ci.nix 10.8 KB
Newer Older
Valentin Reis's avatar
stub ci    
Valentin Reis committed
1
{
Valentin Reis's avatar
ci fix    
Valentin Reis committed
2
  pkgs ? import ../pin.nix {jsonpath=../nixpkgs-18.03.json;}
Valentin Reis's avatar
stub ci    
Valentin Reis committed
3
4
5
6
}:
let
  keys = [ (pkgs.lib.readFile keys/id_rsa_vrg.pub) ];
  argopkgs = import ../pkgs {};
Valentin Reis's avatar
Valentin Reis committed
7
  hydraSrc = builtins.fetchTarball https://github.com/nixos/hydra/archive/master.tar.gz;
Valentin Reis's avatar
Valentin Reis committed
8
  argomodules = import ../modules/module-list.nix;
Valentin Reis's avatar
stub ci    
Valentin Reis committed
9
10
11
12
13
in
  {
    network.description = "argo-ci";
    network.enableRollback = false;

Valentin Reis's avatar
Valentin Reis committed
14
    hydra-tacc =
Valentin Reis's avatar
ci fix    
Valentin Reis committed
15
    { config, ... }:
Valentin Reis's avatar
Valentin Reis committed
16
    {
Valentin Reis's avatar
Valentin Reis committed
17
18
19
20
21
22
23
24
25
26
27
      deployment.targetEnv = "none";
      deployment.targetHost = "argo.freux.fr";

      deployment.keys."id_buildfarm"     =   {
        destDir = "/run";
        keyFile = ./id_buildfarm.secret;
        user = "hydra-queue-runner";
        group = "hydra";
        permissions = "600";
      };

Valentin Reis's avatar
Valentin Reis committed
28
      require=argomodules;
29
      environment.argo.known-hosts.enable=true;
Valentin Reis's avatar
Valentin Reis committed
30
      environment.argo.provider-tacc.enable=true;
31
      environment.argo.root-access.enable=true;
Valentin Reis's avatar
Valentin Reis committed
32
      environment.argo.ssh-config.enable=true;
Valentin Reis's avatar
Valentin Reis committed
33

Valentin Reis's avatar
Valentin Reis committed
34
35
      environment.variables.TERM = "xterm";

36
      imports = [ "${hydraSrc}/hydra-module.nix" ];
Valentin Reis's avatar
Valentin Reis committed
37
38


Valentin Reis's avatar
Valentin Reis committed
39
40
41
42
43
44
45
46
47
48
      i18n.defaultLocale = "en_US.UTF-8";
      services.ntp.enable = false;
      services.openssh.allowSFTP = false;

      assertions = pkgs.lib.singleton {
        assertion = pkgs.system == "x86_64-linux";
        message = "unsupported system ${pkgs.system}";
      };

      nix = {
49
50
        sshServe= { inherit keys; enable=true;};
        package = pkgs.nixUnstable; trustedUsers = [ "hydra" ]; binaryCaches = [ "https://cache.nixos.org" ];
Valentin Reis's avatar
Valentin Reis committed
51
52
53
54
        useChroot = true;
        nrBuildUsers = 30;
        distributedBuilds = true;
        buildMachines = [
Valentin Reis's avatar
Valentin Reis committed
55
          {
Valentin Reis's avatar
Valentin Reis committed
56
            hostName = "slave-desktop-tunnel";
Valentin Reis's avatar
Valentin Reis committed
57
            maxJobs = 40;
58
            speedFactor = 1;
Valentin Reis's avatar
Valentin Reis committed
59
            sshKey = "/run/id_buildfarm";
Valentin Reis's avatar
Valentin Reis committed
60
            sshUser = "fre";
Valentin Reis's avatar
ci fix    
Valentin Reis committed
61
            systems = ["builtin" "x86_64-linux" "i686-linux"];
Valentin Reis's avatar
Valentin Reis committed
62
            supportedFeatures = [ "nixos-test" "benchmark" "icc" ];
Valentin Reis's avatar
ci fix    
Valentin Reis committed
63
          }
Valentin Reis's avatar
Valentin Reis committed
64
65
66
67
        ];
        extraOptions = "auto-optimise-store = true";
      };

