!DBFhtjpqmJNENpLDOv:nixos.org

NixOS systemd

576 Members
NixOS ❤️ systemd158 Servers

Load older messages


SenderMessageTime
1 Mar 2025
@emilazy:matrix.orgemilyyeah, would be cool.14:08:28
@emilazy:matrix.orgemilyI personally don't think that pointy-clicky configuration is a market it makes sense for NixOS to target at all right now but partitioning is indeed uniquely annoying/fiddly14:09:31
@arianvp:matrix.orgArianYeh but if not point clicks at least not imperative 14:12:48
@raitobezarius:matrix.orgraitobezarius
In reply to @emilazy:matrix.org
I personally don't think that pointy-clicky configuration is a market it makes sense for NixOS to target at all right now but partitioning is indeed uniquely annoying/fiddly
I agree but also almost everyone I know starts by using the graphical installer
14:32:55
@raitobezarius:matrix.orgraitobezariuswhich horrifies me14:32:57
@emilazy:matrix.orgemilyyes, I mean it's very appealing14:33:44
@emilazy:matrix.orgemilyI just think it gives a bad impression because as a graphical installer it's not very polished, and as a prelude to the "NixOS experience" it's incredibly misleading14:33:44
@emilazy:matrix.orgemilyit's like we built a really ornate-looking stairs and door with a nice soft doormat but when you open it it falls off the hinges a little and then when you walk inside you immediately end up in a maintenance crawlspace14:34:16
2 Mar 2025
@elvishjerricco:matrix.org@elvishjerricco:matrix.org I just realized... I've long complained that nixos-generate-config unlocks any encrypted file system during stage 1, when that usually only needs to be done for the root FS. But I just realized, we could use the fileSystems.*.encrypted options to determine which drives to unlock in stage 1 based on fsNeededForBoot. Just needs a bit more logic to make a stage 2 crypttab and a pretty simple change to nixos-generate-config 01:06:14
@uep:matrix.orguepwhen that's using LUKS, and the same passphrase is used, it gets cached/reused over multiple devices. Would such a split mean getting prompted twice?01:19:16
@elvishjerricco:matrix.org@elvishjerricco:matrix.org
In reply to @uep:matrix.org
when that's using LUKS, and the same passphrase is used, it gets cached/reused over multiple devices. Would such a split mean getting prompted twice?
Not with systemd initrd because systemd initrd caches the password in the kernel key ring
01:22:17
@uep:matrix.orguepcool, wasn't sure if that would persist from one to the other, that's all. 01:25:16
3 Mar 2025
@bendanm:matrix.orgbendanm joined the room.04:43:22
@mornix:matrix.orgmornix joined the room.04:51:17
4 Mar 2025
@arianvp:matrix.orgArian So when ProtectSystem is set in system.conf then initrd remounts /usr as read-only. I wonder if we should patch that behaviour in pid1 to do the same for /nix/store ? 13:55:29
@arianvp:matrix.orgArian * So when ProtectSystem is set in system.conf then pid1 remounts /usr as read-only. I wonder if we should patch that behaviour in pid1 to do the same for /nix/store ? 13:55:42
@raitobezarius:matrix.orgraitobezarius isn't /nix/store already RO? 13:57:01
@emilazy:matrix.orgemilydon't we already do a fancy bind-mount thing for the store?13:57:30
@emilazy:matrix.orgemilyor are you proposing we use systemd to do it?13:57:36
@arianvp:matrix.orgArian/nix/store is not RO in initrd13:58:27
@arianvp:matrix.orgArianit’s writeable13:58:29
@emilazy:matrix.orgemilyyikes13:58:42
@raitobezarius:matrix.orgraitobezarius no problem: https://gerrit.lix.systems/c/lix/+/2690 13:59:05
@arianvp:matrix.orgArianit’s just /sysroot/nix/store that we remount as read-only13:59:06
@emilazy:matrix.orgemilyand I guess we don't need the fancy bind mount stuff because the daemon isn't running in stage 1 anyway?13:59:07
@emilazy:matrix.orgemilytypo: "Flancher" 😆13:59:42
@raitobezarius:matrix.orgraitobezariusthis is the 2nd time someone told me13:59:50
@raitobezarius:matrix.orgraitobezariusi am fixing it now13:59:51
@raitobezarius:matrix.orgraitobezariusElvish never told me the typo btw13:59:54
@raitobezarius:matrix.orgraitobezariusdone14:00:06

Show newer messages


Back to Room ListRoom Version: 6