<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Posts on Thomas Ieong</title>
        <link>https://ieong.ovh/posts/</link>
        <description>Recent content in Posts on Thomas Ieong</description>
        <generator>Hugo -- gohugo.io</generator>
        <language>en-US</language>
        <copyright>&lt;a href=&#34;https://creativecommons.org/licenses/by-nc/4.0/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CC BY-NC 4.0&lt;/a&gt;</copyright>
        <lastBuildDate>Sat, 17 Feb 2024 00:00:00 +0000</lastBuildDate>
        <atom:link href="https://ieong.ovh/posts/index.xml" rel="self" type="application/rss+xml" />
        
        <item>
            <title>How do you find information about Guix?</title>
            <link>https://ieong.ovh/posts/how-do-you-find-information-about-guix/</link>
            <pubDate>Sat, 17 Feb 2024 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/how-do-you-find-information-about-guix/</guid>
            <description>So you&amp;rsquo;re trying to make some app work on Guix or maybe you have some questions on how to do X or Y, you use google to find what you&amp;rsquo;re looking for but there isn&amp;rsquo;t that much results, not much on stackoverflow either so where are you supposed to look?
Everybody in this community (mostly) hang out in mailing lists or IRC, you can see the archive of each of these in the below links:</description>
            <content type="html"><![CDATA[<p>So you&rsquo;re trying to make some app work on Guix or maybe you have some questions on how to do X or Y, you
use google to find what you&rsquo;re looking for but there isn&rsquo;t that much results, not much on stackoverflow either so
where are you supposed to look?</p>
<p>Everybody in this community (mostly) hang out in mailing lists or IRC, you can see the archive of each of these in the below links:</p>
<ul>
<li><a href="https://lists.gnu.org/archive/html/help-guix/">https://lists.gnu.org/archive/html/help-guix/</a></li>
<li><a href="https://lists.gnu.org/archive/html/guix-devel/">https://lists.gnu.org/archive/html/guix-devel/</a></li>
<li><a href="https://logs.guix.gnu.org/">https://logs.guix.gnu.org/</a></li>
</ul>
<p>I highly recommend that you subscribe to these lists, there is an actual subreddit for Guix but not many people
there.</p>
<p>If you have a bug or try to package some app not yet in guix, first check this site:</p>
<ul>
<li><a href="https://issues.guix.gnu.org/">https://issues.guix.gnu.org/</a></li>
</ul>
<p>Here is an awesome list for Guix that I found not so long ago:</p>
<ul>
<li><a href="https://sr.ht/~lle-bout/awesome-guix/">https://sr.ht/~lle-bout/awesome-guix/</a></li>
</ul>
<p>When I was starting out with this system and had trouble configuring my system to make the wifi, bluetooth works&hellip; I found that the most effective thing to do in this situation was to stalk people involved in the project to lift some parts of their configuration, here is a small list I&rsquo;ve compiled:</p>
<ul>
<li><a href="https://rendaw.gitlab.io/blog/55daefcf49e2.html">https://rendaw.gitlab.io/blog/55daefcf49e2.html</a></li>
<li>Ambrevar</li>
<li>System Crafters</li>
<li>Andrew Tropin</li>
<li><a href="https://git.sr.ht/~efraim/guix-config/tree/master/3900XT.scm">https://git.sr.ht/~efraim/guix-config/tree/master/3900XT.scm</a></li>
<li><a href="https://othacehe.org/building-your-own-channels.html">https://othacehe.org/building-your-own-channels.html</a></li>
<li><a href="https://gitlab.inria.fr/froehly/guix-hpc">https://gitlab.inria.fr/froehly/guix-hpc</a></li>
<li><a href="https://lepiller.eu/fr/">https://lepiller.eu/fr/</a></li>
<li><a href="https://people.bordeaux.inria.fr/lcourtes/">https://people.bordeaux.inria.fr/lcourtes/</a></li>
<li><a href="http://sed.bordeaux.inria.fr/la-bidouille">http://sed.bordeaux.inria.fr/la-bidouille</a></li>
<li><a href="https://gitlab.inria.fr/guix-hpc/guix-kernel">https://gitlab.inria.fr/guix-hpc/guix-kernel</a></li>
<li><a href="https://git.sr.ht/~efraim/guix-config/tree/master/3900XT.scm">https://git.sr.ht/~efraim/guix-config/tree/master/3900XT.scm</a></li>
<li><a href="https://github.com/qbladea/linux-os/blob/master/luhux/operating-system/thinkpad-x230.scm">https://github.com/qbladea/linux-os/blob/master/luhux/operating-system/thinkpad-x230.scm</a></li>
<li><a href="https://git.sr.ht/~raingloom/guix-source/tree/6ae4644984608b7eff7ab54d3a5787c661d85b2e/item/gnu/home-services/xdg.scm">https://git.sr.ht/~raingloom/guix-source/tree/6ae4644984608b7eff7ab54d3a5787c661d85b2e/item/gnu/home-services/xdg.scm</a></li>
<li><a href="https://gitlab.com/jonsger/jonsger-guix/-/tree/master/config">https://gitlab.com/jonsger/jonsger-guix/-/tree/master/config</a></li>
<li><a href="https://framagit.org/tyreunom/system-configuration/-/tree/master/homes">https://framagit.org/tyreunom/system-configuration/-/tree/master/homes</a></li>
<li><a href="https://gitlab.com/pinoaffe/guix_config/-/blob/master/systems/geirskogul.scm">https://gitlab.com/pinoaffe/guix_config/-/blob/master/systems/geirskogul.scm</a></li>
<li><a href="https://github.com/alezost/guix-config">https://github.com/alezost/guix-config</a></li>
<li><a href="https://rednosehacker.com/">https://rednosehacker.com/</a></li>
<li><a href="https://www.futurile.net/2023/04/30/guix-reproducible-dev-environments/">https://www.futurile.net/2023/04/30/guix-reproducible-dev-environments/</a></li>
<li><a href="https://gitlab.com/pjotrp/guix-notes">https://gitlab.com/pjotrp/guix-notes</a></li>
<li><a href="https://git.sr.ht/~bosco/guix/tree/2312dd82e4e35436e038ab0db68fdd559f7ba859/nongnu/packages/linux-vbox.scm">https://git.sr.ht/~bosco/guix/tree/2312dd82e4e35436e038ab0db68fdd559f7ba859/nongnu/packages/linux-vbox.scm</a></li>
<li><a href="https://git.sr.ht/~bosco/guix/tree">https://git.sr.ht/~bosco/guix/tree</a></li>
<li><a href="https://github.com/pmeiyu/guix-config">https://github.com/pmeiyu/guix-config</a></li>
<li><a href="https://github.com/aartaka/guix-config/blob/master/nonfree-desktop.scm">https://github.com/aartaka/guix-config/blob/master/nonfree-desktop.scm</a></li>
<li><a href="https://zenn.dev/saitoyutaka/articles/b0d93353ad2e0b">https://zenn.dev/saitoyutaka/articles/b0d93353ad2e0b</a></li>
<li><a href="https://habr.com/ru/post/436938/">https://habr.com/ru/post/436938/</a></li>
<li><a href="https://www.opennet.ru/docs/RUS/guix/">https://www.opennet.ru/docs/RUS/guix/</a></li>
<li><a href="https://git.sr.ht/~boeg/home/tree/master/.config/guix/system/config.scm">https://git.sr.ht/~boeg/home/tree/master/.config/guix/system/config.scm</a></li>
<li><a href="https://git.sr.ht/~boeg/home/tree/master/item/.config/guix/system/bootstrap.sh">https://git.sr.ht/~boeg/home/tree/master/item/.config/guix/system/bootstrap.sh</a></li>
<li><a href="https://sqrtminusone.xyz/configs/guix/">https://sqrtminusone.xyz/configs/guix/</a></li>
</ul>
<p>Now let say you want to deploy guix in production, where do you find examples?</p>
<ul>
<li><a href="https://git.savannah.gnu.org/cgit/guix/maintenance.git/tree/hydra">https://git.savannah.gnu.org/cgit/guix/maintenance.git/tree/hydra</a></li>
</ul>
<p>You want to make nvidia works? Check out the nonguix channel</p>
<ul>
<li><a href="https://gitlab.com/nonguix/nonguix">https://gitlab.com/nonguix/nonguix</a></li>
</ul>
<p>As of february 2024 this is the PR that makes NVIDIA actually works on my machine <a href="https://gitlab.com/nonguix/nonguix/-/merge_requests/328">https://gitlab.com/nonguix/nonguix/-/merge_requests/328</a></p>
<p>Finally let&rsquo;s not forget the official site and the cookbook</p>
<ul>
<li><a href="https://guix.gnu.org/cookbook/en/guix-cookbook.html">https://guix.gnu.org/cookbook/en/guix-cookbook.html</a></li>
<li><a href="https://guix.gnu.org/en/manual/en/guix.html">https://guix.gnu.org/en/manual/en/guix.html</a></li>
</ul>
<p>Youtube wise last time I checked there wasn&rsquo;t much content about Guix in general, only videos on the topic
were from Andrew Tropin and System Crafters.</p>
]]></content>
        </item>
        
        <item>
            <title>Recipes to make Tor,Burp Suite,Android Studio… works on Guix</title>
            <link>https://ieong.ovh/posts/recipes-to-make-tor-burp-android-works-on-guix/</link>
            <pubDate>Sat, 17 Feb 2024 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/recipes-to-make-tor-burp-android-works-on-guix/</guid>
            <description>Hey quick post on how I managed to get some of these apps running on my machine:
Android Studio guix shell --container --network --emulate-fhs -e $&amp;#39;(list (@@ (gnu packages gcc) gcc) &amp;#34;lib&amp;#34;)&amp;#39; --development ungoogled-chromium nss nss-certs libgccjit alsa-lib bash grep sed file libcxx libxkbfile openjdk fuse gtk gtk+ cups --preserve=&amp;#39;^DISPLAY$&amp;#39; --share=/tmp --preserve=&amp;#39;^DBUS_&amp;#39; --expose=/var/run/dbus --expose=/sys/dev --expose=/sys/devices --expose=/dev/dri --share=/home/user --share=/dev/kvm Then I run the emulator with the following flags, they are needed otherwise it crashes.</description>
            <content type="html"><![CDATA[<p>Hey quick post on how I managed to get some of these apps running on my machine:</p>
<h2 id="android-studio">Android Studio</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>guix shell --container --network --emulate-fhs        -e <span style="color:#e6db74">$&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span>        --development ungoogled-chromium        nss nss-certs libgccjit alsa-lib bash grep sed file        libcxx libxkbfile openjdk fuse gtk gtk+ cups        --preserve<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;^DISPLAY$&#39;</span>        --share<span style="color:#f92672">=</span>/tmp        --preserve<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;^DBUS_&#39;</span> --expose<span style="color:#f92672">=</span>/var/run/dbus        --expose<span style="color:#f92672">=</span>/sys/dev --expose<span style="color:#f92672">=</span>/sys/devices --expose<span style="color:#f92672">=</span>/dev/dri --share<span style="color:#f92672">=</span>/home/user --share<span style="color:#f92672">=</span>/dev/kvm
</span></span></code></pre></div><p>Then I run the emulator with the following flags, they are needed otherwise it crashes.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>user@linux ~/Android/Sdk/emulator <span style="color:#f92672">[</span>env<span style="color:#f92672">]</span>$ ./emulator -avd Pixel_6_Pro_API_33 -feature -Vulkan -writable-system
</span></span></code></pre></div><h2 id="burp-suite">Burp Suite</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span><span style="color:#75715e"># launch this with shell positionned in $HOME/</span>
</span></span><span style="display:flex;"><span>guix shell --container --network --emulate-fhs --preserve<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;DISPLAY|_JAVA.*|DBUS.*|QT.*|SDL.*|XDG.*&#39;</span> --expose<span style="color:#f92672">=</span>/var/run/dbus --expose<span style="color:#f92672">=</span>/run/user/<span style="color:#66d9ef">$(</span>id -u<span style="color:#66d9ef">)</span>  --expose<span style="color:#f92672">=</span>/sys/dev --expose<span style="color:#f92672">=</span>/sys/devices --expose<span style="color:#f92672">=</span>/dev/dri --share<span style="color:#f92672">=</span>/dev/kvm --development ungoogled-chromium --expression<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span> coreutils bash grep sed gcc-toolchain patchelf gtk+ dbus-glib libxt libevent openssl glibc file alsa-lib nss nss-certs cups openjdk gzip tar zlib freetype file fontconfig openssh libxext libx11 libxrender libxtst dbus
