- Preflight validation now validates against the endpoint that issued
the token (IMDS_BASE_URL) instead of re-scanning all endpoints. The
previous behavior could silently switch to a different endpoint and
wasted time retrying unreachable ones.
- Add local keyword to endpoint variables in get_imds_token and
preflight_imds_token to avoid polluting global scope.
Updates the EC2 IMDS metadata fetcher script to support IPv6 endpoints. If you start an instance in an IPv6 subnet, if the EC2 instance gets an IPv6 address before the IPv4 address (extremely common), systemd will trigger the IMDS fetcher script and fail to fetch your NixOS configuration, leaving you with a useless unconfigured EC2 instance. This at least allows the NixOS configuration to be fetched and applied.
Refactor try_decompress to use a decompress_cmd variable, making it
straightforward to add new compression formats. Add bzip2 support
and a corresponding NixOS test.
- Declare `ftype` as local to avoid leaking into caller scope
- Skip decompression attempt on empty files
- Clean up temp file on decompression failure
This prints the whole host public keys in the same format as cloud-init.
The main benefit is that this allows the direct generation of a known_hosts
file, simplifying client setup.
This commit also provides a new NixOS test that's an alternative to the
currently broken nixos/tests/ec2.nix tests.
We don't need both wget and curl, so let's use only curl (which is
part of a minimal NixOS closure, unlike wget).
Logging to the console is helpful for debugging.