windows: seal mode -- generic OOBE-deferred base, per-VM data on a config CD

A sealed image bakes no per-VM data. generalize.nix gains a gated
configMedium flag (false path byte-identical, so the shared macOS
generalize path is untouched): the baked answer file stays generic and
the target's first boot reads hostname/static-IP/timezone/tint off a
small removable CD via a finder (vmix-load-config.cmd) + applier
(vmix-apply-config.ps1), with the static-IP script dot-sourcing the same
config. templates.seal is a thin preset (delayOobeRun + configMedium +
D:\Users profiles + a data disk); images gain a .seal leaf next to
.generalize; makeConfigMedium renders the per-VM ISO.

So one sealed store path is shared by every VM, each mints its own SID
on first boot and builds the whole profile on D:, and only a cheap ISO
is per-VM. Also folds in the delayOobeRun reconcile: extraDisk (and the
audit-mode data-disk init) are gated off under deferral, so a sealed
image ships with no throwaway `data` output -- the target's specialize
formats the host zvol instead.

vms: disks.config.file attaches the config medium as a second CD-ROM.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0117qMyjpuXsjpVAcpJbFD8g
This commit is contained in:
Git Sagar 2026-09-16 13:01:12 -03:00
parent c40f4460e3
commit 702f723e6d
6 changed files with 173 additions and 15 deletions

View file

@ -39,6 +39,18 @@ in rec {
# Generalize (sysprep + OOBE). Pass seal=true for hardware deployment.
generalize = import ./generalize.nix args;
# Seal: a generic OOBE-deferred base whose per-VM data is not baked but
# delivered at deploy time on a config medium (helpers/makeConfigMedium.nix).
# One sealed store path is shared by every VM; each VM's first boot mints its
# own SID and builds the whole profile on the relocated data volume (D:).
# Forces only the structural bits -- account, RDP and locale stay caller args.
seal = templateArgs: generalize ({
delayOobeRun = true;
configMedium = true;
profilesDirectory = "D:\\Users";
dataDisk = { driveLetter = "D"; label = "data"; };
} // templateArgs);
# Offline registry templates
reg = import ./registry args;