</span></span></code></pre></div><p>I think I must have given up on trying to make it work with Guix I don&rsquo;t remember exactly why, I think it had to do with the embedded chromium browser not working fine, so I ended up just using nix IIRC.</p>
<p>NIXPKGS_ALLOW_UNFREE=1 nix profile  install &ndash;impure nixpkgs#burpsuite</p>
<h2 id="bellard-s-textsynth">Bellard&rsquo;s TextSynth</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span> guix shell --check --pure --expression<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span> coreutils bash grep sed gcc-toolchain patchelf gtk+ dbus-glib libxt libevent openssl glibc file alsa-lib libmicrohttpd libjpeg cuda-toolkit@12.3.2 nvidia-driver
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>FIRST_PART<span style="color:#f92672">=</span><span style="color:#66d9ef">$(</span>echo <span style="color:#e6db74">&#34;</span>$LIBRARY_PATH<span style="color:#e6db74">&#34;</span> | cut -d <span style="color:#e6db74">&#34;:&#34;</span> -f1<span style="color:#66d9ef">)</span>
</span></span><span style="display:flex;"><span>SECOND_PART<span style="color:#f92672">=</span><span style="color:#66d9ef">$(</span>echo <span style="color:#e6db74">&#34;</span>$LIBRARY_PATH<span style="color:#e6db74">&#34;</span> | cut -d <span style="color:#e6db74">&#34;:&#34;</span> -f2<span style="color:#66d9ef">)</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>patchelf --set-interpreter $FIRST_PART/ld-linux-x86-64.so.2 ts_server
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libjpeg.so.62 ts_server
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libmicrohttpd.so.12 ts_server
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libstdc++.so.6 ts_server
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libgcc_s.so.1 ts_server
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libcublasLt.so.12  libnc_cuda.so
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libcuda.so.1 libnc_cuda.so
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>./ts_sd --cuda -m sd_v2.1.bin -o out.jpg <span style="color:#e6db74">&#34;an astronaut riding a horse&#34;</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>./ts_sd --cuda -m sd_v2.1.bin -o out.jpg <span style="color:#e6db74">&#34;an astronaut riding a horse&#34;</span> -t bf16
</span></span></code></pre></div><h2 id="tor-browser">Tor Browser</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-shell" data-lang="shell"><span style="display:flex;"><span>cd Browser
</span></span><span style="display:flex;"><span>guix shell --check --pure --expression<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span> coreutils bash grep sed gcc-toolchain patchelf gtk+ dbus-glib libxt libevent openssl glibc file alsa-lib
</span></span><span style="display:flex;"><span>patchelf --set-interpreter $LIBRARY_PATH/ld-linux-x86-64.so.2 firefox.real
</span></span><span style="display:flex;"><span>patchelf --set-interpreter $LIBRARY_PATH/ld-linux-x86-64.so.2 updater
</span></span><span style="display:flex;"><span>patchelf --set-interpreter $LIBRARY_PATH/ld-linux-x86-64.so.2 TorBrowser/Tor/tor
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>LD_LIBRARY_PATH<span style="color:#f92672">=</span>$LIBRARY_PATH ./start-tor-browser
</span></span></code></pre></div><p>See <a href="https://gitlab.com/nonguix/nonguix/-/issues/112">https://gitlab.com/nonguix/nonguix/-/issues/112</a></p>
<h2 id="building-a-kernel">Building a kernel</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-shell" data-lang="shell"><span style="display:flex;"><span>guix shell -D gcc-toolchain ncurses bison bc flex openssl@1.1.1l util-linux make autoconf coreutils sed diffutils bash grep libelf findutils elfutils gawk crypto++ perl gzip kmod
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>Don<span style="color:#960050;background-color:#1e0010">&#39;</span>t forget to make clean <span style="color:#66d9ef">if</span> somethings weird
</span></span></code></pre></div><h2 id="vscodium">VSCodium</h2>
<p><a href="https://gitlab.com/nonguix/nonguix/-/issues/51">https://gitlab.com/nonguix/nonguix/-/issues/51</a></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>guix shell --container --network --emulate-fhs <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     -e <span style="color:#e6db74">$&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --development ungoogled-chromium <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     nss nss-certs libgccjit alsa-lib bash grep sed file <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     libcxx libxkbfile openjdk fuse gtk gtk+ cups <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --preserve<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;^DISPLAY$&#39;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --share<span style="color:#f92672">=</span>/tmp <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --preserve<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;^DBUS_&#39;</span> --expose<span style="color:#f92672">=</span>/var/run/dbus <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --expose<span style="color:#f92672">=</span>/sys/dev --expose<span style="color:#f92672">=</span>/sys/devices --expose<span style="color:#f92672">=</span>/dev/dri
</span></span><span style="display:flex;"><span>./VSCodium-1.78.2.23132.glibc2.17-x86_64.AppImage --appimage-extract-and-run
</span></span></code></pre></div>]]></content>
        </item>
        
        <item>
            <title>Comment lancer OWASP ZAP dans Gitlab avec l&#39;Automation Framework ?</title>
            <link>https://ieong.ovh/posts/zaproxy/</link>
            <pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/zaproxy/</guid>
            <description>ZAP est un scanner de sécurité pour des applications web, on m&amp;rsquo;a chargé de le mettre en place au boulot dans la chaîne d&amp;rsquo;intégration.
Pour des scénarios simples ça se fait assez facilement, mais dès qu&amp;rsquo;on veut utiliser l&amp;rsquo;outil à pleine puissance la documentation est juste manquante.
Là dans notre chaîne on voudrait faire en sorte que ZAP utilise nos tests selenium pour apprendre la structure de notre application, une fois fait ZAP devrait lancer ses scans puis générer un rapport qui sera envoyé par mail, dans notre slack&amp;hellip;</description>
            <content type="html"><![CDATA[<p>ZAP est un scanner de sécurité pour des applications web, on m&rsquo;a chargé de le mettre en place au boulot dans
la chaîne d&rsquo;intégration.</p>
<p>Pour des scénarios simples ça se fait assez facilement, mais dès qu&rsquo;on veut utiliser l&rsquo;outil à pleine puissance
la documentation est juste manquante.</p>
<p>Là dans notre chaîne on voudrait faire en sorte que ZAP utilise nos tests selenium pour apprendre la structure
de notre application, une fois fait ZAP devrait lancer ses scans puis générer un rapport qui sera envoyé par mail, dans notre slack&hellip;</p>
<p>Ça à l&rsquo;air simple sur le papier mais pour gitlab y&rsquo;a pas de template ou quoi faut tout réimplémenter et c&rsquo;est pas simple parce que je me suis heurté à des limitations de gitlab.</p>
<p>Mon premier instinct aurait été d&rsquo;implémenter ZAP dans un job qui ressemblerait à ça:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">zap-vulnerability-test</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">stage</span>: <span style="color:#ae81ff">test</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">when</span>: <span style="color:#ae81ff">manual</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">image</span>: <span style="color:#ae81ff">big-business-image-containing-zap</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">tags</span>:
</span></span><span style="display:flex;"><span>    - <span style="color:#ae81ff">php</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">variables</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">ZAP_PLAN_AUTHORITY</span>: <span style="color:#e6db74">&#34;http://10.X.X.X&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">ZAP_PLAN_AUTHORITY_REPORT</span>: <span style="color:#e6db74">&#34;10.X.X.X&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">parallel</span>: <span style="color:#ae81ff">5</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">services</span>:
</span></span><span style="display:flex;"><span>    - <span style="color:#ae81ff">selenium-standalone/firefox</span>
</span></span><span style="display:flex;"><span>    - <span style="color:#ae81ff">postgresql</span>
</span></span><span style="display:flex;"><span>    - <span style="color:#f92672">name</span>: <span style="color:#ae81ff">ghcr.io/zaproxy/zaproxy:2.14.0</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">alias</span>: <span style="color:#ae81ff">zap</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">command</span>: [
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;zap.sh&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;-cmd&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;-silent&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;-host&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;0.0.0.0&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;-port&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;8080&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;-configfile&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;config-zap&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;-autorun&#34;</span>,
</span></span><span style="display:flex;"><span>        <span style="color:#e6db74">&#34;plan.yml&#34;</span>
</span></span><span style="display:flex;"><span>      ]
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">script</span>:
</span></span><span style="display:flex;"><span>    - <span style="color:#75715e"># lancer votre commande pour les tests selenium</span>
</span></span><span style="display:flex;"><span>    - <span style="color:#75715e"># Une fois que tous les tests sont passé signaler à ZAP qu&#39;il peut lancer les tests</span>
</span></span></code></pre></div><p>Et là je suis bloqué parce que vu qu&rsquo;on a plein de tests selenium, je les fait tourner en parallèle, je peux
pas utiliser le keyword after_script pour dire que ok tous les tests sont passés, ça marche que pour chaque groupe individuel de test alors qu&rsquo;on veut que ZAP continue son travail après que l&rsquo;intégralité des tests soit passé.</p>
<p>Et il est hors de question de lancer les 300 tests dans un seul job donc je vois pas trop de solution à part
ne pas utiliser ZAP en tant que service mais plutot le déployer dans un environnement dédié.</p>
<p>J&rsquo;ai envoyé toute une série de mails <a href="https://groups.google.com/g/zaproxy-users/c/TKe1_OrsqOU">https://groups.google.com/g/zaproxy-users/c/TKe1_OrsqOU</a> qui reprend tout ça plus en détail mais pour l&rsquo;instant pas de réponse et toujours aucun exemple :(</p>
<p>N&rsquo;hésitez pas à me contacter si vous avez déjà eus affaire à ce genre de cas d&rsquo;utilisation.</p>
]]></content>
        </item>
        
        <item>
            <title>[UPDATED] Guix on Vultr</title>
            <link>https://ieong.ovh/posts/guix-vultr/</link>
            <pubDate>Mon, 05 Feb 2024 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/guix-vultr/</guid>
            <description>Hey there,
Quick post to report back on my experiment with guix on a Vultr VPS.
There are 2 options to get a Guix system running:
Custom ISO From your Vultr panel you need to add a custom iso, simply points it toward the guix installer iso.
Then on your VPS go to server details -&amp;gt; and look for isos, attach your iso.