Valentin Reis's avatar
Valentin Reis committed
68
69
70
71
72
73
74
75
      programs.ssh.extraConfig = ''
        Host slave-desktop-tunnel
        HostName localhost
        Port 2210
        User frex
        IdentityFile /run/id_buildfarm
      '';

Valentin Reis's avatar
Valentin Reis committed
76
77
      networking = {
        firewall = {
78
79
          allowedTCPPorts=[ 2210 80 443 8081];
          allowedUDPPorts=[ 2210 80 443 8081];
Valentin Reis's avatar
Valentin Reis committed
80
81
82
83
        };
      };
      services.nginx = {
        enable = true;
84
85
        user = "hydra-queue-runner";
        group= "hydra";
Valentin Reis's avatar
Valentin Reis committed
86
        virtualHosts = {
Valentin Reis's avatar
Valentin Reis committed
87
88
89
90
          "argo.freux.fr" = {
            basicAuth = { argo = "${builtins.readFile ./auth_argo.secret}"; };
            enableACME = true;
            forceSSL = true;
91
92
93
94
              locations."/store".root="/nix";
              locations."/store".extraConfig="autoindex on;";
              locations."/cache".root="/var/lib/hydra";
              locations."/cache".extraConfig="autoindex on;";
Valentin Reis's avatar
Valentin Reis committed
95
96
97
              locations."/"= {
                proxyPass="http://localhost:6080/";
                extraConfig = ''
Valentin Reis's avatar
Valentin Reis committed
98
                  proxy_redirect http://127.0.0.1:6080 https://argo.freux.fr;
Valentin Reis's avatar
Valentin Reis committed
99
100
101
102
103
104
105
106
107
108
                  proxy_set_header  Host              $host;
                  proxy_set_header  X-Real-IP         $remote_addr;
                  proxy_set_header  X-Forwarded-For   $proxy_add_x_forwarded_for;
                  proxy_set_header  X-Forwarded-Proto $scheme;
                  proxy_set_header  X-Request-Base    /;
                '';
              };
              locations."/hydra"= {
                proxyPass="http://localhost:8080/";
                extraConfig = ''
Valentin Reis's avatar
Valentin Reis committed
109
                  proxy_redirect http://127.0.0.1:8080 https://argo.freux.fr/hydra;
Valentin Reis's avatar
Valentin Reis committed
110
111
112
113
114
115
116
117
118
119
120
                  proxy_set_header  Host              $host;
                  proxy_set_header  X-Real-IP         $remote_addr;
                  proxy_set_header  X-Forwarded-For   $proxy_add_x_forwarded_for;
                  proxy_set_header  X-Forwarded-Proto $scheme;
                  proxy_set_header  X-Request-Base    /hydra;
                '';
              };
            };
          };
        };

Valentin Reis's avatar
Valentin Reis committed
121
      services.hydra = {
Valentin Reis's avatar
Valentin Reis committed
122
        useSubstitutes = true;
Valentin Reis's avatar
Valentin Reis committed
123
        enable = true;
Valentin Reis's avatar
Valentin Reis committed
124
        hydraURL = "https://argo.freux.fr/hydra";
Valentin Reis's avatar
Valentin Reis committed
125
        listenHost = "localhost";
Valentin Reis's avatar
Valentin Reis committed
126
127
        notificationSender = "hydra@example.org";
        port = 8080;
Valentin Reis's avatar
Valentin Reis committed
128
        extraConfig = ''
Valentin Reis's avatar
Valentin Reis committed
129
          store_uri = file:///var/lib/hydra/cache?secret-key=/etc/nix/argo.freux.fr/secret
Valentin Reis's avatar
Valentin Reis committed
130
          using_frontend_proxy 1
Valentin Reis's avatar
Valentin Reis committed
131
132
          base_uri argo.freux.fr/hydra
          binary_cache_public_uri argo.freux.fr/cache
Valentin Reis's avatar
Valentin Reis committed
133
          max_output_size = 4294967296
Valentin Reis's avatar
Valentin Reis committed
134
          secret-key=/etc/nix/argo.freux.fr/secret
Valentin Reis's avatar
Valentin Reis committed
135
        '';
Valentin Reis's avatar
Valentin Reis committed
136
137
138
        buildMachinesFiles = [ "/etc/nix/machines" ];
      };

139
140
      environment.systemPackages = [ pkgs.nix-serve ];

