!PSmBFWNKoXmlQBzUQf:helsinki-systems.de

Stage 1 systemd

80 Members
systemd in NixOs's stage 1, replacing the current bash tooling https://github.com/NixOS/nixpkgs/projects/5125 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
27 Nov 2022
@me:linj.tech@me:linj.tech

Arian: your trick works!

pre-device-command = {
            description = "pre device command";
            wantedBy = [ "cryptsetup.target" ];
            wants = [ "cryptsetup-pre.target" ];
            before = [ "cryptsetup-pre.target" ];
            unitConfig.DefaultDependencies = false;
            # serviceConfig = {
            #   Type = "oneshot";
            #   RemainAfterExit = true;
            # };
            script = ''
              echo pre-device-command-start
              echo pre-device-command-end
            '';
          };
23:01:17
@arianvp:matrix.org@arianvp:matrix.orgGreat 23:01:46
@elvishjerricco:matrix.org@elvishjerricco:matrix.org linj: I'm very curious what you're trying to achieve 23:01:51
@me:linj.tech@me:linj.techemm, what I want is somewhat weird: generate a keyfile on the fly for luks without storing that keyfile in initrd23:03:52
@me:linj.tech@me:linj.techon a vps23:04:23
@me:linj.tech@me:linj.tech another question: the before = [ "" ] does not seem to work: 59:50 localhost systemd[1]: Reached target Local Encrypted Volumes (Pre). is before 59:50 localhost systemd[1]: pre-device-command.service: Deactivated successfully. in journal 23:06:13
@me:linj.tech@me:linj.tech * another question: the before = [ "cryptsetup-pre.target" ] does not seem to work: 59:50 localhost systemd[1]: Reached target Local Encrypted Volumes (Pre). is before 59:50 localhost systemd[1]: pre-device-command.service: Deactivated successfully. in journal 23:06:25
@me:linj.tech@me:linj.tech
In reply to @me:linj.tech
another question: the before = [ "cryptsetup-pre.target" ] does not seem to work: 59:50 localhost systemd[1]: Reached target Local Encrypted Volumes (Pre). is before 59:50 localhost systemd[1]: pre-device-command.service: Deactivated successfully. in journal
oneshot does not change this
23:06:55
@arianvp:matrix.org@arianvp:matrix.orgthere's an easier way to do that I think23:10:25
@arianvp:matrix.org@arianvp:matrix.org pretty sure you can do this with systemd-repart 23:16:51
@arianvp:matrix.org@arianvp:matrix.org (Using /dev/urandom as the keyfile) 23:17:12
@me:linj.tech@me:linj.techmy keyfile has a pre-defined key in it23:18:19
@me:linj.tech@me:linj.technot random23:18:29
@me:linj.tech@me:linj.tech
In reply to @me:linj.tech
oneshot does not change this
well, oneshot does make sure my service is before cryptsetup-pre.target. I confirm it with sleep 10
23:20:40
@me:linj.tech@me:linj.techthanks23:20:53
@me:linj.tech@me:linj.tech

It's weird that my pre-device-command.service and cryptsetup-pre.target stops after finishing running nixos activation script.

from man systemd.special:

this target (cryptsetup-pre.target) is particularly useful to ensure that a service is shut down only after all encrypted block devices are fully stopped.

23:27:01
@me:linj.tech@me:linj.techguess our initrd is not the same as what systemd's manual says23:28:06

Show newer messages


Back to Room ListRoom Version: 6