ci-deploy: grant the trigger user polkit access to nixos-upgrade #26

Merged
repomaa merged 1 commit from fix/ci-deploy-polkit into main 2026-09-28 01:26:45 +03:00
Collaborator

Run #316 (ci: validate deploy key and run ssh -T before deploy) showed the deploy key itself is now fine — ssh -T connected and the forced command ran — but the trigger script's systemctl start --wait nixos-upgrade.service was denied:

Failed to start nixos-upgrade.service: Access denied as the requested operation requires interactive authentication. However, interactive authentication has not been enabled by the calling program.

The forced command runs as the non-interactive ci-deploy user, so polkit checks the start request and denies it without a rule. This PR adds a security.polkit.extraConfig rule inside modules/ci-deploy.nix allowing exactly the ci-deploy user to start exactly nixos-upgrade.service (polkit is already enabled on freun-dev for the netbird rules; this only adds the scoped rule).

Verified: nix eval + full nix build of nixosConfigurations.freun-dev.config.system.build.toplevel; the merged security.polkit.extraConfig contains both the netbird rules and the new nixos-upgrade rule; polkit.enable = true.

Run #316 (`ci: validate deploy key and run ssh -T before deploy`) showed the deploy key itself is now fine — `ssh -T` connected and the forced command ran — but the trigger script's `systemctl start --wait nixos-upgrade.service` was denied: ``` Failed to start nixos-upgrade.service: Access denied as the requested operation requires interactive authentication. However, interactive authentication has not been enabled by the calling program. ``` The forced command runs as the non-interactive `ci-deploy` user, so polkit checks the start request and denies it without a rule. This PR adds a `security.polkit.extraConfig` rule inside `modules/ci-deploy.nix` allowing exactly the `ci-deploy` user to start exactly `nixos-upgrade.service` (polkit is already enabled on freun-dev for the netbird rules; this only adds the scoped rule). Verified: `nix eval` + full `nix build` of `nixosConfigurations.freun-dev.config.system.build.toplevel`; the merged `security.polkit.extraConfig` contains both the netbird rules and the new nixos-upgrade rule; polkit.enable = true.
ci-deploy: grant the trigger user polkit access to nixos-upgrade
All checks were successful
Build Images / build (pull_request) Successful in 39s
Check / check (pull_request) Successful in 4m34s
2b07224c69
The forced command runs as the non-interactive ci-deploy user, so
systemctl start --wait nixos-upgrade.service is polkit-checked and was
denied with 'Access denied ... interactive authentication has not been
enabled'. Allow exactly that user to start exactly that unit.
repomaa scheduled this pull request to auto merge when all checks succeed 2026-09-28 01:25:54 +03:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
repomaa/nixos!26
No description provided.