Valentin Reis's avatar
Valentin Reis committed
141
142
143
144
145
      services.postgresql = {
        package = pkgs.postgresql94;
        dataDir = "/var/db/postgresql-${config.services.postgresql.package.psqlSchema}";
      };

Valentin Reis's avatar
Valentin Reis committed
146
147
148
149
150
151
152
      systemd.services.hydra-manual-setup = let
        hydraEnv =
          { HYDRA_DBI = config.services.hydra.dbi;
            HYDRA_CONFIG = "/var/lib/hydra/hydra.conf";
            HYDRA_DATA = "/var/lib/hydra";
          };
        in {
Valentin Reis's avatar
Valentin Reis committed
153
154
155
156
157
158
        description = "Create Admin User for Hydra";
        serviceConfig.Type = "oneshot";
        serviceConfig.RemainAfterExit = true;
        wantedBy = [ "multi-user.target" ];
        requires = [ "hydra-init.service" ];
        after = [ "hydra-init.service" ];
Valentin Reis's avatar
Valentin Reis committed
159
160
161
162
163
164
165
166
        environment =  { NIX_REMOTE = "daemon";
                         SSL_CERT_FILE = "/etc/ssl/certs/ca-certificates.crt"; # Remove in 16.03
                         PGPASSFILE = "/var/lib/hydra/pgpass";
                         NIX_REMOTE_SYSTEMS = pkgs.lib.concatStringsSep ":" config.services.hydra.buildMachinesFiles;
                       } // pkgs.lib.optionalAttrs (config.services.hydra.smtpHost != null) {
                         EMAIL_SENDER_TRANSPORT = "SMTP";
                         EMAIL_SENDER_TRANSPORT_host = config.services.hydrasmtpHost;
                       } // hydraEnv // config.services.hydra.extraEnv;
Valentin Reis's avatar
Valentin Reis committed
167
168
169
        script = ''
          if [ ! -e ~hydra/.setup-is-complete ]; then
            # create admin user
Valentin Reis's avatar
Valentin Reis committed
170
171
            /run/current-system/sw/bin/hydra-create-user fre --full-name 'Valentin Reis' --email-address 'fre@freux.fr' --password foobar --role admin
            /run/current-system/sw/bin/hydra-create-user swann --full-name 'Swann Perarnau' --email-address 'swann@anl.gov' --password swannswann --role admin
Valentin Reis's avatar
Valentin Reis committed
172
            # create signing keys
Valentin Reis's avatar
Valentin Reis committed
173
174
175
176
177
            /run/current-system/sw/bin/install -d -m 551 /etc/nix/argo.freux.fr
            /run/current-system/sw/bin/nix-store --generate-binary-cache-key argo.freux.fr /etc/nix/argo.freux.fr/secret /etc/nix/argo.freux.fr/public
            /run/current-system/sw/bin/chown -R hydra:hydra /etc/nix/argo.freux.fr
            /run/current-system/sw/bin/chmod 440 /etc/nix/argo.freux.fr/secret
            /run/current-system/sw/bin/chmod 444 /etc/nix/argo.freux.fr/public
178
            #store
Valentin Reis's avatar
Valentin Reis committed
179
            /run/current-system/sw/bin/install -d -m 776 /var/lib/hydra/cache
180
            /run/current-system/sw/bin/chown -R hydra-queue-runner:hydra /var/lib/hydra/cache
Valentin Reis's avatar
Valentin Reis committed
181
182
183
184
185
            # done
            touch ~hydra/.setup-is-complete
          fi
        '';
      };
Valentin Reis's avatar
Valentin Reis committed
186
187