Now this is all good if you want to do things manually but what about something more automatable?</description>
            <content type="html"><![CDATA[<p>Hey there,</p>
<p>Quick post to report back on my experiment with guix on a Vultr VPS.</p>
<p>There are 2 options to get a Guix system running:</p>
<h2 id="custom-iso">Custom ISO</h2>
<p>From your Vultr panel you need to add a custom iso, simply points it
toward the guix installer <a href="https://ftpmirror.gnu.org/gnu/guix/guix-system-install-1.4.0.x86_64-linux.iso">iso</a>.</p>
<p>Then on your VPS go to server details -&gt; and look for isos, attach your iso.</p>
<p>Now this is all good if you want to do things manually but what about something
more automatable?</p>
<h2 id="vultr-snapshot-and-guix-images">Vultr snapshot and guix images</h2>
<p>Fortunately Vultr allows you to bring in your own snapshots.</p>
<p>As of 2024 Guix does not provide an equivalent of Preseed/Kickstart or answers file
so that&rsquo;s why we&rsquo;re not going to make an iso using that feature.</p>
<p>The only way for you to make a pre-made system is via the <code>guix system image</code> api.</p>
<p>The workflow is like this:</p>
<ol>
<li>
<p>Generate an image with the api, in our case we will need to generate an efi-raw image
as the vultr snapshot feature only accept those, which is a shame as they do take more space
than qcow2</p>
</li>
<li>
<p>Upload that image to a bucket on S3 (scaleway, aws&hellip;)</p>
</li>
<li>
<p>Download that image on Vultr</p>
</li>
<li>
<p>When you deploy a news vps look for snapshot, and simply choose the snapshot you downloaded, it will restart
with your snapshot.</p>
</li>
<li>
<p>Resize the partition and the filesystem of the snapshot to match with the HDD/SSD storage volume provided
by vultr.</p>
</li>
<li>
<p>Create a swapfile.</p>
</li>
<li>
<p>Recreate the /etc/guix/acl file, if this file is missing any guix pull or guix install command will
try to build everything instead of using substitutes, I do not know why this is happening so please
feel free to ping me.</p>
<p>For now this is easily fixed with a guix archive command and then a reconfigure.</p>
</li>
<li>
<p>As a bonus we will explore the setup of an nginx server with tls support.</p>
</li>
</ol>
<h3 id="creating-the-image">Creating the image</h3>
<p>Here is a sample os.scm:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-scheme" data-lang="scheme"><span style="display:flex;"><span>(<span style="color:#a6e22e">use-modules</span> (<span style="color:#a6e22e">gnu</span>))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>(<span style="color:#a6e22e">use-service-modules</span> networking ssh admin virtualization sysctl web mcron certbot)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>(<span style="color:#a6e22e">use-package-modules</span> bootloaders ssh certs tls python linux disk)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>(<span style="color:#66d9ef">define </span>garbage-collector-job
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;; Collect garbage 5 minutes after midnight every day.</span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;; The job&#39;s action is a shell command.</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">#</span>~(<span style="color:#a6e22e">job</span> <span style="color:#e6db74">&#34;5 0 * * *&#34;</span>            <span style="color:#75715e">;Vixie cron syntax</span>
</span></span><span style="display:flex;"><span>       <span style="color:#e6db74">&#34;guix gc -F 1G&#34;</span>))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>(<span style="color:#66d9ef">define </span>%web-root
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">with-imported-modules</span> <span style="color:#f92672">&#39;</span>((<span style="color:#a6e22e">guix</span> build utils))
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">#</span>~(<span style="color:#a6e22e">begin</span>
</span></span><span style="display:flex;"><span>      (<span style="color:#a6e22e">use-modules</span> (<span style="color:#a6e22e">guix</span> build utils))
</span></span><span style="display:flex;"><span>      (<span style="color:#a6e22e">mkdir-p</span> <span style="color:#e6db74">&#34;/srv/http/YOUR-SITE&#34;</span>)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>      (call-with-output-file <span style="color:#e6db74">&#34;/srv/http/YOUR-SITE/index.html&#34;</span>
</span></span><span style="display:flex;"><span>        (<span style="color:#66d9ef">lambda </span>(<span style="color:#a6e22e">port</span>)
</span></span><span style="display:flex;"><span>          (display <span style="color:#e6db74">&#34;\
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&lt;!DOCTYPE html&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&lt;html&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  &lt;head&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    &lt;title&gt;Welcome to nginx!&lt;/title&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    &lt;style&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">     html { color-scheme: light dark; }
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">     body { width: 35em; margin: 0 auto;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">       font-family: Tahoma, Verdana, Arial, sans-serif; }
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    &lt;/style&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  &lt;/head&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  &lt;body&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    &lt;h1&gt;Welcome to nginx!&lt;/h1&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    &lt;p&gt;If you see this page, the nginx web server is successfully installed and
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      working. Further configuration is required.&lt;/p&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    &lt;p&gt;For online documentation and support please refer to
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      &lt;a href=&#39;http://nginx.org/&#39;&gt;nginx.org&lt;/a&gt;.&lt;br/&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      Commercial support is available at
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      &lt;a href=&#39;http://nginx.com/&#39;&gt;nginx.com&lt;/a&gt;.&lt;/p&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    &lt;p&gt;&lt;em&gt;Thank you for using nginx.&lt;/em&gt;&lt;/p&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  &lt;/body&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&lt;/html&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&#34;</span> port))))))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>(<span style="color:#a6e22e">operating-system</span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">bootloader</span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">bootloader-configuration</span>
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">bootloader</span> grub-efi-bootloader)
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">targets</span> (list <span style="color:#e6db74">&#34;/boot/efi&#34;</span>))
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; It is very important that terminal-outputs and inputs are set to serial.</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; I spent a couple hours trying to debug something that made syslogd using 100% cpu.</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; At first I noticed that too many failed attempts when sshing into the box caused a hang.</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; Then when I logged into the box via a kvm console I noticed syslog taking all the cpu.</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; To find out why I straced the process and discovered that it was trying to write</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; &#34;max failed attempts blabla&#34; to /dev/console except that it couldnt it was full of I/O</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; exceptions and syslog would try indefinitely to write to /dev/console.</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; I also had logs about agetty complaining about ttyS0 not being a real device or something.</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; So that&#39;s what pointed me towards the GRUB terminal outputs and input config and after</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; a bit of fiddling I found a config that worked.</span>
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">terminal-outputs</span> <span style="color:#f92672">&#39;</span>(serial))
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">terminal-inputs</span> <span style="color:#f92672">&#39;</span>(serial))
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">serial-unit</span> <span style="color:#ae81ff">0</span>)
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">serial-speed</span> <span style="color:#ae81ff">115200</span>)))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">host-name</span> <span style="color:#e6db74">&#34;web&#34;</span>)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">sudoers-file</span> (<span style="color:#a6e22e">plain-file</span> <span style="color:#e6db74">&#34;sudoers&#34;</span> <span style="color:#e6db74">&#34;\
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74"> root ALL=(ALL) ALL
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74"> %wheel ALL=(ALL) NOPASSWD: ALL
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74"> &#34;</span>))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">timezone</span> <span style="color:#e6db74">&#34;Etc/UTC&#34;</span>)
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">locale</span> <span style="color:#e6db74">&#34;en_US.utf8&#34;</span>)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">swap-devices</span> (list (<span style="color:#a6e22e">swap-space</span>
</span></span><span style="display:flex;"><span>                    (<span style="color:#a6e22e">target</span> <span style="color:#e6db74">&#34;/swapfile&#34;</span>))))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">file-systems</span> (<span style="color:#a6e22e">cons*</span>
</span></span><span style="display:flex;"><span>              (<span style="color:#a6e22e">file-system</span>
</span></span><span style="display:flex;"><span>               (<span style="color:#a6e22e">mount-point</span> <span style="color:#e6db74">&#34;/boot&#34;</span>)
</span></span><span style="display:flex;"><span>               (<span style="color:#a6e22e">type</span> <span style="color:#e6db74">&#34;vfat&#34;</span>)
</span></span><span style="display:flex;"><span>               (<span style="color:#a6e22e">device</span> <span style="color:#e6db74">&#34;/dev/vda1&#34;</span>))
</span></span><span style="display:flex;"><span>              (<span style="color:#a6e22e">file-system</span>
</span></span><span style="display:flex;"><span>               (<span style="color:#a6e22e">mount-point</span> <span style="color:#e6db74">&#34;/&#34;</span>)
</span></span><span style="display:flex;"><span>               (<span style="color:#a6e22e">device</span> <span style="color:#e6db74">&#34;/dev/vda2&#34;</span>)
</span></span><span style="display:flex;"><span>               (<span style="color:#a6e22e">type</span> <span style="color:#e6db74">&#34;ext4&#34;</span>))
</span></span><span style="display:flex;"><span>              %base-file-systems))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">users</span> (<span style="color:#a6e22e">cons*</span>
</span></span><span style="display:flex;"><span>       (<span style="color:#a6e22e">user-account</span>
</span></span><span style="display:flex;"><span>        (<span style="color:#a6e22e">name</span> <span style="color:#e6db74">&#34;YOUR-USER&#34;</span>)
</span></span><span style="display:flex;"><span>        (<span style="color:#a6e22e">comment</span> <span style="color:#e6db74">&#34;guix user&#34;</span>)
</span></span><span style="display:flex;"><span>        (<span style="color:#a6e22e">group</span> <span style="color:#e6db74">&#34;users&#34;</span>)
</span></span><span style="display:flex;"><span>        (<span style="color:#a6e22e">supplementary-groups</span> (<span style="color:#66d9ef">quote </span>(<span style="color:#e6db74">&#34;wheel&#34;</span>)))
</span></span><span style="display:flex;"><span>        (<span style="color:#a6e22e">home-directory</span> <span style="color:#e6db74">&#34;/home/YOUR-USER&#34;</span>))
</span></span><span style="display:flex;"><span>       %base-user-accounts))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">packages</span> (<span style="color:#a6e22e">cons*</span> nss-certs gnutls python strace parted %base-packages))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span> (<span style="color:#a6e22e">services</span> (append (<span style="color:#a6e22e">list</span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">service</span> dhcp-client-service-type)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">service</span> unattended-upgrade-service-type)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">service</span> ntp-service-type)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">simple-service</span> <span style="color:#e6db74">&#39;make-web-root</span>
</span></span><span style="display:flex;"><span>                                  activation-service-type
</span></span><span style="display:flex;"><span>                                  %web-root)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">simple-service</span> <span style="color:#e6db74">&#39;my-cron-jobs</span>
</span></span><span style="display:flex;"><span>                                  mcron-service-type
</span></span><span style="display:flex;"><span>                                  (list garbage-collector-job))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">service</span> nginx-service-type
</span></span><span style="display:flex;"><span>                           (<span style="color:#a6e22e">nginx-configuration</span>
</span></span><span style="display:flex;"><span>                            (<span style="color:#a6e22e">server-blocks</span>
</span></span><span style="display:flex;"><span>                             (list (<span style="color:#a6e22e">nginx-server-configuration</span>
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">listen</span> <span style="color:#f92672">&#39;</span>(<span style="color:#e6db74">&#34;443 ssl&#34;</span>))
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">server-name</span> <span style="color:#f92672">&#39;</span>(<span style="color:#e6db74">&#34;YOUR-SITE&#34;</span>))
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">ssl-certificate</span>
</span></span><span style="display:flex;"><span>                                     <span style="color:#e6db74">&#34;/etc/certs/YOUR-SITE/fullchain.pem&#34;</span>)
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">ssl-certificate-key</span>
</span></span><span style="display:flex;"><span>                                     <span style="color:#e6db74">&#34;/etc/certs/YOUR-SITE/privkey.pem&#34;</span>)
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">root</span> <span style="color:#e6db74">&#34;/srv/http/YOUR-SITE&#34;</span>))))))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">service</span> certbot-service-type
</span></span><span style="display:flex;"><span>                           (<span style="color:#a6e22e">certbot-configuration</span>
</span></span><span style="display:flex;"><span>                            <span style="color:#75715e">;; (server &#34;https://acme-staging-v02.api.letsencrypt.org/directory&#34;)</span>
</span></span><span style="display:flex;"><span>                            (<span style="color:#a6e22e">email</span> <span style="color:#e6db74">&#34;YOUR-EMAIL&#34;</span>)
</span></span><span style="display:flex;"><span>                            (<span style="color:#a6e22e">certificates</span>
</span></span><span style="display:flex;"><span>                             (<span style="color:#a6e22e">list</span>
</span></span><span style="display:flex;"><span>                              (<span style="color:#a6e22e">certificate-configuration</span>
</span></span><span style="display:flex;"><span>                               (<span style="color:#a6e22e">domains</span> <span style="color:#f92672">&#39;</span>(<span style="color:#e6db74">&#34;YOUR-DOMAIN&#34;</span>)))))))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">service</span> openssh-service-type
</span></span><span style="display:flex;"><span>                           (<span style="color:#a6e22e">openssh-configuration</span>
</span></span><span style="display:flex;"><span>                            (<span style="color:#a6e22e">openssh</span> openssh-sans-x)
</span></span><span style="display:flex;"><span>                            (<span style="color:#a6e22e">permit-root-login</span> <span style="color:#66d9ef">#f</span>)
</span></span><span style="display:flex;"><span>                            (<span style="color:#a6e22e">password-authentication?</span> <span style="color:#66d9ef">#f</span>)
</span></span><span style="display:flex;"><span>                            (<span style="color:#a6e22e">authorized-keys</span> <span style="color:#f92672">`</span>((<span style="color:#e6db74">&#34;YOUR-USER&#34;</span> <span style="color:#f92672">,</span>(<span style="color:#a6e22e">plain-file</span> <span style="color:#e6db74">&#34;YOUR-USER.pub&#34;</span> <span style="color:#e6db74">&#34;\
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">YOUR-PUBKEY
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&#34;</span>)))))))
</span></span><span style="display:flex;"><span>                 %base-services)))
</span></span></code></pre></div><p>Don&rsquo;t forget to replace these values:</p>
<ul>
<li>YOUR-USER</li>
<li>YOUR-PUBKEY</li>
<li>YOUR-SITE</li>
<li>YOUR-EMAIL</li>
<li>YOUR-DOMAIN</li>
</ul>
<p>Here is a sample script to create an image from scratch:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span><span style="color:#75715e">#!/usr/bin/env bash
</span></span></span><span style="display:flex;"><span><span style="color:#75715e"></span>new_name<span style="color:#f92672">=</span>$1
</span></span><span style="display:flex;"><span>image<span style="color:#f92672">=</span><span style="color:#66d9ef">$(</span>guix system image --image-type<span style="color:#f92672">=</span>efi-raw --image-size<span style="color:#f92672">=</span><span style="color:#ae81ff">4831838208</span> --save-provenance os.scm<span style="color:#66d9ef">)</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>cp <span style="color:#e6db74">&#34;</span>$image<span style="color:#e6db74">&#34;</span> .
