forked from boinkor-net/tsnsrv
-
Notifications
You must be signed in to change notification settings - Fork 0
/
flake.nix
160 lines (147 loc) · 4.84 KB
/
flake.nix
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
{
outputs = inputs @ {
self,
flake-parts,
flocken,
nixpkgs,
...
}:
flake-parts.lib.mkFlake {inherit inputs;} {
imports = [
inputs.devshell.flakeModule
inputs.flake-parts.flakeModules.easyOverlay
];
systems = [
"x86_64-darwin"
"x86_64-linux"
"aarch64-darwin"
"aarch64-linux"
];
perSystem = {
config,
pkgs,
final,
system,
...
}: let
tsnsrvPkg = p:
p.buildGo121Module {
pname = "tsnsrv";
version = "0.0.0";
vendorHash = builtins.readFile ./tsnsrv.sri;
src = with p; lib.sourceFilesBySuffices (lib.sources.cleanSource ./.) [".go" ".mod" ".sum"];
meta.mainProgram = "tsnsrv";
};
imageArgs = p: {
name = "tsnsrv";
tag = "latest";
contents = [
(p.buildEnv {
name = "image-root";
paths = [(tsnsrvPkg p)];
pathsToLink = ["/bin" "/tmp"];
})
p.dockerTools.caCertificates
];
config.EntryPoint = ["/bin/tsnsrv"];
};
in {
overlayAttrs = {
inherit (config.packages) tsnsrv tsnsrvOciImage;
};
packages = {
default = config.packages.tsnsrv;
tsnsrv = tsnsrvPkg pkgs;
# This platform's "natively" built docker image:
tsnsrvOciImage = pkgs.dockerTools.buildLayeredImage (imageArgs pkgs);
# "cross-platform" build, mainly to support building on github actions (but also on macOS with apple silicon):
tsnsrvOciImage-cross-aarch64-linux = pkgs.pkgsCross.aarch64-multiplatform.dockerTools.buildLayeredImage (imageArgs pkgs.pkgsCross.aarch64-multiplatform);
# To provide a smoother dev experience:
regenSRI = let
nardump = pkgs.buildGoModule rec {
pname = "nardump";
version = "1.38.4";
src = pkgs.fetchFromGitHub {
owner = "tailscale";
repo = "tailscale";
rev = "v${version}";
sha256 = "sha256-HjN8VzysxQvx5spXgbgbItH3y1bLbfHO+udNQMuyhAk=";
};
vendorSha256 = "sha256-LIvaxSo+4LuHUk8DIZ27IaRQwaDnjW6Jwm5AEc/V95A=";
subPackages = ["cmd/nardump"];
};
in
pkgs.writeShellApplication {
name = "regenSRI";
text = ''
set -eu -o pipefail
src="$(pwd)"
temp="$(mktemp -d)"
trap 'rm -rf "$temp"' EXIT
go mod vendor -o "$temp"
${nardump}/bin/nardump -sri "$temp" >"$src/tsnsrv.sri"
'';
};
};
apps = {
default = config.apps.tsnsrv;
tsnsrv.program = config.packages.tsnsrv;
streamTsnsrvOciImage.program = "${pkgs.dockerTools.streamLayeredImage imageArgs}";
pushImagesToGhcr = {
program = flocken.legacyPackages.${system}.mkDockerManifest (let
ref = builtins.getEnv "GITHUB_REF_NAME";
branch =
if pkgs.lib.hasSuffix "/merge" ref
then "pr-${pkgs.lib.removeSuffix "/merge" ref}"
else ref;
in {
inherit branch;
name = "ghcr.io/" + builtins.getEnv "GITHUB_REPOSITORY";
version = builtins.getEnv "VERSION";
# Here we build the x86_64-linux variants only because
# that is what runs on GHA, whence we push the images to
# ghcr.
images = with self.packages; [
x86_64-linux.tsnsrvOciImage
x86_64-linux.tsnsrvOciImage-cross-aarch64-linux
];
});
type = "app";
};
};
formatter = pkgs.alejandra;
devshells.default = {
commands = [
{
name = "regenSRI";
category = "dev";
help = "Regenerate tsnsrv.sri in case the module SRI hash should change";
command = "${config.packages.regenSRI}/bin/regenSRI";
}
];
packages = [
pkgs.go_1_21
pkgs.gopls
(pkgs.golangci-lint.override
{buildGoModule = args: (pkgs.buildGo121Module args);})
];
};
};
flake.nixosModules = {
default = import ./nixos {flake = self;};
};
};
inputs = {
flake-parts.url = "github:hercules-ci/flake-parts";
devshell.url = "github:numtide/devshell";
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
flake-compat = {
url = "github:edolstra/flake-compat";
flake = false;
};
flocken = {
url = "github:mirkolenz/flocken/v1";
inputs.nixpkgs.follows = "nixpkgs";
};
};
}