muscari: switch bootloader to systemd-boot (UEFI)

Changes:
- boot.loader: generic-extlinux-compatible (BIOS) → systemd-boot (UEFI)
- YC standard-v3 VM is UEFI by default; systemd-boot is the modern
  choice for single-disk cloud VMs (no GRUB complexity)
- Comments updated: nixos-anywhere → nixos-install (in tmux), aligning
  with the documented install procedure in projects/servers/muscari/SETUP.md
- .gitignore: add hosts/*/hardware-configuration.nix as defense-in-depth
  (muscari uses disko and has no hw-config file; this guards future hosts
  from leaking UUIDs/MACs to the public forgejo repo)

Context:
- muscari VM specs: 2 vCPU / 8 GB / 100 GB SSD (was incorrectly documented
  as 4/16 in muscari/README.md; fixed there too)
- Flake builds cleanly:
    nix flake show           → nixosConfigurations.muscari
    hostname                 → "muscari"
    systemd-boot.enable      → true
    fileSystems."/"         → ext4 (disko-derived)
    fileSystems."/boot"     → vfat (disko-derived)

Verified: nix --extra-experimental-features 'nix-command flakes' flake show
and eval .#nixosConfigurations.muscari.config.{networking.hostName,
boot.loader.systemd-boot.enable, fileSystems} all pass.

Session: verify plan
This commit is contained in:
mikl 2026-06-26 02:44:08 +03:00
parent 99b887e97f
commit 5e1b3697c8
2 changed files with 10 additions and 6 deletions

4
.gitignore vendored
View file

@ -22,3 +22,7 @@ devenv.yaml
*.age-key
*age-keys.txt
*age-keys.json
# hardware-configuration per-host (защита от случайного коммита в публичный repo)
# muscari использует disko и не имеет этого файла — это defense-in-depth для будущих хостов
hosts/*/hardware-configuration.nix

View file

@ -1,4 +1,4 @@
# muscari — k3s single-node cluster на YC (Debian 12 → Nix через nixos-anywhere)
# muscari — k3s single-node cluster на YC (Debian 12 → NixOS 25.11 через nixos-install в tmux)
# https://git.iscg.dev/mikl/nix-config
{ config, pkgs, lib, ... }:
@ -20,14 +20,14 @@
];
};
# Bootloader — extlinux (совместимо с YC BIOS boot)
boot.loader.grub.enable = false;
boot.loader.generic-extlinux-compatible.enable = true;
# Bootloader — systemd-boot (UEFI, требуется для YC standard-v3)
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
# fileSystems — определяется через disko (см. disk-config.nix)
# Не задаём явно fileSystems."/" чтобы не конфликтовать с disko
# После nixos-anywhere первая установка может быть 26.05,
# После nixos-install первая установка 25.11,
# потом не трогаем (NixOS convention)
system.stateVersion = "25.11";
}