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>image_name<span style="color:#f92672">=</span><span style="color:#66d9ef">$(</span>basename <span style="color:#e6db74">&#34;</span>$image<span style="color:#e6db74">&#34;</span><span style="color:#66d9ef">)</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>chmod +w <span style="color:#e6db74">&#34;</span>$image_name<span style="color:#e6db74">&#34;</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mv <span style="color:#e6db74">&#34;</span>$image_name<span style="color:#e6db74">&#34;</span> <span style="color:#e6db74">&#34;</span>$new_name<span style="color:#e6db74">&#34;</span>
</span></span></code></pre></div><p>Copy it somewhere and name it build-images, make it executable and then invoke it like this:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>./build-images my-awesome-vultr-snapshot
</span></span></code></pre></div><p>The first parameter is a human readable name of the snapshot because by default guix output the image
it created into the store and that one has a hash as a name.</p>
<p>You&rsquo;ll notice that the image size is roughly around 4.5Gb , this is because the filesystem and partition
will be resized later as mentionned earlier.</p>
<p>&ndash;save-provenance is there so that you can find the os.scm that was used to create the snapshot in /run/current-system/configuration.scm on the running machine.</p>
<h3 id="upload-the-image">Upload the image</h3>
<p>I chose scaleway because they offer ~70gb for free in object storage.</p>
<p>You can do everything by the gui or the cli(recommended for gb uploads) so not much to say there, just don&rsquo;t forget to configure the visibility of the object to public or generate a temporary link to share with vultr.</p>
<h3 id="download-from-vultr">Download from vultr</h3>
<p>Products -&gt; Orchestration -&gt; Snapshots -&gt; Add Snapshot -&gt; Upload snapshot from remote machine</p>
<p>Do not forget to tick the UEFI box.</p>
<p>Then:</p>
<p>Products -&gt; Compute -&gt; Deploy new instance -&gt; At the server image section choose your snapshot.</p>
<h3 id="resize-the-partition-and-the-filesystem">Resize the partition and the filesystem</h3>
<p>You should be able to ssh into the machine, once you&rsquo;re in you&rsquo;ll just need to resize the partition
with parted and the filesystem with resize2fs.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span><span style="color:#75715e"># https://bugs.launchpad.net/ubuntu/+source/parted/+bug/1270203</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># I tried to get a command that woud launch without prompting but alas :(</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Just follow the prompt, say fix and answer 2 then 100%</span>
</span></span><span style="display:flex;"><span>sudo parted  --fix -a opt -m /dev/vda ---pretend-input-tty unit % resizepart <span style="color:#ae81ff">2</span>
</span></span><span style="display:flex;"><span>sudo echo -e <span style="color:#e6db74">&#34;yes\n100%&#34;</span> | sudo parted --fix -a opt -m /dev/vda ---pretend-input-tty unit % resizepart <span style="color:#ae81ff">2</span>
</span></span><span style="display:flex;"><span>sudo resize2fs /dev/vda2
</span></span></code></pre></div><p>A resize filesystem service was discussed on the mailing list <a href="https://www.mail-archive.com/help-guix@gnu.org/msg17088.html">https://www.mail-archive.com/help-guix@gnu.org/msg17088.html</a> but nothing merged yet.</p>
<p>If you want to automate this kind of thing in the future you basically have 2 options:</p>
<ul>
<li>Delegate this to an external tool such as Terraform, Pulumi or Ansible&hellip;</li>
<li>Write custom code in your os.scm that will take care of that, typically this will be implemented
as a one-time service, you can use the link I posted earlier for an example.</li>
</ul>
<h3 id="create-a-swapfile">Create a swapfile</h3>
<p>We&rsquo;ll create a swap file here, but you can use a partition aswell.</p>
<p>It is not enough to have this snippet in your code:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span><span style="color:#f92672">(</span>swap-devices <span style="color:#f92672">(</span>list <span style="color:#f92672">(</span>swap-space
</span></span><span style="display:flex;"><span>                 <span style="color:#f92672">(</span>target <span style="color:#e6db74">&#34;/swapfile&#34;</span><span style="color:#f92672">))))</span>
</span></span></code></pre></div><p>You really need to create the file with the following commands:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>sudo truncate -s <span style="color:#ae81ff">0</span> /swapfile
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Change the amount of swap according to your requirements</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># I picked 512Mb because on the vultr machine I have it has 1gb of ram.</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># But you can certainly do much better, there is a plethora of literature</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># concerning the optimal size of a swap file.</span>
</span></span><span style="display:flex;"><span>sudo fallocate -l 512M /swapfile
</span></span><span style="display:flex;"><span>sudo chmod <span style="color:#ae81ff">0600</span> /swapfile
</span></span><span style="display:flex;"><span>sudo mkswap /swapfile
</span></span></code></pre></div><p>And then start the swap service or reboot.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>sudo herd start swap-/swapfile
</span></span></code></pre></div><p>Again you can write custom code to automate this or use an external tool.</p>
<h3 id="making-substitutes-work-again">Making substitutes work again</h3>
<p>I noticed that any guix pull or install would throw with this warning:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>substitute: guix substitute: warning: ACL <span style="color:#66d9ef">for</span> archive imports seems to be uninitialized, substitutes may be unavailable
</span></span></code></pre></div><p>I have no idea why but the /etc/guix/acl file doesn&rsquo;t get created when you restore the snapshot, this file
is necessary otherwise you won&rsquo;t download packages and build everything from scratch.</p>
<p>The workaround is simple just use the guix archive command to recreate that file and then reconfigure the system.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>sudo guix archive --authorize &lt; /run/current-system/profile/share/guix/berlin.guix.gnu.org.pub
</span></span><span style="display:flex;"><span>sudo guix system reconfigure /run/current-system/configuration.scm
</span></span></code></pre></div><p>The reconfigure will make sure that you have the acl with the keys you defined in your os.scm or the default ones.</p>
<h3 id="deploying-an-nginx-site-with-tls-support">Deploying an nginx site with tls support</h3>
<p>In 2023 nginx and certbot didn&rsquo;t play nice together and you first needed to reconfigure once with only the
certbot service defined to get the certificates and a second time with the actual nginx service.</p>
<p>This was needed because if nginx started without a path to a certificate file it would just error out.</p>
<p>Now this has been fixed and you can have the 2 services at the same time from the get go, basically certbot will generate a self signed certificate for nginx to use so that it doesn&rsquo;t complain about the missing certificate and then the cronjob that run certbot every hour will try to get a new one from let&rsquo;s encrypt.</p>
<p>If you do not want to wait for the cronjob you can force the renewal with this:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>sudo herd start renew-certbot-certificates
</span></span></code></pre></div><p>Of course be sure to have pointed an A record to your VPS, if anything fails you&rsquo;ll get the logs in /var/log/letsencrypt</p>
<p>Finally if you want to know when the next certbot command will be run you can check with:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>sudo herd schedule mcron
</span></span></code></pre></div><p>Pro-tip to know which action you can use on a service use:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>sudo herd doc mcron list-actions
</span></span></code></pre></div><h3 id="conclusion">Conclusion</h3>
<p>You should have a guix system up and running.</p>
]]></content>
        </item>
        
        <item>
            <title>CCNA</title>
            <link>https://ieong.ovh/posts/ccna-experience/</link>
            <pubDate>Sun, 05 Feb 2023 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/ccna-experience/</guid>
            <description>Random thoughts about the CCNA.
I passed it at the beginning of this month, the test center was quite shit, they gave me a marker that was end of life so I could not write on that tiny board for long. And to add insult to injury they gave me a qwerty which meant I had to type very slowly.
Now the exam in itself, I feel it was ok, the labs weren&amp;rsquo;t hard they were quite broad but that&amp;rsquo;s all, I don&amp;rsquo;t know if you had to write mem?</description>
            <content type="html"><![CDATA[<p>Random thoughts about the CCNA.</p>
<p>I passed it at the beginning of this month, the test center was quite shit, they gave
me a marker that was end of life so I could not write on that tiny board for long.
