diff --git a/flake.lock b/flake.lock index 43c000f..fa75b0f 100644 --- a/flake.lock +++ b/flake.lock @@ -181,11 +181,11 @@ ] }, "locked": { - "lastModified": 1789726083, - "narHash": "sha256-oxlp99L8KXYDdzroS+QeqhQyFigVHp44D6aVFsifpe0=", + "lastModified": 1789975217, + "narHash": "sha256-n7L5vHbyemIa5jzlueIdpWmQsQSkv5Rrf9JV5kTZ6uU=", "ref": "clanService-router-ai", - "rev": "4146f2c878b104d96d25575be553378ae276f6e0", - "revCount": 198, + "rev": "596ac1f4bb851af3e03c06ba286cb33ae36095d2", + "revCount": 201, "type": "git", "url": "https://git.b4l.co.th/B4L/cnx-network-clan" }, diff --git a/machines/stellio/configuration.nix b/machines/stellio/configuration.nix index ad47162..f99937d 100644 --- a/machines/stellio/configuration.nix +++ b/machines/stellio/configuration.nix @@ -1,4 +1,10 @@ -{ inputs, lib, ... }: +{ + config, + inputs, + lib, + pkgs, + ... +}: { imports = [ inputs.matthew-hardware.nixosModules.mt7986a-glinet-gl-mt6000 @@ -27,5 +33,20 @@ clan.core.settings.name = "stellio"; clan.core.settings.machine.description = "Flint-2 router"; + + # nixpkgs' services.blocky check runs the aarch64 blocky in a + # system.checks derivation, which an x86_64 builder without binfmt cannot + # execute (`--max-jobs 0` -> Exec format error). Validate the same YAML + # with the build host's blocky instead. Drop once cnx-network's router + # service carries this itself (router/dns: validate the Blocky config + # with the build host's binary). + services.blocky.enableConfigCheck = false; + system.checks = [ + (pkgs.runCommand "check-blocky-config" { } '' + ${lib.getExe pkgs.buildPackages.blocky} --config ${ + (pkgs.formats.yaml { }).generate "blocky-config.yaml" config.services.blocky.settings + } validate && touch $out + '') + ]; }; }