_64-linux" "i686-linux"];
Valentin Reis's avatar
Valentin Reis committed
64
            supportedFeatures = [ "nixos-test" "benchmark" "icc" ];
Valentin Reis's avatar
ci fix    
Valentin Reis committed
65
          }
Valentin Reis's avatar
Valentin Reis committed
66
67
68
69
        ];
        extraOptions = "auto-optimise-store = true";
      };

Valentin Reis's avatar
Valentin Reis committed
70
71
72
73
74
75
76
77
      programs.ssh.extraConfig = ''
        Host slave-desktop-tunnel
        HostName localhost
        Port 2210
        User frex
        IdentityFile /run/id_buildfarm
      '';

Valentin Reis's avatar
Valentin Reis committed
78
79
      networking = {
        firewall = {
80
81
          allowedTCPPorts=[ 2210 80 443 8081];
          allowedUDPPorts=[ 2210 80 443 8081];
Valentin Reis's avatar
Valentin Reis committed
82
83
84
85
        };
      };
      services.nginx = {
        enable = true;
86
87
        user = "hydra-queue-runner";
        group= "hydra";
Valentin Reis's avatar
Valentin Reis committed
88
        virtualHosts = {
Valentin Reis's avatar
Valentin Reis committed
89
90
91
92
          "argo.freux.fr" = {
            basicAuth = { argo = "${builtins.readFile ./auth_argo.secret}"; };
            enableACME = true;
            forceSSL = true;
93
94
95
96
              locations."/store".root="/nix";
              locations."/store".extraConfig="autoindex on;";
              locations."/cache".root="/var/lib/hydra";
              locations."/cache".extraConfig="autoindex on;";
Valentin Reis's avatar
Valentin Reis committed
97
              locations."/"= {
Valentin Reis's avatar
Valentin Reis committed
98
                proxyPass="http://127.0.0.1:6080/";
Valentin Reis's avatar
Valentin Reis committed
99
                extraConfig = ''
Valentin Reis's avatar
Valentin Reis committed
100
                  proxy_redirect http://127.0.0.1:6080 https://argo.freux.fr;
Valentin Reis's avatar
Valentin Reis committed
101
102
103
104
105
106
107
108
                  proxy_set_header  Host              $host;
                  proxy_set_header  X-Real-IP         $remote_addr;
                  proxy_set_header  X-Forwarded-For   $proxy_add_x_forwarded_for;
                  proxy_set_header  X-Forwarded-Proto $scheme;
                  proxy_set_header  X-Request-Base    /;
                '';
              };
              locations."/hydra"= {
Valentin Reis's avatar
Valentin Reis committed
109
                proxyPass="http://127.0.0.1:8080/";
Valentin Reis's avatar
Valentin Reis committed
110
                extraConfig = ''
Valentin Reis's avatar
Valentin Reis committed
111
                  proxy_redirect http://127.0.0.1:8080 https://argo.freux.fr/hydra;
Valentin Reis's avatar
Valentin Reis committed
112
113
114
115
116
117
118
119
120
121
122
                  proxy_set_header  Host              $host;
                  proxy_set_header  X-Real-IP         $remote_addr;
                  proxy_set_header  X-Forwarded-For   $proxy_add_x_forwarded_for;
                  proxy_set_header  X-Forwarded-Proto $scheme;
                  proxy_set_header  X-Request-Base    /hydra;
                '';
              };
            };
          };
        };

Valentin Reis's avatar
Valentin Reis committed
123
      services.hydra = {
Valentin Reis's avatar
Valentin Reis committed
124
        useSubstitutes = true;
Valentin Reis's avatar
Valentin Reis committed
125
        enable = true;
Valentin Reis's avatar
Valentin Reis committed
126
        hydraURL = "https://argo.freux.fr/hydra";
127
        listenHost = "127.0.0.1";
Valentin Reis's avatar
Valentin Reis committed
128
129
        notificationSender = "hydra@example.org";
        port = 8080;
Valentin Reis's avatar
Valentin Reis committed
130
        extraConfig = ''
Valentin Reis's avatar
Valentin Reis committed
131
          store_uri = file:///var/lib/hydra/cache?secret-key=/etc/nix/argo.freux.fr/secret
Valentin Reis's avatar
Valentin Reis committed
132
          using_frontend_proxy 1
Valentin Reis's avatar
Valentin Reis committed
133
134
          base_uri argo.freux.fr/hydra
          binary_cache_public_uri argo.freux.fr/cache
Valentin Reis's avatar
Valentin Reis committed
135
          max_output_size = 4294967296
Valentin Reis's avatar
Valentin Reis committed
136
          secret-key=/etc/nix/argo.freux.fr/secret
Valentin Reis's avatar
Valentin Reis committed
137
        '';
Valentin Reis's avatar
Valentin Reis committed
138
139
140
        buildMachinesFiles = [ "/etc/nix/machines" ];
      };

