Providers
Guix System
Install Guix System on a Hetzner server, then deploy it with guix deploy.
(use-modules (chaudron) (chaudron hetzner))hetzner-guix-system runs Guix System on a Hetzner server.
The first run installs it; then it deploys your configuration with
guix deploy whenever it changes.
What you need
On the machine running chaudron:
guix; Guix can be installed on any distribution;sshandssh-keyscan;- a Guix signing key:
guix archive --generate-key.
The configuration
A file whose last expression is an operating-system. Start from
make-hetzner-os, from (gnu machine hetzner), given the server's type: it
sets the bootloader, the file systems and the network for it.
(use-modules (gnu)
(gnu machine hetzner))
(use-service-modules web)
(define %base
(make-hetzner-os "cx23"))
(operating-system
(inherit %base)
(host-name "forge")
(services
(cons* (service nginx-service-type)
(operating-system-user-services %base))))Declaring it
(with-stage "prod"
(define key
(hetzner-ssh-key "me" #:public-key-file "~/.ssh/id_ed25519.pub"))
(define forge
(hetzner-server "forge" #:type "cx23" #:location "fsn1"
#:ssh-keys (list key)))
(hetzner-guix-system "forge"
#:server forge
#:os "forge-os.scm"
#:ssh-key key))| Argument | Default | |
|---|---|---|
#:server | required | a hetzner-server |
#:os | required | the configuration file |
#:ssh-key | required | the hetzner-ssh-key of #:identity |
#:identity | "~/.ssh/id_ed25519" | the private key to reach the server |
#:os and #:identity are relative to the directory chaudron runs from.
The first run
- It boots the server into Hetzner's rescue system.
- It erases the disk and installs a minimal Guix System, reachable over SSH as root.
- It reboots into it, then deploys your configuration with
guix deploy.
If it is interrupted after rebooting, the next run sees that Guix System already runs, and only deploys.
Later runs
It deploys again whenever the configuration file, or the Guix you run, as
given by guix describe, changes. Only the file's content is compared:
changes to the modules or files it uses are not noticed. To deploy them,
edit the file; a comment is enough. Touching it is not.
chaudron: update hetzner-guix-system/forge (configuration)
chaudron: 203.0.113.7: deploying /home/me/infra/forge-os.scm
If the server was just resized, it waits for it to be back before deploying.
On a new server, HTTPS with certbot-service-type works from the first
deployment: nginx starts with a temporary certificate, which certbot then
replaces. examples/guix-system.scm
does just that.
Volumes
Volumes are not mounted for you on Guix System: add a file-system for
their linux-device output.
Removing it
Removing hetzner-guix-system from the program only stops managing the
system: the server is left as it is. Giving it another server replaces it,
installing Guix System there.