aboutsummaryrefslogtreecommitdiff
path: root/nixos
diff options
context:
space:
mode:
authorMartin Fischer <martin@push-f.com>2026-09-30 12:53:10 +0200
committerMartin Fischer <martin@push-f.com>2026-09-30 12:53:10 +0200
commitbc50c5d3c209e5b365755f76d1cf188b665ecd60 (patch)
treeaa784c0c990837982ec3d35385600631aa0a070c /nixos
parenta45df5c11dd40b8f827470ff3e105b01591e0e4f (diff)
tweak(server): add hostname change preSwitchCheck
Diffstat (limited to 'nixos')
-rw-r--r--nixos/profiles/server/default.nix1
-rw-r--r--nixos/profiles/server/detect-hostname-change.nix50
2 files changed, 51 insertions, 0 deletions
diff --git a/nixos/profiles/server/default.nix b/nixos/profiles/server/default.nix
index 07dcd4b..6e744a6 100644
--- a/nixos/profiles/server/default.nix
+++ b/nixos/profiles/server/default.nix
@@ -3,6 +3,7 @@
{
imports = [
../common
+ ./detect-hostname-change.nix
];
services = {
diff --git a/nixos/profiles/server/detect-hostname-change.nix b/nixos/profiles/server/detect-hostname-change.nix
new file mode 100644
index 0000000..c745493
--- /dev/null
+++ b/nixos/profiles/server/detect-hostname-change.nix
@@ -0,0 +1,50 @@
+# Protection against deploying system closures to the wrong host.
+# (copied from https://github.com/nix-community/srvos)
+{
+ config,
+ lib,
+ ...
+}:
+{
+ config = lib.mkIf (config.networking.hostName != "") {
+ system.preSwitchChecks.detectHostnameChange = ''
+ detectHostnameChange() {
+ local actual
+ actual="$(< /proc/sys/kernel/hostname)"
+
+ # Ignore if the system is getting installed
+ # https://github.com/nix-community/nixos-images/blob/2fc023e024c0a5e8e98ae94363dbf2962da10886/nix/installer.nix#L12-L13
+ if [[ ! -e /run/booted-system || "$actual" == "nixos-installer" ]]; then
+ return
+ fi
+
+ desired="${config.networking.hostName}"
+
+ if [[ "$actual" = "$desired" ]]; then
+ return
+ fi
+
+ # Useful for automation
+ if [[ "''${EXPECTED_HOSTNAME:-}" = "$desired" ]]; then
+ return
+ fi
+
+ log() {
+ echo "$*" >&2
+ }
+
+ log "WARNING: machine hostname change detected from '$actual' to '$desired'"
+ log
+ log "Are you deploying on the right host?"
+ log
+ log "Type YES to continue:"
+ read -r reply
+ if [[ $reply != YES ]]; then
+ echo "aborting"
+ exit 1
+ fi
+ }
+ detectHostnameChange
+ '';
+ };
+}