From b71518e75222f9dd8fdcef21031221543cb39371 Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Wed, 19 Aug 2026 10:46:35 +0800 Subject: [PATCH 1/9] warpgate: 0.26.1 -> 0.28.0 --- .../wa/warpgate/hardcode-version.patch | 22 ++++------- pkgs/by-name/wa/warpgate/package.nix | 38 ++++++++++++------- .../warpgate/remove-nightly-rustflags.patch | 31 --------------- .../wa/warpgate/web-ui-package-json.patch | 24 ++++++------ 4 files changed, 43 insertions(+), 72 deletions(-) delete mode 100644 pkgs/by-name/wa/warpgate/remove-nightly-rustflags.patch diff --git a/pkgs/by-name/wa/warpgate/hardcode-version.patch b/pkgs/by-name/wa/warpgate/hardcode-version.patch index 359c7bd04c10..5481d48a2d1a 100644 --- a/pkgs/by-name/wa/warpgate/hardcode-version.patch +++ b/pkgs/by-name/wa/warpgate/hardcode-version.patch @@ -1,20 +1,12 @@ diff --git a/warpgate-common/src/version.rs b/warpgate-common/src/version.rs -index 0e7985a..62c2b67 100644 +index 31104706..ec201419 100644 --- a/warpgate-common/src/version.rs +++ b/warpgate-common/src/version.rs -@@ -1,14 +1,3 @@ --use git_version::git_version; -- - pub const fn warpgate_version() -> &'static str { -- git_version!( -- args = [ -- "--tags", -- "--always", -- "--dirty=-modified", -- "--match", -- "v[0-9]*" -- ], +@@ -9,6 +9,6 @@ pub const fn warpgate_version() -> &'static str { + "--match", + "v[0-9]*" + ], - fallback = "unknown" -- ) -+ "v@version@" ++ fallback = "v@version@" + ) } diff --git a/pkgs/by-name/wa/warpgate/package.nix b/pkgs/by-name/wa/warpgate/package.nix index e9136ea3cdfc..8672b035d5bf 100644 --- a/pkgs/by-name/wa/warpgate/package.nix +++ b/pkgs/by-name/wa/warpgate/package.nix @@ -7,20 +7,24 @@ openapi-generator-cli, nixosTests, nix-update-script, + perl, + withRDPLegacyTLSBackend ? false, }: rustPlatform.buildRustPackage ( finalAttrs: let - warpgate-web = buildNpmPackage { - pname = "${finalAttrs.pname}-web"; + webUi = buildNpmPackage { + pname = "warpgate-web"; version = finalAttrs.version; src = finalAttrs.src; sourceRoot = "${finalAttrs.src.name}/warpgate-web"; - patches = [ ./web-ui-package-json.patch ]; + patches = [ + ./web-ui-package-json.patch + ]; - npmDepsHash = "sha256-McQI5EmTfrbdcWnYRsoRHjhZphrZVaV/fN9i9MX8XF0="; + npmDepsHash = "sha256-x3N5fW7g1wyXvTcLdZBcg1Rv57o2dyqIaEyDiZK0T14="; nativeBuildInputs = [ openapi-generator-cli ]; @@ -35,45 +39,51 @@ rustPlatform.buildRustPackage ( in { pname = "warpgate"; - version = "0.26.1"; + version = "0.28.0"; src = fetchFromGitHub { owner = "warp-tech"; repo = "warpgate"; tag = "v${finalAttrs.version}"; - hash = "sha256-1Dg7bzhBQNe+u90Tw+kcmVaxV5IK0/t505HZr18qP5I="; + hash = "sha256-yRm8c/SZ0SvDsRkJlGNJOMtl2iOqfqxJskceQFp+zkw="; }; - cargoHash = "sha256-A5rRLrqlAZV/3ID8F+wUO8OP3Ocivg7vYrNDiMqRKik="; + cargoHash = "sha256-RPARpBFnQbDKy/uXM150nf0xJqOU0Nbw2b6e0Ch61Uw="; patches = [ (replaceVars ./hardcode-version.patch { inherit (finalAttrs) version; }) - ./remove-nightly-rustflags.patch ]; - env.RUSTFLAGS = "--cfg tokio_unstable"; + env = { + # uses nightly feature: gethostname, once_cell_try + RUSTC_BOOTSTRAP = true; + RUSTFLAGS = "--cfg tokio_unstable"; + }; + + nativeBuildInputs = lib.optional withRDPLegacyTLSBackend perl; buildFeatures = [ "postgres" "mysql" "sqlite" - ]; + ] + ++ lib.optional withRDPLegacyTLSBackend "rdp-openssl-tls"; preBuild = '' - rm -r .cargo/ - ln -rs "${warpgate-web}" warpgate-web/dist + rm -rf .cargo/ + ln -rs "${webUi}" warpgate-web/dist ''; # skip check, project included tests require python stuff and docker doCheck = false; passthru = { - inherit warpgate-web; + inherit webUi; tests = { inherit (nixosTests) warpgate; }; updateScript = nix-update-script { - extraArgs = [ "--subpackage=warpgate-web" ]; + extraArgs = [ "--subpackage=webUi" ]; }; }; diff --git a/pkgs/by-name/wa/warpgate/remove-nightly-rustflags.patch b/pkgs/by-name/wa/warpgate/remove-nightly-rustflags.patch deleted file mode 100644 index caa2ceba247d..000000000000 --- a/pkgs/by-name/wa/warpgate/remove-nightly-rustflags.patch +++ /dev/null @@ -1,31 +0,0 @@ -diff --git a/Cargo.toml b/Cargo.toml -index 0e92acb..d187ebc 100644 ---- a/Cargo.toml -+++ b/Cargo.toml -@@ -1,5 +1,3 @@ --cargo-features = ["profile-rustflags"] -- - [workspace] - members = [ - "warpgate", -@@ -160,20 +158,2 @@ - [profile.coverage] - inherits = "dev" -- --[profile.dev.package.aws-sdk-ec2] --hint-mostly-unused = true -- --[profile.release.package.aws-sdk-ec2] --hint-mostly-unused = true -- --[profile.dev.package.aws-sdk-rds] --hint-mostly-unused = true -- --[profile.release.package.aws-sdk-rds] --hint-mostly-unused = true -- --[profile.dev.package.aws-sdk-eks] --hint-mostly-unused = true -- --[profile.release.package.aws-sdk-eks] --hint-mostly-unused = true diff --git a/pkgs/by-name/wa/warpgate/web-ui-package-json.patch b/pkgs/by-name/wa/warpgate/web-ui-package-json.patch index 973c19a97f8b..62e56c10bf6e 100644 --- a/pkgs/by-name/wa/warpgate/web-ui-package-json.patch +++ b/pkgs/by-name/wa/warpgate/web-ui-package-json.patch @@ -1,15 +1,15 @@ diff --git a/package.json b/package.json -index 0f1d768..c070a59 100644 +index d8734a74..513d5606 100644 --- a/package.json +++ b/package.json -@@ -12,8 +12,8 @@ - "postinstall": "npm run openapi:client:gateway && npm run openapi:client:admin", - "openapi:schema:gateway": "cargo run -p warpgate-protocol-http > src/gateway/lib/openapi-schema.json", - "openapi:schema:admin": "cargo run -p warpgate-admin > src/admin/lib/openapi-schema.json", -- "openapi:client:gateway": "openapi-generator-cli generate -g typescript-fetch -i src/gateway/lib/openapi-schema.json -o src/gateway/lib/api-client -p npmName=warpgate-gateway-api-client -p useSingleRequestParameter=true && cd src/gateway/lib/api-client && npm i typescript@5 && npm i && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json", -- "openapi:client:admin": "openapi-generator-cli generate -g typescript-fetch -i src/admin/lib/openapi-schema.json -o src/admin/lib/api-client -p npmName=warpgate-admin-api-client -p useSingleRequestParameter=true && cd src/admin/lib/api-client && npm i typescript@5 && npm i && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json", -+ "openapi:client:gateway": "openapi-generator-cli generate -g typescript-fetch -i src/gateway/lib/openapi-schema.json -o src/gateway/lib/api-client -p npmName=warpgate-gateway-api-client -p useSingleRequestParameter=true && ln -sr node_modules src/gateway/lib/api-client/node_modules && cd src/gateway/lib/api-client && npx tsc --target esnext --moduleResolution node && npx tsc -p tsconfig.esm.json --target esnext --moduleResolution node && rm -rf src tsconfig.json tsconfig.esm.json", -+ "openapi:client:admin": "openapi-generator-cli generate -g typescript-fetch -i src/admin/lib/openapi-schema.json -o src/admin/lib/api-client -p npmName=warpgate-admin-api-client -p useSingleRequestParameter=true && ln -sr node_modules src/admin/lib/api-client/node_modules && cd src/admin/lib/api-client && npx tsc --target esnext --moduleResolution node && npx tsc -p tsconfig.esm.json --target esnext --moduleResolution node && rm -rf src tsconfig.json tsconfig.esm.json", - "openapi:tests-sdk": "openapi-generator-cli generate -g python -i src/admin/lib/openapi-schema.json -o ../tests/api_sdk", - "openapi": "npm run openapi:schema:admin && npm run openapi:schema:gateway && npm run openapi:client:admin && npm run openapi:client:gateway" - }, +@@ -16,8 +16,8 @@ + "postinstall": "npm run openapi:client:gateway && npm run