141
142
      environment.systemPackages = [ pkgs.nix-serve ];

Valentin Reis's avatar
Valentin Reis committed
143
144
145
146
147
      services.postgresql = {
        package = pkgs.postgresql94;
        dataDir = "/var/db/postgresql-${config.services.postgresql.package.psqlSchema}";
      };

Valentin Reis's avatar
Valentin Reis committed
148
149
150
151
152
153
154
      systemd.services.hydra-manual-setup = let
        hydraEnv =
          { HYDRA_DBI = config.services.hydra.dbi;
            HYDRA_CONFIG = "/var/lib/hydra/hydra.conf";
            HYDRA_DATA = "/var/lib/hydra";
          };
        in {
Valentin Reis's avatar
Valentin Reis committed
155
156
157
158
159
160
        description = "Create Admin User for Hydra";
        serviceConfig.Type = "oneshot";
        serviceConfig.RemainAfterExit = true;
        wantedBy = [ "multi-user.target" ];
        requires = [ "hydra-init.service" ];
        after = [ "hydra-init.service" ];
Valentin Reis's avatar
Valentin Reis committed
161
162
163
164
165
166
167
168
        environment =  { NIX_REMOTE = "daemon";
                         SSL_CERT_FILE = "/etc/ssl/certs/ca-certificates.crt"; # Remove in 16.03
                         PGPASSFILE = "/var/lib/hydra/pgpass";
                         NIX_REMOTE_SYSTEMS = pkgs.lib.concatStringsSep ":" config.services.hydra.buildMachinesFiles;
                       } // pkgs.lib.optionalAttrs (config.services.hydra.smtpHost != null) {
                         EMAIL_SENDER_TRANSPORT = "SMTP";
                         EMAIL_SENDER_TRANSPORT_host = config.services.hydrasmtpHost;
                       } // hydraEnv // config.services.hydra.extraEnv;
Valentin Reis's avatar
Valentin Reis committed
169
170
171
        script = ''
          if [ ! -e ~hydra/.setup-is-complete ]; then
            # create admin user
Valentin Reis's avatar
Valentin Reis committed
172
173
            /run/current-system/sw/bin/hydra-create-user fre --full-name 'Valentin Reis' --email-address 'fre@freux.fr' --password foobar --role admin
            /run/current-system/sw/bin/hydra-create-user swann --full-name 'Swann Perarnau' --email-address 'swann@anl.gov' --password swannswann --role admin
Valentin Reis's avatar
Valentin Reis committed
174
            # create signing keys
Valentin Reis's avatar
Valentin Reis committed
175
176
177
178
179
            /run/current-system/sw/bin/install -d -m 551 /etc/nix/argo.freux.fr
            /run/current-system/sw/bin/nix-store --generate-binary-cache-key argo.freux.fr /etc/nix/argo.freux.fr/secret /etc/nix/argo.freux.fr/public
            /run/current-system/sw/bin/chown -R hydra:hydra /etc/nix/argo.freux.fr
            /run/current-system/sw/bin/chmod 440 /etc/nix/argo.freux.fr/secret
            /run/current-system/sw/bin/chmod 444 /etc/nix/argo.freux.fr/public
180
            #store
Valentin Reis's avatar
Valentin Reis committed
181
            /run/current-system/sw/bin/install -d -m 776 /var/lib/hydra/cache
182
            /run/current-system/sw/bin/chown -R hydra-queue-runner:hydra /var/lib/hydra/cache
Valentin Reis's avatar
Valentin Reis committed
183
184
185
186
187
            # done
            touch ~hydra/.setup-is-complete
          fi
        '';
      };
Valentin Reis's avatar
Valentin Reis committed
188
189