And to add insult to injury they gave me a qwerty which meant I had to type very slowly.</p>
<p>Now the exam in itself, I feel it was ok, the labs weren&rsquo;t hard they were quite broad
but that&rsquo;s all, I don&rsquo;t know if you had to <code>write mem</code>? I only did it 2 out of 3 labs.</p>
<p>Lot of memorization concerning proprietary protocols that I am certainly not going to use
like EIGRP, PaGP or the cisco marketing bullshit with meraki, I got 2-3 questions on that
and they weren&rsquo;t technical just marketing.</p>
<p>I ended up speedrunning the exam I had 2:30 to do the exam, I only need 1:30, I thought
I had failed but there you go.</p>
<h2 id="the-value-of-certs">The value of certs</h2>
<p>Now I don&rsquo;t think certs bring that much on the table, and I don&rsquo;t think it&quot;s limited to certs
in IT but in general.</p>
<p>It really feels like it&rsquo;s a business, with all those courses on youtube,udemy, paid exams&hellip;</p>
<p>Sure you do have to put in some work to get the damn paper, but it&rsquo;s not really
that hard, like I feel you could just study like a monkey the topic exams, ace the exam and still
be not very useful in a real situation where you actually have to put into practice
what you have supposedly learnt.</p>
<p>But hey if this can get me a job or atleast a foot in the door I&rsquo;m not gonna complain
I don&rsquo;t actually have any formal education in IT, so let&rsquo;s see how this will turn out.</p>
<p>I think I will try to pass the AWS devops and stop there with the certs while they don&rsquo;t cost
much compared to a year in college in the US it&rsquo;s still 300$.</p>
]]></content>
        </item>
        
        <item>
            <title>How do you deal with your favorite package not being in Guix?</title>
            <link>https://ieong.ovh/posts/how-do-you-deal-with-your-favorite-package-not-being-in-guix/</link>
            <pubDate>Sat, 17 Feb 2024 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/how-do-you-deal-with-your-favorite-package-not-being-in-guix/</guid>
            <description>You have 2 options:
Package the missing app yourself and contribute it back to upstream. Give up and just use Nix, the language package manager or just use guix shell and patchelf your way through. Option 1 is fairly involved, depending on how big the dependency tree of your app is you&amp;rsquo;re probably not going to want to do this even if you manage to package the app and want to contribute it back you&amp;rsquo;ll have to get used to the mail workflow, how to use git send-email, patch guidelines&amp;hellip; not that it&amp;rsquo;s particularly hard but if you&amp;rsquo;re just getting started I highly recommend taking it slow and contribute only once you feel comfortable.</description>
            <content type="html"><![CDATA[<p>You have 2 options:</p>
<ul>
<li>Package the missing app yourself and contribute it back to upstream.</li>
<li>Give up and just use Nix, the language package manager or just use guix shell and patchelf your way through.</li>
</ul>
<p>Option 1 is fairly involved, depending on how big the dependency tree of your app is you&rsquo;re probably not going
to want to do this even if you manage to package the app and want to contribute it back you&rsquo;ll have to get used
to the mail workflow, how to use git send-email, patch guidelines&hellip; not that it&rsquo;s particularly hard but if you&rsquo;re just getting started I highly recommend taking it slow and contribute only once you feel comfortable.</p>
<p>We&rsquo;ll explore option 2 in this post:</p>
<h2 id="use-nix">Use nix</h2>
<p>Nix is the alternative to Guix if you want to keep using a functional package manager it has been around for a quite a while and the community is a bit bigger, there is also much more packages to choose from.</p>
<p>Just drop this snippet in your configuration.scm:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-scheme" data-lang="scheme"><span style="display:flex;"><span>(<span style="color:#a6e22e">service</span> nix-service-type)
</span></span></code></pre></div><p>And then you can use the usual nix command to install stuff:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>nix search nixpkgs#burpsuite
</span></span><span style="display:flex;"><span>nix profile install nipkgs#burpsuite
</span></span></code></pre></div><p>I&rsquo;ll leave you with my config for nix:</p>
<p>Here is my ~/.config/nix/nix.conf</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>experimental-features <span style="color:#f92672">=</span> nix-command flakes
</span></span></code></pre></div><p>The channels that I use</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>https://github.com/nix-community/home-manager/archive/master.tar.gz home-manager
</span></span><span style="display:flex;"><span>https://nixos.org/channels/nixpkgs-unstable nixpkgs
</span></span><span style="display:flex;"><span>https://tadfisher.github.io/android-nixpkgs android-nixpkgs
</span></span></code></pre></div><p>And my ~/.config/nixpkgs/config.nix file</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>  <span style="color:#f92672">{</span>
</span></span><span style="display:flex;"><span>  allowUnfree <span style="color:#f92672">=</span> true;
</span></span><span style="display:flex;"><span>  packageOverrides <span style="color:#f92672">=</span> pkgs: with pkgs; <span style="color:#f92672">{</span>
</span></span><span style="display:flex;"><span>    myPackages <span style="color:#f92672">=</span> pkgs.buildEnv <span style="color:#f92672">{</span>
</span></span><span style="display:flex;"><span>      name <span style="color:#f92672">=</span> <span style="color:#e6db74">&#34;myPackages&#34;</span>;
</span></span><span style="display:flex;"><span>      paths <span style="color:#f92672">=</span> <span style="color:#f92672">[</span>
</span></span><span style="display:flex;"><span>      scrcpy
</span></span><span style="display:flex;"><span>      deno
</span></span><span style="display:flex;"><span>      nodejs
</span></span><span style="display:flex;"><span>      apktool
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">]</span>;
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">}</span>;
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">}</span>;
</span></span><span style="display:flex;"><span><span style="color:#f92672">}</span>
</span></span></code></pre></div><p>Finally you might encounter a weird little bug when you try to launch a nix command, it complains about
a pseudo tty missing or something, there is an issue for that on <a href="https://issues.guix.gnu.org/">https://issues.guix.gnu.org/</a> but basically
you just have to restart the nix daemon.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>sudo herd restart nix-daemon
</span></span></code></pre></div><h2 id="use-your-language-package-manager">Use your language package manager</h2>
<p>Not much to say here, once you installed say python with guix you can just use pip to install apps not
yet packaged in guix.</p>
<p>You might need to change your PATH to ~/.local/bin or wherever your language package manager is storing its binaries but that should be all.</p>
<h2 id="use-guix-shell">Use Guix shell</h2>
<p>If the app that you want is not packaged in Guix,Nix or a language package manager and you just have a binary
to work with you&rsquo;ll have to use ldd and patchelf the headers of that binary to make it work.</p>
<p>I&rsquo;ll take the TextSynth server from Fabrice Bellard as an example, once you downloaded the ts_zip you&rsquo;ll have
multiple binaries to work with.</p>
<p>If you try to launch them directly it&rsquo;s going to complain about a file not being there:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>-bash: ./ts_sd: Aucun fichier ou dossier de ce type
</span></span></code></pre></div><p>But what this really means is that the binary complains about missing libraries, to found out which one you&rsquo;ll have to use ldd, a tool that comes with glibc:lib on guix:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>guix shell --check --pure --expression<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span> coreutils bash grep sed gcc-toolchain patchelf
</span></span></code></pre></div><p>Then run:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>ldd ts_sd
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># it yields something like</span>
</span></span><span style="display:flex;"><span>user@linux ~/Downloads/ts_server_free-2024-01-20 <span style="color:#f92672">[</span>env<span style="color:#f92672">]</span>$ ldd ts_sd
</span></span><span style="display:flex;"><span>      linux-vdso.so.1 <span style="color:#f92672">(</span>0x00007ffe1655e000<span style="color:#f92672">)</span>
</span></span><span style="display:flex;"><span>      libnc.so <span style="color:#f92672">=</span>&gt; /home/user/Downloads/ts_server_free-2024-01-20/./libnc.so <span style="color:#f92672">(</span>0x00007f1024a00000<span style="color:#f92672">)</span>
</span></span><span style="display:flex;"><span>      libjpeg.so.62 <span style="color:#f92672">=</span>&gt; not found
</span></span><span style="display:flex;"><span>      libm.so.6 <span style="color:#f92672">=</span>&gt; /gnu/store/ln6hxqjvz6m9gdd9s97pivlqck7hzs99-glibc-2.35/lib/libm.so.6 <span style="color:#f92672">(</span>0x00007f1024d3a000<span style="color:#f92672">)</span>
</span></span><span style="display:flex;"><span>      libpthread.so.0 <span style="color:#f92672">=</span>&gt; /gnu/store/ln6hxqjvz6m9gdd9s97pivlqck7hzs99-glibc-2.35/lib/libpthread.so.0 <span style="color:#f92672">(</span>0x00007f1024d35000<span style="color:#f92672">)</span>
</span></span><span style="display:flex;"><span>      libc.so.6 <span style="color:#f92672">=</span>&gt; /gnu/store/ln6hxqjvz6m9gdd9s97pivlqck7hzs99-glibc-2.35/lib/libc.so.6 <span style="color:#f92672">(</span>0x00007f1024804000<span style="color:#f92672">)</span>
</span></span><span style="display:flex;"><span>      libdl.so.2 <span style="color:#f92672">=</span>&gt; /gnu/store/ln6hxqjvz6m9gdd9s97pivlqck7hzs99-glibc-2.35/lib/libdl.so.2 <span style="color:#f92672">(</span>0x00007f1024d2e000<span style="color:#f92672">)</span>
</span></span><span style="display:flex;"><span>      /lib64/ld-linux-x86-64.so.2 <span style="color:#f92672">=</span>&gt; /gnu/store/ln6hxqjvz6m9gdd9s97pivlqck7hzs99-glibc-2.35/lib/ld-linux-x86-64.so.2 <span style="color:#f92672">(</span>0x00007f1024e19000<span style="color:#f92672">)</span>
</span></span></code></pre></div><p>So we know that libjpeg is missing, we use a guix search libjpeg command to see if it&rsquo;s packaged in guix, fortunately for us it is and we add it to our command line like this:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>guix shell --check --pure --expression<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span> coreutils bash grep sed gcc-toolchain patchelf libjpeg
</span></span></code></pre></div><p>Now you&rsquo;ll need to patch the actual binary, one in the guix shell run:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>patchelf --add-needed $LIBRARY_PATH/libjpeg.so.62 ts_server
</span></span></code></pre></div><p>Repeat the process until you have all the libraries that you need, at the end of the day this is what I needed to make it work on my machine:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>  guix shell --check --pure --expression<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span> coreutils bash grep sed gcc-toolchain patchelf gtk+ dbus-glib libxt libevent openssl glibc file alsa-lib libmicrohttpd libjpeg cuda-toolkit@12.3.2 nvidia-driver
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>FIRST_PART<span style="color:#f92672">=</span><span style="color:#66d9ef">$(</span>echo <span style="color:#e6db74">&#34;</span>$LIBRARY_PATH<span style="color:#e6db74">&#34;</span> | cut -d <span style="color:#e6db74">&#34;:&#34;</span> -f1<span style="color:#66d9ef">)</span>
</span></span><span style="display:flex;"><span>SECOND_PART<span style="color:#f92672">=</span><span style="color:#66d9ef">$(</span>echo <span style="color:#e6db74">&#34;</span>$LIBRARY_PATH<span style="color:#e6db74">&#34;</span> | cut -d <span style="color:#e6db74">&#34;:&#34;</span> -f2<span style="color:#66d9ef">)</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>patchelf --set-interpreter $FIRST_PART/ld-linux-x86-64.so.2 ts_server
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libjpeg.so.62 ts_server
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libmicrohttpd.so.12 ts_server
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libstdc++.so.6 ts_server
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libgcc_s.so.1 ts_server
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libcublasLt.so.12  libnc_cuda.so
</span></span><span style="display:flex;"><span>patchelf --add-needed $FIRST_PART/libcuda.so.1 libnc_cuda.so
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>./ts_sd --cuda -m sd_v2.1.bin -o out.jpg <span style="color:#e6db74">&#34;an astronaut riding a horse&#34;</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>./ts_sd --cuda -m sd_v2.1.bin -o out.jpg <span style="color:#e6db74">&#34;an astronaut riding a horse&#34;</span> -t bf16
</span></span></code></pre></div><p>Note that you could also have used the &ndash;emulate-fhs flag, what it does is basically recreate the usual /usr/lib /lib&hellip; file structure and with that I think you could have skipped the various patchelf steps.</p>
<p>What if you don&rsquo;t want to guix shell every single time? Well you could actually turn this into it&rsquo;s own package
with the patchelf included, you have plenty of examples in the nonguix channel and the guix-games channel.</p>
]]></content>
        </item>
        
        <item>
            <title>Guix for a newcomer</title>
            <link>https://ieong.ovh/posts/guix-newcomer/</link>
            <pubDate>Sun, 05 Feb 2023 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/guix-newcomer/</guid>
            <description>I first heard about Guix from friends on a discord, the declarative configuration that is a full fledged programming language greatly appealed to me.
So I decided to give it a try, watched some videos from SystemCrafters and read some pages in the manual and I was good to go.