openapi:client:admin", + "openapi:schema:gateway": "cargo run -p warpgate-protocol-http > src/gateway/lib/openapi-schema.json", + "openapi:schema:admin": "cargo run -p warpgate-admin > src/admin/lib/openapi-schema.json", +- "openapi:client:gateway": "openapi-generator-cli generate -g typescript-fetch -i src/gateway/lib/openapi-schema.json -o src/gateway/lib/api-client -p npmName=warpgate-gateway-api-client -p useSingleRequestParameter=true && cd src/gateway/lib/api-client && npm i typescript@5 && npm i && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json", +- "openapi:client:admin": "openapi-generator-cli generate -g typescript-fetch -i src/admin/lib/openapi-schema.json -o src/admin/lib/api-client -p npmName=warpgate-admin-api-client -p useSingleRequestParameter=true && cd src/admin/lib/api-client && npm i typescript@5 && npm i && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json", ++ "openapi:client:gateway": "openapi-generator-cli generate -g typescript-fetch -i src/gateway/lib/openapi-schema.json -o src/gateway/lib/api-client -p npmName=warpgate-gateway-api-client -p useSingleRequestParameter=true && ln -sr node_modules src/gateway/lib/api-client/node_modules && cd src/gateway/lib/api-client && npx tsc --target esnext --moduleResolution node && npx tsc -p tsconfig.esm.json --target esnext --moduleResolution node && rm -rf src tsconfig.json tsconfig.esm.json", ++ "openapi:client:admin": "openapi-generator-cli generate -g typescript-fetch -i src/admin/lib/openapi-schema.json -o src/admin/lib/api-client -p npmName=warpgate-admin-api-client -p useSingleRequestParameter=true && ln -sr node_modules src/admin/lib/api-client/node_modules && cd src/admin/lib/api-client && npx tsc --target esnext --moduleResolution node && npx tsc -p tsconfig.esm.json --target esnext --moduleResolution node && rm -rf src tsconfig.json tsconfig.esm.json", + "openapi:tests-sdk": "openapi-generator-cli generate -g python -i src/admin/lib/openapi-schema.json -o ../tests/api_sdk", + "openapi": "npm run openapi:schema:admin && npm run openapi:schema:gateway && npm run openapi:client:admin && npm run openapi:client:gateway" + }, From 441b7a7035c6c7ce1926de55f762290672b7a751 Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Wed, 19 Aug 2026 10:58:22 +0800 Subject: [PATCH 2/9] nixos/warpgate: configurable advertised MySQL server version --- nixos/modules/services/security/warpgate.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/nixos/modules/services/security/warpgate.nix b/nixos/modules/services/security/warpgate.nix index 3547d199cae0..50b4811e66b6 100644 --- a/nixos/modules/services/security/warpgate.nix +++ b/nixos/modules/services/security/warpgate.nix @@ -301,6 +301,14 @@ in default = "/var/lib/warpgate/tls.key.pem"; type = str; }; + advertised_version = mkOption { + description = '' + The server version advertised to clients during the handshake. + Warpgate can't auto-match the target's version since the target is only known after the handshake, but Warpgate's clients use it to pick a protocol dialect. + ''; + default = "8.0.3-Warpgate"; + type = str; + }; }; postgres = { enable = mkOption { From 315434f232c300c52e49c421bf6279be01ac69e8 Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Wed, 19 Aug 2026 10:58:47 +0800 Subject: [PATCH 3/9] nixos/warpgate: proxy protocol support --- nixos/modules/services/security/warpgate.nix | 25 ++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/nixos/modules/services/security/warpgate.nix b/nixos/modules/services/security/warpgate.nix index 50b4811e66b6..35557c75eae8 100644 --- a/nixos/modules/services/security/warpgate.nix +++ b/nixos/modules/services/security/warpgate.nix @@ -160,6 +160,11 @@ in default = "[::]:2222"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The SSH listener is reachable via this domain name externally."; default = null; @@ -201,6 +206,11 @@ in default = "[::]:8888"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The HTTP listener is reachable via this domain name externally."; default = null; @@ -281,6 +291,11 @@ in default = "[::]:33306"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The MySQL listener is reachable via this domain name externally."; default = null; @@ -321,6 +336,11 @@ in default = "[::]:55432"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The PostgreSQL listener is reachable via this domain name externally."; default = null; @@ -353,6 +373,11 @@ in default = "[::]:8443"; type = str; }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy."; + default = false; + type = bool; + }; external_host = mkOption { description = "The Kubernetes listener is reachable via this domain name externally."; default = null; From accca4bd9520fdd0cb1b226da953c4eb2d9fb89f Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Wed, 19 Aug 2026 11:11:25 +0800 Subject: [PATCH 4/9] nixos/warpgate: RDP and VNC support --- nixos/modules/services/security/warpgate.nix | 82 ++++++++++++++++++++ 1 file changed, 82 insertions(+) diff --git a/nixos/modules/services/security/warpgate.nix b/nixos/modules/services/security/warpgate.nix index 35557c75eae8..42c8798295e4 100644 --- a/nixos/modules/services/security/warpgate.nix +++ b/nixos/modules/services/security/warpgate.nix @@ -280,6 +280,88 @@ in type = str; }; }; + rdp = { + enable = mkOption { + description = "Whether to enable RDP listener."; + default = false; + type = bool; + }; + listen = mkOption { + description = "Listen endpoint of RDP listener."; + default = "[::]:3389"; + type = str; + }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from the listener's peer."; + default = false; + type = bool; + }; + external_host = mkOption { + description = "The RDP listener is reachable via this domain name externally."; + default = null; + type = nullOr str; + }; + external_port = mkOption { + description = "The RDP listener is reachable via this port externally."; + default = null; + type = nullOr str; + }; + certificate = mkOption { + description = "Path to RDP listener certificate."; + default = "/var/lib/warpgate/tls.certificate.pem"; + type = str; + }; + key = mkOption { + description = "Path to RDP listener private key."; + default = "/var/lib/warpgate/tls.key.pem"; + type = str; + }; + }; + vnc = { + enable = mkOption { + description = "Whether to enable VNC listener."; + default = false; + type = bool; + }; + listen = mkOption { + description = "Listen endpoint of VNC listener."; + default = "[::]:5900"; + type = str; + }; + proxy_protocol = mkOption { + description = "Accept HAProxy PROXY protocol v1/v2 headers from the listener's peer."; + default = false; + type = bool; + }; + external_host = mkOption { + description = "The VNC listener is reachable via this domain name externally."; + default = null; + type = nullOr str; + }; + external_port = mkOption { + description = "The VNC listener is reachable via this port externally."; + default = null; + type = nullOr str; + }; + certificate = mkOption { + description = "Path to VNC listener certificate."; + default = "/var/lib/warpgate/tls.certificate.pem"; + type = str; + }; + key = mkOption { + description = "Path to VNC listener private key."; + default = "/var/lib/warpgate/tls.key.pem"; + type = str; + }; + enable_ard_auth = mkOption { + description = '' + Enable Apple-DH (Apple Remote Desktop / type 30) auth, which is to ensure compatibility with Apple clients. + However [connections from macOS built-in VNC client with ARD auth is not