      services.hound={
Valentin Reis's avatar
Valentin Reis committed
188
189
        enable = true;
        listen = "localhost:6080";
Valentin Reis's avatar
Valentin Reis committed
190
191
192
193
194
195
        config = ''
          {
             "max-concurrent-indexers" : 2,
             "dbpath" : "${config.services.hound.home}/data",
             "repos" : {
                "argopkgs": { "url" : "https://xgitlab.cels.anl.gov/argo/argopkgs.git" },
Valentin Reis's avatar
Valentin Reis committed
196
197
198
199
200
201
202
203
204
205
206
207
                 "nauts": { "url" : "https://xgitlab.cels.anl.gov/argo/nauts.git" },
                 "nrm": { "url" : "https://xgitlab.cels.anl.gov/argo/nrm.git" },
                 "infrastructure": { "url" : "https://xgitlab.cels.anl.gov/argo/infrastructure.git" },
                 "cuttr": { "url" : "https://xgitlab.cels.anl.gov/argo/cuttr.git" },
                 "aml": { "url" : "https://xgitlab.cels.anl.gov/argo/aml.git" },
                 "yggdrasil-integration": { "url" : "https://xgitlab.cels.anl.gov/argo/yggdrasil-integration.git" },
                 "yggdrasil": { "url" : "https://xgitlab.cels.anl.gov/argo/yggdrasil.git" },
                 "libnrm": { "url" : "https://xgitlab.cels.anl.gov/argo/libnrm.git" },
                 "progress-benchmarks": { "url" : "https://xgitlab.cels.anl.gov/argo/progress-benchmarks.git" },
                 "umap": { "url" : "https://xgitlab.cels.anl.gov/argo/umap.git" },
                 "power-bandit": { "url" : "https://xgitlab.cels.anl.gov/argo/power-bandit.git" },
                 "kernel": { "url" : "https://xgitlab.cels.anl.gov/argo/kernel.git" },
208
                 "util-linux": { "url" : "https://xgitlab.cels.anl.gov/argo/util-linux.git" },
209
                 "libmsr": { "url" : "https://github.com/LLNL/libmsr.git" }
Valentin Reis's avatar
Valentin Reis committed
210
211
212
213
             }
          }
        '';
      };
Valentin Reis's avatar
Valentin Reis committed
214
215
      users.extraUsers.root.openssh.authorizedKeys.keys = [ (pkgs.lib.readFile ./keys/id_buildfarm.pub)];
      users.extraUsers.fre.openssh.authorizedKeys.keys = [ (pkgs.lib.readFile ./keys/id_buildfarm.pub)];
Valentin Reis's avatar
Valentin Reis committed
216
     };
Valentin Reis's avatar
Valentin Reis committed
217

Valentin Reis's avatar
Valentin Reis committed
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
     slave-desktop =
     { ... }:
     {
       deployment.targetEnv = "none";
       deployment.targetHost = "140.221.10.9";

        deployment.keys."id_buildfarm" = {
          destDir = "/run";
          keyFile = ./id_buildfarm.secret;
          user = "fre";
          group = "users";
          permissions = "600";
        };

        systemd.services.tunnel-hydra= {
          path = [pkgs.autossh];
          enable= true;
          description = "ssh tunnel to hydra";
          after = [];
          wantedBy = [ "multi-user.target" ];
          environment.AUTOSSH_GATETIME="0";
          environment.AUTOSSH_POLL="30";
          serviceConfig = {
            User = "fre";
            Restart = "on-success";
            Type = "simple";
            ExecStart = ''
              ${pkgs.autossh}/bin/autossh -M 0 -N -o "ServerAliveInterval 30" -o "ServerAliveCountMax 3" -T -R 2210:localhost:22 fre@argo.freux.fr -i /run/id_buildfarm
           '';
          };
        };

       require=argomodules;
       environment.argo.known-hosts.enable=true;
       environment.argo.provider-openspace.enable=true;
       environment.argo.root-access.enable=true;

       environment.variables.TERM = "xterm";

       i18n.defaultLocale = "en_US.UTF-8";
       nix.useSandbox = true;
       nix.nrBuildUsers = 30;
       nix.trustedUsers=["root" "fre" ];

       services.ntp.enable = false;
       services.openssh.allowSFTP = false;

       nix.gc = {
         automatic = true;
         dates = "05:15";
         options = ''--max-freed "$((32 * 1024**3 - 1024 * $(df -P -k /nix/store | tail -n 1 | ${pkgs.gawk}/bin/awk '{ print $4 }')))"'';
       };
      services.openssh.enable = true;
      users.extraUsers.root.openssh.authorizedKeys.keys = [ (pkgs.lib.readFile ./keys/id_buildfarm.pub)];
      users.extraUsers.fre.openssh.authorizedKeys.keys = [ (pkgs.lib.readFile ./keys/id_buildfarm.pub)];
      };

Valentin Reis's avatar
Valentin Reis committed
275
   }