Raspberry Pi config for all things Internet
github.com
github.com
[1] https://www.jeffgeerling.com/blog/2021/monitor-your-internet...
[2] https://www.jeffgeerling.com/blog/2021/airgradient-diy-air-q...
Just I'm this week, I made an iso for my rpi config, which has everything setup from ssh keys to the services i want to use. All I need to do is flash it and it's good to go. Not to mention that I can easier manage a fleet of this with remote deployment[2].
[2] Nixops, deploy-rs or the --target-host flag in nixos-rebuild
The setup is mostly mirrored from https://sgt.hootr.club/molten-matter/nix-distributed-builds/
Be sure to enable binfmt for whatever architecture your pi uses on your main machine for cross compilation.
For generating the iso I used nixos-generators.
https://github.com/NelsonJeppesen/nix-lifestyle/blob/main/ni...
After the first hump of learning the Nix ecosystem, the rewards on time are great
EDIT: After looking over the repo, I can see how much code would be unneeded over a Nix[os] configuration
That being said, I've been using NixOS on my main system and loving it! I've been through format-and-resetup dance far too many times to understand NixOS is worst system management tool, except all the others.
Are you sure? TBH I don't know if there's a binary cache, but I installed without issue. It was longer than say a Debian install, but can't say it took that long
What timeframe do you need to meet your needs?
> ssh pi4 (nelson@pi4) Password: Last login: Sun Aug 15 10:44:23 2021 from 192.168.86.235 nelson@pi4:~/ > sudo nix-channel --update [sudo] password for nelson: unpacking channels... created 1 symlinks in user environment nelson@pi4:~/ > sudo nixos-rebuild switch
... > copying path '/nix/store/qpd30425yap9y2mhsa4lg8cfid6703cz-glibc-locales-2.33-49' from 'https://cache.nixos.org'... copying path '/nix/store/59mpcrm3ndbg32834038v1c6lzjh9yi7-linux-5.10.52-1.20210805' from 'https://cache.nixos.org'... copying path
ect
On another note, do you have any idea why Pi foundation still recommends 32bit images for Raspbian?
But looks like I was wrong and there is a cache as long as I use aarch64. I'm not sure why Pi foundation recommends 32bit image, but NixOS should be fine imo.
I'm curious to hear more about this - can you explain?
If you have ever reinstalled Windows, you probably had to hunt,download and reconfigure every single piece of software on your system to get it back to previous state. That takes hours and still miss something.
With Linux distributions, things are easier. All software comes from single source and you can back up most config files. But there is still space for error. You can forget to install something, config files can be scattered across multiple locations (/etc, ~, ~/.config etc). If any of this is missed in being backed up or restored, then you have to re-learn the whole process yet again.
With Nix(OS), the whole system state (applications and their configuration) resides in single file (or repo). It is the only thing you ever need to back up or restore. If something changed, configuration.nix is single source of truth to show it. You can go back in time and see what changed, and restore it. If a package is removed from configuration.nix, it also automatically gets uninstalled from system (unlike Ansible). If nVidia driver doesn't agree with kernel update, you're not stuck with black screen until rescue disk is prepared. Most distros solve this problem by extensive testing, which obviously delays updates to end user. On NixOS, you can simply select previous generation from boot menu and be on your merry way. Because of this, NixOS updates fast, and requires practically no maintenance beyond setup. Any time I setup a complex service, I only have to learn it once. The whole process gets automatically scripted when I'm doing it the first time, and I never have to re-learn it.
Its very liberating when you're not worried about your system being unusable. Learning Nix language (which is not pleasant) is a cludge, but right now, I haven't found anything better.
All of that state can be described with nix. So if I wanted to reinstall right now, I'd have the exact same system as before. Naturally you'll have to put in some work to make your system 100% nix, but it's worth it.
That's also why I think it's perfect for projects like this one, people will merely have to copy your config file, change nothing if deploying on the same hardware (except maybe some IP address here and there) and it should all just work:tm:
I don't see how this is different to ansible, you install an OS then run an ansible playbook remotely via SSH to get your Pi/whatever to the state you want.
I have an ansible setup that manages 3 Pis this way, all from one command.
Granted, writing YAML is not fun, but i'd like to see a stronger argument why Nix is worth the effort.
Put another way, if you add a package to your playbook and then remove it, the package is still there on your system until you remove it old fashioned way. With Nix, if something removed from config, it also automatically gets removed from system.
Next and imo biggest benefit of NixOS is generations. Every time you change or update your system, the whole system gets rebuilt and creates a new generation. If kernel update broke your display, you can reboot and select previous entry from boot menu and go about as if update never happened. I'm not aware if Ansible can do that yet.
Last, Nix can let you create isolated islands of package config, where you can have your project dependencies setup without affecting or being affected by system dependencies. Obvious examples are Python and Ruby, but these islands or 'nix shell's as they are called can be used to prepare any combination of languages unlike single language tools like pip or cargo.
I recommend giving Nix a go for any system for few months. Its not the most pleasant learning experience (documentation is crap, to put nicely), but if you manage to climb that hill, the view will probably make you stay.
Good grief.
I think part of the issue may be that because I'm not using Ansible every day, whenever I come back to it there is a bit of context that I need to reload into my brain to get back up to speed... I guess that could be a sign that the tool is too heavy for my use case perhaps.
I have a bunch of provisioning shell scripts that I do seem to find a bit less abstract and easier to manage. In fact I need to use one today to renew my home lab wildcard SSL domain certificate and push it to my various local systems.
1. It can handle up to 650 Mbit if you use firewalling with iptables
2. You only need one (1) interface if you use VLANS.
Is that at 1.5 GHz?
I was surprised by how powerful Pi 4s are. At 2 GHz they'll do cake at gig.
> Due to traffic management demands, speeds are limited to around 350Mbps, so if on fiber or high-speed cable, that's the measurable limit.
https://evenroute.com/iqrouter#:~:text=ensure%20low%20latenc...
If you don't mind doing a little work a Pi 4 will do cake at gig.
TL-R605 by TP-Link is the router I'm using.
I have been trying to extricate my family from Google & Apple ecosystems. This requires various servers. At first, I was going to do something like a rackmount server with KVM, Docker, or similar virtualization. Turns out, the cost of a handful of RasPi4B8Gs (~$75 x n, where n is server per service) is less expensive then running a full server (~$1500+).
Now just to find the right and stable software packages that are relatively smooth transition. :/
I currently have them set up as my DNS & filtering, & DHCPD, working on calDAV, cardDAV, VPN, and file (& bookmarks) synch.
>Annual Subscription
>Annual subscription required.