supported](https://github.com/warp-tech/warpgate/blob/47e676969a0b1e0b8456f9a5f1474d6c58648c4f/warpgate-protocol-vnc/src/server/rfb.rs#L8-L10). + ''; + default = false; + type = bool; + }; + }; mysql = { enable = mkOption { description = "Whether to enable MySQL listener."; From fdfbcde1ef0635d9231052e726013566bf63bf71 Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Wed, 19 Aug 2026 11:51:19 +0800 Subject: [PATCH 5/9] nixos/warpgate: drop `settings.recordings` --- nixos/modules/services/security/warpgate.nix | 16 ++++------------ 1 file changed, 4 insertions(+), 12 deletions(-) diff --git a/nixos/modules/services/security/warpgate.nix b/nixos/modules/services/security/warpgate.nix index 42c8798295e4..6fc3efdca8f3 100644 --- a/nixos/modules/services/security/warpgate.nix +++ b/nixos/modules/services/security/warpgate.nix @@ -120,18 +120,6 @@ in ] ''; }; - recordings = { - enable = mkOption { - description = "Whether to enable session recording."; - default = true; - type = bool; - }; - path = mkOption { - description = "Path to store session recordings."; - default = "/var/lib/warpgate/recordings"; - type = str; - }; - }; external_host = mkOption { description = '' Configure the domain name of this Warpgate instance. @@ -582,6 +570,10 @@ in assertion = !(lib.hasAttr "config_provider" cfg.settings); message = "`services.warpgate.settings.config_provider` is a legacy option that has been removed since 0.14.0. Please do not set this option."; } + { + assertion = !(lib.hasAttr "recordings" cfg.settings); + message = "`services.warpgate.settings.recordings` has been deprecated by S3 recording storage support in 0.27.0. Please remove this section from your config and set it from admin UI."; + } ]; environment.systemPackages = [ cfg.package ]; From e8112eeda652937b42901d64b49f6392e1efaa83 Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Wed, 19 Aug 2026 11:16:05 +0800 Subject: [PATCH 6/9] nixos/tests/warpgate: fix typo --- nixos/tests/warpgate.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/tests/warpgate.nix b/nixos/tests/warpgate.nix index 64ec9bd6dc22..5a0969398c13 100644 --- a/nixos/tests/warpgate.nix +++ b/nixos/tests/warpgate.nix @@ -9,7 +9,7 @@ }; machine2 = { - environment.etc."warpgate-db-url".text = "database: sqlite:/var/lib/warpgate/db/"; + environment.etc."warpgate-db-url".text = "database_url: sqlite:/var/lib/warpgate/db/"; services.warpgate = { enable = true; databaseUrlFile = "/etc/warpgate-db-url"; From 5d95c61e4e1de9f2638ca2f56d360d1ee087a4aa Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Wed, 19 Aug 2026 11:17:20 +0800 Subject: [PATCH 7/9] nixos/tests/warpgate: test enable all listeners --- nixos/tests/warpgate.nix | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/nixos/tests/warpgate.nix b/nixos/tests/warpgate.nix index 5a0969398c13..d8e2c8e70c1c 100644 --- a/nixos/tests/warpgate.nix +++ b/nixos/tests/warpgate.nix @@ -24,6 +24,12 @@ enable = true; settings = { http.listen = "[::]:443"; + ssh.enable = true; + rdp.enable = true; + vnc.enable = true; + mysql.enable = true; + postgres.enable = true; + kubernetes.enable = true; }; }; }; @@ -43,6 +49,12 @@ machine3.wait_for_unit("warpgate.service") machine3.wait_for_open_port(443) + machine3.wait_for_open_port(2222) + machine3.wait_for_open_port(3389) + machine3.wait_for_open_port(5900) + machine3.wait_for_open_port(33306) + machine3.wait_for_open_port(55432) + machine3.wait_for_open_port(8443) machine3.succeed("curl -k --fail https://localhost/@warpgate") machine3.shutdown() ''; From a2cba672c94f26bad885c1227af81ef1cf5500ef Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Fri, 21 Aug 2026 22:07:12 +0800 Subject: [PATCH 8/9] nixos/warpgate: support encrypting credentials at