Note that guix is both a system and a package manager, I&amp;rsquo;ll mostly talk about the system in this short post.</description>
            <content type="html"><![CDATA[<p>I first heard about Guix from friends on a discord, the declarative
configuration that is a full fledged programming language greatly appealed to me.</p>
<p>So I decided to give it a try, watched some videos from SystemCrafters and
read some pages in the manual and I was good to go.</p>
<p>Note that guix is both a system and a package manager, I&rsquo;ll mostly talk
about the system in this short post.</p>
<h2 id="installation">Installation</h2>
<p>It&rsquo;s straightforward the only pain point is that guix has a very strong
stance on software freedom and as such it won&rsquo;t include the blobs
necessary for you wifi to work.</p>
<p>That would have been a deal breaker if there was not an easy to use <a href="https://github.com/SystemCrafters/guix-installer">iso</a> with
the full kernel, thanks to David.</p>
<p>Now one thing to note on the speed of the download/install package cycles is that it feels
a lot slower on guix compared to your average distro, if you don&rsquo;t have an SSD this will
be very painful.</p>
<p>Note that as of 2023 there is no equivalent of preseed for guix, only shell scripts to
automate it.</p>
<h2 id="daily-usage">Daily usage</h2>
<p>So far if you followed the manual you should get a basic environment with
X up and running.</p>
<h3 id="learning-scheme">Learning scheme</h3>
<p>Now what about actually deviating from the default? what about
adding new services and packages? Mass producing os-definition
so that you can <code>guix system image</code> them and deploy on libvirt?</p>
<p>Well in order to do that you really need to learn scheme(the guile dialect to be more precise)
there is no way around that.</p>
<p>Depending on your background you will have to write a few programs before
getting the hang of it and feel confortable in guix, git clone the source
code of guix, take a little stroll in it.</p>
<p>But once you have it will feels incredible to not be bound by a DSL.</p>
<p>See <a href="https://guix.gnu.org/cookbook/en/html_node/A-Scheme-Crash-Course.html">Scheme primer</a> for more info</p>
<h3 id="learning-how-to-actually-use-the-system">Learning how to actually use the system</h3>
<p>You &rsquo;ll learn mostly by spending time on it.</p>
<p>The commands that I run most often are</p>
<p><code>guix pull</code> to download new definitions of packages and services</p>
<p><code>guix system reconfigure</code> to update the system</p>
<p><code>guix home reconfigure</code> to update my home services</p>
<p>and finally I have a wrapper that update all extra-profiles that
I have in my dotfiles directory.</p>
<p>One thing that is annoying is that guix will sometimes try to compile
humonguous packages like qt,firefox,libreoffice&hellip; and your only options
to avoid that are basically setting the version of the software you want
to an inferior version.</p>
<p>Or check with guix weather before reconfiguring the system.</p>
<p>You could have your own build farm too I guess.</p>
<h3 id="how-to-use-steam-how-to-webdev-where-is-my-favorite-package">How to use steam? How to webdev? Where is my favorite package?</h3>
<p>Well&hellip;. you will have to use <a href="https://gitlab.com/nonguix/nonguix">nonguix</a> that is a channel containing
some non free software.</p>
<p>Now what if your package/service is not in there? Well you could try
search over the internet for a channel that has what you want but you
will most likely either:</p>
<ol>
<li>
<p>Package it yourself, depending on the package
it can be too time consuming or dead simple.</p>
<p>Now there are importers to ease the process of packaging
but they are not magic, sometimes they just don&rsquo;t work.</p>
<p>And even if they are working if your package is non trivial
you will most likely have to do some manual stuff.</p>
</li>
<li>
<p>Download the binary, and if it has dynamic dependencies
you will have to patch them, here is a small snippet
that was used to run tor-browser</p>
<p>Found it in nonguix I believe</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>cd Browser
</span></span><span style="display:flex;"><span>guix shell --check --pure --expression<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;(list (@@ (gnu packages gcc) gcc) &#34;lib&#34;)&#39;</span> coreutils bash grep sed gcc-toolchain patchelf gtk+ dbus-glib libxt libevent openssl@1.1.1l glibc
</span></span><span style="display:flex;"><span>patchelf --set-interpreter $LIBRARY_PATH/ld-linux-x86-64.so.2 firefox.real
</span></span><span style="display:flex;"><span>patchelf --set-interpreter $LIBRARY_PATH/ld-linux-x86-64.so.2 updater
</span></span><span style="display:flex;"><span>patchelf --set-interpreter $LIBRARY_PATH/ld-linux-x86-64.so.2 TorBrowser/Tor/tor
</span></span><span style="display:flex;"><span>LD_LIBRARY_PATH<span style="color:#f92672">=</span>$LIBRARY_PATH ./start-tor-browser
</span></span></code></pre></div></li>
<li>
<p>Just give up and use your language package manager to install
the package locally inside some foler.</p>
</li>
</ol>
<p>So yeah that takes much more time than a simple <code>apt update</code> and <code>apt install package</code></p>
<h3 id="get-help">Get help</h3>
<p>The official IRC channel is at #guix on libera.chat people are pretty
friendly there.</p>
<p>Other options are the mailing-list help-guix and guix-devel comes to mind.</p>
<p>I know that SystemCrafters has a discord and they do talk about guix in it.</p>
<p>See this list for more <a href="https://sr.ht/~lle-bout/awesome-guix/">resources</a></p>
<p>The rest are random blog post like this one, github gists.</p>
<p>So all in all not that much places compared to say debian.</p>
<h3 id="guix-is-fat">Guix is fat</h3>
<p>Over time you&rsquo;ll notice that the store just keeps getting larger
and larger you will need garbage collect every once in a while.</p>
<p>Every time you update the system with a reconfigure that makes a new generation.</p>
<p>From what I heard it&rsquo;s a bit better with btrfs as there is transparent compression
in that file system.</p>
<h3 id="breaking-guix">Breaking Guix</h3>
<p>You do have to watch out for filesystem corruptions, I had one of these happens
to some packages in the store and I could not delete it even with the force option
of the guix gc.</p>
<p>The result was that I could not use the package IIRC.</p>
<p>If anyone has more details on what to do in these cases?</p>
<p>Also see <a href="https://guix.gnu.org/manual/devel/en/html_node/Chrooting-into-an-existing-system.html">chrooting into existing system</a> if you like me managed to break
grub a few times.</p>
<h2 id="conclusion">Conclusion</h2>
<p>I think Guix has very solid foundations and it makes ansible &amp; co feels
prehistoric note that I feel like I haven&rsquo;t talk enough about all the things can do for you
so I will do a short summary here.</p>
<ol>
<li>
<p>Can actually be used to manage other guix systems with guix deploy
eliminating the need for ansible.</p>
</li>
<li>
<p>Manage your dotfiles in a manner that is reproducible with guix home
see rde from Andrew Tropin that demonstrates its full power.</p>
</li>
<li>
<p>If you managed to package stuff in guix, you can export it in .deb,.rpm format or
even a docker, pretty neat right?</p>
</li>
<li>
<p>You can actually transfer some elements of the store into another guix machine, and you can
offload the build of big packages like Qt to a remote guix(note that this only concerns
some part IIRC you will still needs to build derivation,profile? on the local)</p>
</li>
<li>
<p>Have a completely isolated environment, here is a short snippet of mine
that contains emacs and some dependencies specified in manifests.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>guix shell --network --container <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --pure --emulate-fhs --no-cwd <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --preserve<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;^DISPLAY</span>$<span style="color:#e6db74">&#34;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --share<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;/home/user/.config/emacs&#34;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --share<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;/home/user/projects/kimsufi-infra/pulumi-state/&#34;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     --share<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;/home/user/projects/kimsufi-infra/pulumi&#34;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     coreutils emacs font-fira-code fontconfig nss-certs bash openssh <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     -m /home/user/dotfiles/guix/manifests/emacs.scm <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     -m /home/user/dotfiles/guix/manifests/devops.scm <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     -m /home/user/dotfiles/guix/manifests/python.scm <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>     -m /home/user/dotfiles/guix/manifests/coding.scm
</span></span></code></pre></div></li>
</ol>
<p>However every pain points revolve around the fact that guix is niche
and there is not that much people that are available to review the patches,
contribute to the core, add packages, write nice documentation with concrete examples.</p>
<p>Despite this I would recommend you to give it a try if you are willing to spend the time.</p>
<p>Now how much time are we talking about exactly?</p>
<p>Well depending on your background (I will assume 0 functionnal programming, nor nix experience just debian/arch experience) you basically have to learn a new language + a new system + the mailling-list workflow + irc
setup (most people use discord these days) + read the source code to know why stuff does not works/works.</p>
<p>That&rsquo;s actually a pretty huge time investment especially the mailing list and the irc, you have
to be very proactive whereas if it was a more mainstream distro like debian you could just follow a blog post/stack overflow, copy paste some instructions with a few changes and boom that works.</p>
<p>Or just download a package and forget about the whole reproducibility crisis.</p>
]]></content>
        </item>
        
        <item>
            <title>Bootstrapping guix on Kimsufi</title>
            <link>https://ieong.ovh/posts/bootstrapping-guix-kimsufi/</link>
            <pubDate>Sun, 05 Feb 2023 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/bootstrapping-guix-kimsufi/</guid>
            <description>UPDATE This post is outdated now, follow this https://guix.gnu.org/en/cookbook/en/html_node/Running-Guix-on-a-Kimsufi-Server.html
This is a short guide on how to get guix up and running on a Kimsufi server.
If only Kimsufi had a Bring Your Own Image feature I would not be writing this post, it took me an entire afternoon to try the usual install the system in rescue mode and that did not work.
Jump straight to Converting Debian into Guix if you just want guix up and running.</description>
            <content type="html"><![CDATA[<p><strong><strong>UPDATE</strong></strong> This post is outdated now, follow this <a href="https://guix.gnu.org/en/cookbook/en/html_node/Running-Guix-on-a-Kimsufi-Server.html">https://guix.gnu.org/en/cookbook/en/html_node/Running-Guix-on-a-Kimsufi-Server.html</a></p>
<p>This is a short guide on how to get guix up and running on
a Kimsufi server.</p>
<p>If only Kimsufi had a Bring Your Own Image feature I would not
be writing this post, it took me an entire afternoon to try the
usual install the system in rescue mode and that did
not work.</p>
<p>Jump straight to <a href="/posts/bootstrapping-guix-kimsufi/#converting-debian-into-guix">Converting Debian into Guix</a> if you just want
guix up and running.</p>
<h2 id="rescue-method">Rescue method</h2>
<h3 id="the-manual-way">The manual way</h3>
<p>From the Web UI you&rsquo;re supposed to change netboot to rescue64-pro then
restart the machine, OVH will then mail you with the credentials needed
to ssh into the server.</p>
<p>Once that is done you have access to a minimal debian with qemu installed
and from there you can partition the disks, download the guix iso, launch it with qemu and
continue the installation through vnc.</p>
<p>See this <a href="https://www.emaxilde.net/posts/2021/07/25/installer-un-serveur-dedie-sans-acces-kvm-ou-ipmi.html">post</a> for a step-by-step guide.</p>
<p>I chose to write a shell script that would automate the bootstrap process.</p>
<p>It&rsquo;s not just a plug and play script you will have
to adapt it to your own config (change the ip addresses, the services that you use&hellip;)
and transfer it plus the  os.scm file via sftp to the server.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span><span style="color:#75715e">#!/usr/bin/env bash
</span></span></span><span style="display:flex;"><span><span style="color:#75715e"></span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># See https://guix.gnu.org/cookbook/en/html_node/Running-Guix-on-a-Linode-Server.html</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># From the webui -&gt; netboot rescue rescue64-pro -&gt; restart -&gt; get the credentials in the mail</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># -&gt; ssh into the machine</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Guix</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>wget https://git.savannah.gnu.org/cgit/guix.git/plain/etc/guix-install.sh
</span></span><span style="display:flex;"><span>chmod +x guix-install.sh
</span></span><span style="display:flex;"><span>./guix-install.sh
</span></span><span style="display:flex;"><span>guix pull
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Partitions</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># See https://blog.hqcodeshop.fi/archives/273-GNU-Parted-Solving-the-dreaded-The-resulting-partition-is-not-properly-aligned-for-best-performance.html</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># https://wiki.archlinux.org/title/Advanced_Format#Partition_alignment</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mdadm --stop /dev/md127
</span></span><span style="display:flex;"><span>mdadm --zero-superblock /dev/sda2 /dev/sdb2
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>wipefs -a /dev/sda
</span></span><span style="display:flex;"><span>wipefs -a /dev/sdb
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>parted /dev/sda --align<span style="color:#f92672">=</span>opt -s -m -- mklabel gpt
</span></span><span style="display:flex;"><span>parted /dev/sda --align<span style="color:#f92672">=</span>opt -s -m -- <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>       mkpart bios_grub 1049kb 512MiB <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>       set <span style="color:#ae81ff">1</span> bios_grub on
</span></span><span style="display:flex;"><span>parted /dev/sda --align<span style="color:#f92672">=</span>opt -s -m -- <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>       mkpart primary 512MiB -512MiB
</span></span><span style="display:flex;"><span>       set <span style="color:#ae81ff">2</span> raid on
</span></span><span style="display:flex;"><span>parted /dev/sda --align<span style="color:#f92672">=</span>opt -s -m -- mkpart primary linux-swap 512MiB 100% <span style="color:#75715e"># Swap</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>parted /dev/sdb --align<span style="color:#f92672">=</span>opt -s -m -- mklabel gpt
</span></span><span style="display:flex;"><span>parted /dev/sdb --align<span style="color:#f92672">=</span>opt -s -m -- <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>         mkpart bios_grub 1049kb 512MiB <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>         set <span style="color:#ae81ff">1</span> bios_grub on
</span></span><span style="display:flex;"><span>parted /dev/sdb --align<span style="color:#f92672">=</span>opt -s -m -- <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>         mkpart primary 512MiB -512MiB <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>         set <span style="color:#ae81ff">2</span> raid on
</span></span><span style="display:flex;"><span>parted /dev/sdb --align<span style="color:#f92672">=</span>opt -s -m -- mkpart primary linux-swap 512MiB 100% <span style="color:#75715e"># Swap</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e">## RAID</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e">## Use btrfs instead of mdadm?</span>
</span></span><span style="display:flex;"><span>mdadm --create /dev/md127 --level<span style="color:#f92672">=</span><span style="color:#ae81ff">1</span> --raid-disks<span style="color:#f92672">=</span><span style="color:#ae81ff">2</span> --metadata<span style="color:#f92672">=</span>0.90 /dev/sda2 /dev/sdb2
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e">## Boot partitions</span>
</span></span><span style="display:flex;"><span>mkfs.ext4  /dev/sda1
</span></span><span style="display:flex;"><span>mkfs.ext4  /dev/sdb1
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e">## Root filesystem</span>
</span></span><span style="display:flex;"><span>mkfs.ext4 /dev/md127
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e">## Swap partitions</span>
</span></span><span style="display:flex;"><span>mkswap /dev/sda3
</span></span><span style="display:flex;"><span>swapon /dev/sda3
</span></span><span style="display:flex;"><span>mkswap /dev/sdb3
</span></span><span style="display:flex;"><span>swapon /dev/sdb3