      services.hound={
Valentin Reis's avatar
Valentin Reis committed
190
191
        enable = true;
        listen = "localhost:6080";
Valentin Reis's avatar
Valentin Reis committed
192
193
194
195
196
197
        config = ''
          {
             "max-concurrent-indexers" : 2,
             "dbpath" : "${config.services.hound.home}/data",
             "repos" : {
                "argopkgs": { "url" : "https://xgitlab.cels.anl.gov/argo/argopkgs.git" },
Valentin Reis's avatar
Valentin Reis committed
198
199
200
201
202
203
204
205
206
207
208
209
                 "nauts": { "url" : "https://xgitlab.cels.anl.gov/argo/nauts.git" },
                 "nrm": { "url" : "https://xgitlab.cels.anl.gov/argo/nrm.git" },
                 "infrastructure": { "url" : "https://xgitlab.cels.anl.gov/argo/infrastructure.git" },
                 "cuttr": { "url" : "https://xgitlab.cels.anl.gov/argo/cuttr.git" },
                 "aml": { "url" : "https://xgitlab.cels.anl.gov/argo/aml.git" },
                 "yggdrasil-integration": { "url" : "https://xgitlab.cels.anl.gov/argo/yggdrasil-integration.git" },
                 "yggdrasil": { "url" : "https://xgitlab.cels.anl.gov/argo/yggdrasil.git" },
                 "libnrm": { "url" : "https://xgitlab.cels.anl.gov/argo/libnrm.git" },
                 "progress-benchmarks": { "url" : "https://xgitlab.cels.anl.gov/argo/progress-benchmarks.git" },
                 "umap": { "url" : "https://xgitlab.cels.anl.gov/argo/umap.git" },
                 "power-bandit": { "url" : "https://xgitlab.cels.anl.gov/argo/power-bandit.git" },
                 "kernel": { "url" : "https://xgitlab.cels.anl.gov/argo/kernel.git" },
210
                 "util-linux": { "url" : "https://xgitlab.cels.anl.gov/argo/util-linux.git" },
211
                 "libmsr": { "url" : "https://github.com/LLNL/libmsr.git" }
Valentin Reis's avatar
Valentin Reis committed
212
213
214
215
             }
          }
        '';
      };
Valentin Reis's avatar
Valentin Reis committed
216
217
      users.extraUsers.root.openssh.authorizedKeys.keys = [ (pkgs.lib.readFile ./keys/id_buildfarm.pub)];
      users.extraUsers.fre.openssh.authorizedKeys.keys = [ (pkgs.lib.readFile ./keys/id_buildfarm.pub)];
Valentin Reis's avatar
Valentin Reis committed
218
     };
Valentin Reis's avatar
Valentin Reis committed
219

Valentin Reis's avatar
Valentin Reis committed
220
221
222
223
224
225
     slave-desktop =
     { ... }:
     {
       deployment.targetEnv = "none";
       deployment.targetHost = "140.221.10.9";

Valentin Reis's avatar
Valentin Reis committed
226
227
        time.timeZone = "America/Chicago";

Valentin Reis's avatar
Valentin Reis committed
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
        deployment.keys."id_buildfarm" = {
          destDir = "/run";
          keyFile = ./id_buildfarm.secret;
          user = "fre";
          group = "users";
          permissions = "600";
        };

        systemd.services.tunnel-hydra= {
          path = [pkgs.autossh];
          enable= true;
          description = "ssh tunnel to hydra";
          after = [];
          wantedBy = [ "multi-user.target" ];
          environment.AUTOSSH_GATETIME="0";
          environment.AUTOSSH_POLL="30";
          serviceConfig = {
            User = "fre";
            Restart = "on-success";
            Type = "simple";
            ExecStart = ''
              ${pkgs.autossh}/bin/autossh -M 0 -N -o "ServerAliveInterval 30" -o "ServerAliveCountMax 3" -T -R 2210:localhost:22 fre@argo.freux.fr -i /run/id_buildfarm
           '';
          };
        };

       require=argomodules;
       environment.argo.known-hosts.enable=true;
       environment.argo.provider-openspace.enable=true;
       environment.argo.root-access.enable=true;

       environment.variables.TERM = "xterm";

       i18n.defaultLocale = "en_US.UTF-8";
       nix.useSandbox = true;
       nix.nrBuildUsers = 30;
       nix.trustedUsers=["root" "fre" ];

       services.ntp.enable = false;
       services.openssh.allowSFTP = false;

       nix.gc = {
         automatic = true;
         dates = "05:15";
         options = ''--max-freed "$((32 * 1024**3 - 1024 * $(df -P -k /nix/store | tail -n 1 | ${pkgs.gawk}/bin/awk '{ print $4 }')))"'';
       };
      services.openssh.enable = true;
      users.extraUsers.root.openssh.authorizedKeys.keys = [ (pkgs.lib.readFile ./keys/id_buildfarm.pub)];
      users.extraUsers.fre.openssh.authorizedKeys.keys = [ (pkgs.lib.readFile ./keys/id_buildfarm.pub)];
      };

Valentin Reis's avatar
Valentin Reis committed
279
   }