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Installing guix system</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mkdir /mnt/guix
</span></span><span style="display:flex;"><span>mount /dev/md127 /mnt/guix
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>guix system init /root/os.scm /mnt/guix
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Need to wait 5-10 mn to reboot</span>
</span></span></code></pre></div><p>Here is an example of an os definition:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-scheme" data-lang="scheme"><span style="display:flex;"><span>(<span style="color:#a6e22e">use-modules</span> (<span style="color:#a6e22e">gnu</span>))
</span></span><span style="display:flex;"><span>(<span style="color:#a6e22e">use-service-modules</span> networking ssh vpn virtualization sysctl admin)
</span></span><span style="display:flex;"><span>(<span style="color:#a6e22e">use-package-modules</span> ssh certs tls tmux vpn virtualization)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>(<span style="color:#a6e22e">operating-system</span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">host-name</span> <span style="color:#e6db74">&#34;kimsufi&#34;</span>)
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">timezone</span> <span style="color:#e6db74">&#34;Etc/UTC&#34;</span>)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">bootloader</span> (<span style="color:#a6e22e">bootloader-configuration</span>
</span></span><span style="display:flex;"><span>             (<span style="color:#a6e22e">bootloader</span> grub-bootloader)
</span></span><span style="display:flex;"><span>                                      <span style="color:#75715e">;(targets (list &#34;/dev/sda&#34; &#34;/dev/sdb&#34;))</span>
</span></span><span style="display:flex;"><span>             (<span style="color:#a6e22e">targets</span> (list <span style="color:#e6db74">&#34;/dev/sda&#34;</span>))
</span></span><span style="display:flex;"><span>             (<span style="color:#a6e22e">terminal-outputs</span> <span style="color:#f92672">&#39;</span>(console))))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;; Add a kernel module for RAID-1 (aka. &#34;mirror&#34;).</span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">initrd-modules</span> (<span style="color:#a6e22e">cons*</span> <span style="color:#e6db74">&#34;raid1&#34;</span>  %base-initrd-modules))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;; (mapped-devices</span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;;  (list</span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;;   (mapped-device</span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;;   ; (source (list &#34;/dev/sda2&#34; &#34;/dev/sdb2&#34;))</span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;;    (target &#34;/dev/md2&#34;)</span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;;    (type raid-device-mapping))))</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">swap-devices</span>
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">list</span>
</span></span><span style="display:flex;"><span>    (<span style="color:#a6e22e">swap-space</span>
</span></span><span style="display:flex;"><span>     (<span style="color:#a6e22e">target</span> <span style="color:#e6db74">&#34;/dev/sda3&#34;</span>))
</span></span><span style="display:flex;"><span>    <span style="color:#75715e">;; (swap-space</span>
</span></span><span style="display:flex;"><span>    <span style="color:#75715e">;;  (target &#34;/dev/sdb3&#34;))</span>
</span></span><span style="display:flex;"><span>    ))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">issue</span>
</span></span><span style="display:flex;"><span>   <span style="color:#75715e">;; Default contents for /etc/issue.</span>
</span></span><span style="display:flex;"><span>   <span style="color:#e6db74">&#34;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">This is the GNU system at Kimsufi.  Welcome.\n&#34;</span>)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">file-systems</span> (<span style="color:#a6e22e">cons*</span> (<span style="color:#a6e22e">file-system</span>
</span></span><span style="display:flex;"><span>                       (<span style="color:#a6e22e">mount-point</span> <span style="color:#e6db74">&#34;/&#34;</span>)
</span></span><span style="display:flex;"><span>                       (<span style="color:#a6e22e">device</span> (<span style="color:#a6e22e">file-system-label</span> <span style="color:#e6db74">&#34;root&#34;</span>))
</span></span><span style="display:flex;"><span>                                      <span style="color:#75715e">;(device &#34;/dev/md2&#34;)</span>
</span></span><span style="display:flex;"><span>                                      <span style="color:#75715e">;(device &#34;/dev/sda2&#34;)</span>
</span></span><span style="display:flex;"><span>                       (<span style="color:#a6e22e">type</span> <span style="color:#e6db74">&#34;ext4&#34;</span>)
</span></span><span style="display:flex;"><span>                                      <span style="color:#75715e">;(dependencies mapped-devices)</span>
</span></span><span style="display:flex;"><span>                       )
</span></span><span style="display:flex;"><span>                     %base-file-systems))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">users</span> (cons (<span style="color:#a6e22e">user-account</span>
</span></span><span style="display:flex;"><span>              (<span style="color:#a6e22e">name</span> <span style="color:#e6db74">&#34;guix&#34;</span>)
</span></span><span style="display:flex;"><span>              (<span style="color:#a6e22e">comment</span> <span style="color:#e6db74">&#34;guix&#34;</span>)
</span></span><span style="display:flex;"><span>              (<span style="color:#a6e22e">group</span> <span style="color:#e6db74">&#34;users&#34;</span>)
</span></span><span style="display:flex;"><span>              (<span style="color:#a6e22e">supplementary-groups</span> <span style="color:#f92672">&#39;</span>(<span style="color:#e6db74">&#34;wheel&#34;</span>))
</span></span><span style="display:flex;"><span>              (<span style="color:#a6e22e">home-directory</span> <span style="color:#e6db74">&#34;/home/guix&#34;</span>))
</span></span><span style="display:flex;"><span>             %base-user-accounts))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">sudoers-file</span>
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">plain-file</span> <span style="color:#e6db74">&#34;sudoers&#34;</span> <span style="color:#e6db74">&#34;\
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">root ALL=(ALL) ALL
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">%wheel ALL=(ALL) ALL
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">guix ALL=(ALL) NOPASSWD:ALL\n&#34;</span>))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  <span style="color:#75715e">;; Globally-installed packages.</span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">packages</span> (<span style="color:#a6e22e">cons*</span> tmux nss-certs gnutls wireguard-tools %base-packages))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>  (<span style="color:#a6e22e">services</span>
</span></span><span style="display:flex;"><span>   (<span style="color:#a6e22e">cons*</span>
</span></span><span style="display:flex;"><span>    (<span style="color:#a6e22e">service</span> static-networking-service-type
</span></span><span style="display:flex;"><span>           (list (<span style="color:#a6e22e">static-networking</span>
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">addresses</span> (list (<span style="color:#a6e22e">network-address</span>
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">device</span> <span style="color:#e6db74">&#34;enp3s0&#34;</span>)
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">value</span> <span style="color:#e6db74">&#34;REPLACE_ME&#34;</span>))
</span></span><span style="display:flex;"><span>                                   (<span style="color:#a6e22e">network-address</span>
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">device</span> <span style="color:#e6db74">&#34;enp3s0&#34;</span>)
</span></span><span style="display:flex;"><span>                                    (<span style="color:#a6e22e">value</span> <span style="color:#e6db74">&#34;REPLACE_ME&#34;</span>))))
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">routes</span> (list (<span style="color:#a6e22e">network-route</span>
</span></span><span style="display:flex;"><span>                                 (<span style="color:#a6e22e">destination</span> <span style="color:#e6db74">&#34;default&#34;</span>)
</span></span><span style="display:flex;"><span>                                 (<span style="color:#a6e22e">gateway</span> <span style="color:#e6db74">&#34;37.187.79.254&#34;</span>))
</span></span><span style="display:flex;"><span>                                (<span style="color:#a6e22e">network-route</span>
</span></span><span style="display:flex;"><span>                                 (<span style="color:#a6e22e">destination</span> <span style="color:#e6db74">&#34;default&#34;</span>)
</span></span><span style="display:flex;"><span>                                 (<span style="color:#a6e22e">gateway</span> <span style="color:#e6db74">&#34;2001:41d0:a:2fFF:FF:FF:FF:FF&#34;</span>))))
</span></span><span style="display:flex;"><span>                  (<span style="color:#a6e22e">name-servers</span> <span style="color:#f92672">&#39;</span>(<span style="color:#e6db74">&#34;213.186.33.99&#34;</span>)))))
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>    (<span style="color:#a6e22e">service</span> unattended-upgrade-service-type)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>    (<span style="color:#a6e22e">service</span> openssh-service-type
</span></span><span style="display:flex;"><span>           (<span style="color:#a6e22e">openssh-configuration</span>
</span></span><span style="display:flex;"><span>            (<span style="color:#a6e22e">openssh</span> openssh-sans-x)
</span></span><span style="display:flex;"><span>            (<span style="color:#a6e22e">permit-root-login</span> <span style="color:#66d9ef">#f</span>)
</span></span><span style="display:flex;"><span>            (<span style="color:#a6e22e">port-number</span> <span style="color:#ae81ff">22222</span>)
</span></span><span style="display:flex;"><span>            (<span style="color:#a6e22e">authorized-keys</span>
</span></span><span style="display:flex;"><span>             (<span style="color:#a6e22e">quasiquote</span>
</span></span><span style="display:flex;"><span>              ((<span style="color:#e6db74">&#34;REPLACE_ME&#34;</span> (<span style="color:#66d9ef">unquote </span>(<span style="color:#a6e22e">plain-file</span> <span style="color:#e6db74">&#34;REPLACE_ME.pub&#34;</span> <span style="color:#e6db74">&#34;SSH_KEY.PUB&#34;</span>))))))))
</span></span><span style="display:flex;"><span>    (<span style="color:#a6e22e">modify-services</span> %base-services
</span></span><span style="display:flex;"><span>      (<span style="color:#a6e22e">sysctl-service-type</span> config =&gt;
</span></span><span style="display:flex;"><span>                         (<span style="color:#a6e22e">sysctl-configuration</span>
</span></span><span style="display:flex;"><span>                          (<span style="color:#a6e22e">settings</span> (append <span style="color:#f92672">&#39;</span>((<span style="color:#e6db74">&#34;net.ipv6.conf.all.autoconf&#34;</span> <span style="color:#f92672">.</span> <span style="color:#e6db74">&#34;0&#34;</span>)
</span></span><span style="display:flex;"><span>                                              (<span style="color:#e6db74">&#34;net.ipv6.conf.all.accept_ra&#34;</span> <span style="color:#f92672">.</span> <span style="color:#e6db74">&#34;0&#34;</span>))
</span></span><span style="display:flex;"><span>                                            %default-sysctl-settings))))))))
</span></span></code></pre></div><p>Now everything should be good to go, the only thing left is to change
the netboot back to hard drive and then reboot the machine.</p>
<p>And&hellip;&hellip;&hellip;&hellip;&hellip;. after rebooting it turns out that I can ping the machine
but all ports are closed.</p>
<p>I did reboot the machine in rescue mode again, mount the guix system into /mnt
hoping to see some logs, but there was not anything, the logs files were simply
not there, neither was the <code>/home/user/guix</code> directory.</p>
<p>So I guess it simply cannot boot but as for why? I have no idea.</p>
<p>Since kimsufi does not provide you with a KVM console you&rsquo;re kinda screwed.</p>
<h3 id="the-automated-way">The automated way</h3>
<p>Now I did not want to do it the manual way, I wanted something that could
be automated with pulumi and some ansible/guile/shell script (ideally everything
would be done via guix and guile but there is sadly too much to reimplement
at the moment).</p>
<h4 id="retrieve-the-ssh-credentials">Retrieve the SSH credentials</h4>
<p>I examined the kimsufi api and there are 3 endpoints of interest:</p>
<ul>
<li><em>/​me/notification/email/history​/</em></li>
<li><em>/​me/notification/email/history/{id}​/</em></li>
<li><em>/​secret​/</em></li>
</ul>
<p>The first endpoint allow you to retrieve alls the ids of the emails that ovh
sent you, from there you can feed the last id to the second endpoint.</p>
<p>This will returns a body of text with the email containing the credentials,
you will have to parse it in order to retrive the secret uuid.</p>
<p>Once this is done you can query the secret endpoint with the uuid and that
will return the ssh password in plain text.</p>
<h4 id="pulumi">Pulumi</h4>
<p>Well now it&rsquo;s time to write a program in one of the language supported by pulumi
I decided to use python since I have to write fewer lines than say Java/C#.</p>
<p>I might have took Go if this was something more important but for my little
infra I don&rsquo;t care that much.</p>
<p>First step it to get the ovh provider for pulumi, this provider will allow us
to query the aforementionned endpoints. Also install the command provider to run
an ansible playbook that will take care of partitioning/running various guix
commands&hellip;</p>
<p>Now the ovh provider is a terraform only thing, the pulumi provider for ovh
is actually entirely generated from that terraform provider.</p>
<p>I could unfortunately not get it to work, when I would run <code>pulumi up</code> it would
crash with a <code>DistroNotFoundError</code>.</p>
<p>So I just gave up because I had other problems in the manual way and I did not
want to use terraform again.</p>
<h2 id="converting-debian-into-guix">Converting Debian into Guix</h2>
<p>From the Web UI you&rsquo;ll need to install either a Debian 10 or Debian 11 machine.</p>
<p>Once that is done you can adapt the script, transfer via sftp and run it.</p>
<p>Now there are gotchas when bootstraping from a live os like this.</p>
<p>If you try to bootstrap with a full configuration with dozen of services
you will get weird errors, so it&rsquo;s better to start with something minimal
and once the system is up reconfigure with the full configuration you want.</p>
<p>That is why libvirt, virtlog&hellip; are commented out, if I did not I would
otherwise get a weird dbus error.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span><span style="color:#75715e">#!/usr/bin/env bash
</span></span></span><span style="display:flex;"><span><span style="color:#75715e"></span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Target a debian10 machine</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>sudo su -
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>apt-get update
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>apt-get install xz-utils -y
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>wget https://ftp.gnu.org/gnu/guix/guix-binary-1.4.0.x86_64-linux.tar.xz
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>cd /tmp
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>tar --warning<span style="color:#f92672">=</span>no-timestamp -xvf ~/guix-binary-1.4.0.x86_64-linux.tar.xz
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mv var/guix /var/ <span style="color:#f92672">&amp;&amp;</span> mv gnu /
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mkdir -p /root/.config/guix
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>ln -sf /var/guix/profiles/per-user/root/current-guix ~root/.config/guix/current
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>export GUIX_PROFILE<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;/root/.config/guix/current&#34;</span> ;
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>source $GUIX_PROFILE/etc/profile
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>groupadd --system guixbuild
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">for</span> i in <span style="color:#e6db74">`</span>seq -w <span style="color:#ae81ff">1</span> 10<span style="color:#e6db74">`</span>; <span style="color:#66d9ef">do</span>
</span></span><span style="display:flex;"><span>    useradd -g guixbuild -G guixbuild         <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>          -d /var/empty -s <span style="color:#e6db74">`</span>which nologin<span style="color:#e6db74">`</span>  <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>          -c <span style="color:#e6db74">&#34;Guix build user </span>$i<span style="color:#e6db74">&#34;</span> --system  <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#ae81ff"></span>          guixbuilder$i;
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">done</span>;
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>cp -v /root/.config/guix/current/lib/systemd/system/guix-daemon.service /etc/systemd/system/
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>systemctl start guix-daemon <span style="color:#f92672">&amp;&amp;</span> systemctl enable guix-daemon
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mkdir -p /usr/local/bin
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>cd /usr/local/bin
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>ln -s /var/guix/profiles/per-user/root/current-guix/bin/guix
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mkdir -p /usr/local/share/info
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>cd /usr/local/share/info
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">for</span> i in /var/guix/profiles/per-user/root/current-guix/share/info/*; <span style="color:#66d9ef">do</span>
</span></span><span style="display:flex;"><span>    ln -s $i;
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">done</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>guix archive --authorize &lt; /root/.config/guix/current/share/guix/ci.guix.gnu.org.pub
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>guix pull
</span></span><span style="display:flex;"><span>guix install glibc-utf8-locales-2.29 openssl glibc-locales
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>export GUIX_LOCPATH<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;</span>$HOME<span style="color:#e6db74">/.guix-profile/lib/locale&#34;</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Yeah I actually have to comment out libvirt and virtlog for now</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># otherwise I get a werid libvirt error.</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># Reenable them once we&#39;ve succesfully bootstraped.</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>cat &gt; /etc/bootstrap-config.scm <span style="color:#e6db74">&lt;&lt; EOF
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">(use-modules (gnu))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">(use-service-modules networking ssh vpn virtualization sysctl certbot admin)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">(use-package-modules ssh certs tls tmux vpn virtualization)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">(operating-system
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (host-name &#34;guix&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (timezone &#34;Etc/UTC&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (bootloader (bootloader-configuration
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">             (bootloader grub-bootloader)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">             (targets (list &#34;/dev/sda&#34; &#34;/dev/sdb&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">             (terminal-outputs &#39;(console))))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  ;; Add a kernel module for RAID-1 (aka. &#34;mirror&#34;).
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (initrd-modules (cons &#34;raid1&#34; %base-initrd-modules))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (mapped-devices
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">   (list
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    (mapped-device
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">     (source (list &#34;/dev/sda2&#34; &#34;/dev/sdb2&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">     (target &#34;/dev/md2&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">     (type raid-device-mapping))))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (swap-devices
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">    (list
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">     (swap-space
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">       (target &#34;/dev/sda3&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">     (swap-space
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">       (target &#34;/dev/sdb3&#34;))))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (issue
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  ;; Default contents for /etc/issue.
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  &#34;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">This is the GNU system at Kimsufi.  Welcome.\n&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (file-systems (cons* (file-system
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                      (mount-point &#34;/&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                      (device &#34;/dev/md2&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                      (type &#34;ext4&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                      (dependencies mapped-devices))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                    %base-file-systems))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (users (cons (user-account
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">              (name &#34;debian&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">              (comment &#34;debian&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">              (group &#34;users&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">              ;(supplementary-groups &#39;(&#34;wheel&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">              ;(supplementary-groups &#39;(&#34;wheel&#34; &#34;libvirt&#34; &#34;kvm&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">              (home-directory &#34;/home/debian&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">             %base-user-accounts))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (sudoers-file
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">   (plain-file &#34;sudoers&#34; &#34;\
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">root ALL=(ALL) ALL
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">%wheel ALL=(ALL) ALL
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">debian ALL=(ALL) NOPASSWD:ALL\n&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  ;; Globally-installed packages.
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (packages (cons* tmux nss-certs gnutls wireguard-tools %base-packages))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">(services
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74"> (cons*
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (service static-networking-service-type
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">         (list (static-networking
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                (addresses (list (network-address
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                                  (device &#34;enp3s0&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                                  (value &#34;37.187.79.64/24&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                                 (network-address
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                                  (device &#34;enp3s0&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                                  (value &#34;2001:41d0:a:2f40::1/64&#34;))))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                (routes (list (network-route
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                               (destination &#34;default&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                               (gateway &#34;37.187.79.254&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                              (network-route
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                               (destination &#34;default&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                               (gateway &#34;2001:41d0:a:2fFF:FF:FF:FF:FF&#34;))))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                (name-servers &#39;(&#34;213.186.33.99&#34;)))))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;             (service unattended-upgrade-service-type)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		     (service nftables-service-type
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;                      (nftables-configuration
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;                       (ruleset
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;                        (plain-file &#34;nftables.nft&#34;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;                                    &#34;\
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;table ip nat {
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;	chain prerouting {
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		type nat hook prerouting priority -100;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		tcp dport { http, https } dnat to 192.168.1.10:http
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;	}
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;	chain postrouting {
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		type nat hook postrouting priority 100;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		masquerade
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;	}
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;}
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;table inet filter {
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">; chain input {
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   type filter hook input priority 0; policy drop;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   # early drop of invalid connections
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   ct state invalid drop
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   # allow established/related connections
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   ct state { established, related } accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   # allow icmp
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   ip protocol icmp accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   ip6 nexthdr icmpv6 accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   # allow from loopback
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   iifname lo accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   # added: make NAT from libvirt work
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   iifname virbr0 accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   # allow ssh,http
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   tcp dport {http,https,53,67,2222} accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   udp dport {53,67} accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   # reject everything else
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   reject with icmpx type port-unreachable
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">; }
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">; chain forward {
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   type filter hook forward priority 0; policy drop;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   iifname virbr0 oifname enp3s0 accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   iifname enp3s0 oifname virbr0 accept
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">; }
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">; chain output {
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;   type filter hook output priority 0; policy accept;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">; }
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;}&#34;))))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;	     (service libvirt-service-type
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		      (libvirt-configuration
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		       (unix-sock-group &#34;libvirt&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		       (tls-port &#34;16555&#34;)))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;	     (service virtlog-service-type
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		      (virtlog-configuration
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">;		       (max-clients 1000)))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">  (service openssh-service-type
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">         (openssh-configuration
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">          (port-number 2222)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">          (permit-root-login #f)))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">           (modify-services %base-services
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">               (sysctl-service-type config =&gt;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                     (sysctl-configuration
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                       (settings (append &#39;((&#34;net.ipv6.conf.all.autoconf&#34; . &#34;0&#34;)
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                                           (&#34;net.ipv6.conf.all.accept_ra&#34; . &#34;0&#34;))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">                                         %default-sysctl-settings))))))))
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">EOF</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>guix system build /etc/bootstrap-config.scm
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># TODO: dbus</span>
</span></span><span style="display:flex;"><span>mv /etc/<span style="color:#f92672">{</span>ssl,pam.d,skel,udev<span style="color:#f92672">}</span> /tmp
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>guix system reconfigure /etc/bootstrap-config.scm
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mv /etc /old-etc
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>mkdir /etc
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>cp -r /old-etc/<span style="color:#f92672">{</span>passwd,group,shadow,gshadow,mtab,guix,bootstrap-config.scm<span style="color:#f92672">}</span> /etc/
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>guix system reconfigure /etc/bootstrap-config.scm
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># The users uid created by guix is set to 100 and the one made</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># made by debian is 1000, so we change that for guix.</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>chown -R debian:users /home/debian
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>reboot
</span></span></code></pre></div><p>Now if everything has gone smoothly you should have a guix system up and running!</p>
]]></content>
        </item>
        
        <item>
            <title>Guix as a mail server</title>
            <link>https://ieong.ovh/posts/guix-mail-server/</link>
            <pubDate>Mon, 06 Feb 2023 00:00:00 +0000</pubDate>
            
            <guid>https://ieong.ovh/posts/guix-mail-server/</guid>
            <description>The mail is not hard is a meme, for my previous deployment of a mail server I had multiple ansible playbooks to deploy the postfix + dovecot + rspamd stack to a debian server.
There were dozens of templates file, it was horrible I did this because I found the other options were way too bloated, most tutorials and examples on the internet tell you to set up a sql database, for a dead simple deployment for 1-6 users this is far too much.</description>
            <content type="html"><![CDATA[<p>The mail is not hard is a meme, for my previous deployment of a mail server I had
multiple ansible playbooks to deploy the postfix + dovecot + rspamd stack to a debian server.</p>
<p>There were dozens of templates file, it was horrible I did this because I found the
other options were way too bloated, most tutorials and examples on the internet tell
you to set up a sql database, for a dead simple deployment for 1-6 users this is far too much.</p>
<p>There are of course containers with mailcow &amp; co but again I found them either too bloated
or the stack was too old.</p>
<p>postfix + amavis + postgrey + spamassassin + opendkim + spfsomething + dovecot + clamav is too much in 2023 when you can simply go opensmtpd + dovecot + rspamd</p>
<p>But there is hope, guix as a system allows you to declaratively configure some services but how far
are we exactly of a fully reproducible mail setup?</p>
<p>Well not that far actually there are opensmtpd and dovecot already packaged and they can be used
as a service already.</p>
<p>There is a patch series for <a href="https://issues.guix.gnu.org/35619">postfix</a> but no news so far.</p>
<p>From what I&rsquo;ve seen dovecot configuration is mostly complete save some modules
like managesieve again a patch series is <a href="https://issues.guix.gnu.org/42899">there</a></p>
<p>Now rspamd is available but it is only available as a package, I am working
to get the service <a href="https://issues.guix.gnu.org/61740">done</a></p>
<p>For webmail roundcube is not packaged in guix because the php imported is not finished yet.</p>
<p>This is just for the setup, now imagine having to deal with your reputation, backup mx, if you
want to get fancy tlsa and mts records, how to manage your dkims keys over time&hellip;</p>
]]></content>
        </item>
        
    </channel>
</rss>