rest --- nixos/modules/services/security/warpgate.nix | 66 +++++++++++++------- nixos/tests/warpgate.nix | 18 +++++- 2 files changed, 61 insertions(+), 23 deletions(-) diff --git a/nixos/modules/services/security/warpgate.nix b/nixos/modules/services/security/warpgate.nix index 6fc3efdca8f3..1ddcb2cf9ff5 100644 --- a/nixos/modules/services/security/warpgate.nix +++ b/nixos/modules/services/security/warpgate.nix @@ -45,6 +45,17 @@ in default = null; }; + databaseEncryptionKeysFile = mkOption { + description = '' + Path to file containing encryption key(s) to encrypt target credentials stored in database. + Should be a env-like file: `WARPGATE_ENCRYPTION_KEY=$(openssl rand -base64 32)`. + If you are rotating key, move the old key to `WARPGATE_ENCRYPTION_KEY_OLD`. + See [Encrypting credentials at rest](https://warpgate.null.page/encryption/). + ''; + type = nullOr str; + default = null; + }; + settings = mkOption { description = "Warpgate configuration."; type = submodule { @@ -523,36 +534,45 @@ in any map head + optional reverseList ; - inherit (lib.strings) splitString toIntBase10; + inherit (lib.strings) + optionalString + splitString + toIntBase10 + ; - preStartScript = pkgs.writers.writeBash "warpgate-init" '' - CFGFILE=/var/lib/warpgate/config.yaml + renderedYamlConfig = yaml.generate "warpgate-config" cfg.settings; + + startupScript = pkgs.writeShellScript "warpgate-run" '' + CFGFILE=$STATE_DIRECTORY/config.yaml if [ ! -O $CFGFILE ] || [ ! -s $CFGFILE ]; then INITPWD=$(tr -dc 'A-Za-z0-9!?%=' /dev/null | head -c 16) ${lib.getExe cfg.package} \ --config $CFGFILE unattended-setup \ - --data-path /var/lib/warpgate \ + --data-path $STATE_DIRECTORY \ --http-port 8888 \ --admin-password $INITPWD fi - ${ - if cfg.databaseUrlFile != null then - '' - sed -e '/^database_url: null/d' ${yaml.generate "warpgate-config" cfg.settings} > $CFGFILE - cat /run/credentials/warpgate.service/databaseUrl >> $CFGFILE - '' - else - "cp --no-preserve=ownership ${yaml.generate "warpgate-config" cfg.settings} $CFGFILE" - } + cp --no-preserve=ownership ${renderedYamlConfig} $CFGFILE + ${optionalString (cfg.databaseUrlFile != null) '' + sed -e '/^database_url: null/d' ${renderedYamlConfig} > $CFGFILE + cat $CREDENTIALS_DIRECTORY/databaseUrl >> $CFGFILE + ''} + ${optionalString (cfg.databaseEncryptionKeysFile != null) '' + set -a + source $CREDENTIALS_DIRECTORY/dbEncryptionKeys + set +a + ''} + ${lib.getExe cfg.package} --config $CFGFILE run ''; bindOnPrivilegedPorts = any (x: toIntBase10 x < 1025) ( map (x: head (reverseList (splitString ":" x))) ( [ cfg.settings.http.listen ] - ++ lib.optional cfg.settings.ssh.enable cfg.settings.ssh.listen - ++ lib.optional cfg.settings.mysql.enable cfg.settings.mysql.listen - ++ lib.optional cfg.settings.postgres.enable cfg.settings.postgres.listen + ++ optional cfg.settings.ssh.enable cfg.settings.ssh.listen + ++ optional cfg.settings.mysql.enable cfg.settings.mysql.listen + ++ optional cfg.settings.postgres.enable cfg.settings.postgres.listen ) ); in @@ -581,14 +601,16 @@ in systemd.services.warpgate = { description = "Warpgate smart bastion"; wantedBy = [ "multi-user.target" ]; - after = [ "network.target" ]; + wants = [ "network-online.target" ]; + after = [ "network-online.target" ]; startLimitBurst = 5; serviceConfig = { - LoadCredential = "${ - if cfg.databaseUrlFile != null then "databaseUrl:${cfg.databaseUrlFile}" else "" - }"; - ExecStartPre = preStartScript; - ExecStart = "${lib.getExe cfg.package} --config /var/lib/warpgate/config.yaml run"; + LoadCredential = + optional (cfg.databaseUrlFile != null) "databaseUrl:${cfg.databaseUrlFile}" + ++ optional ( + cfg.databaseEncryptionKeysFile != null + ) "dbEncryptionKeys:${cfg.databaseEncryptionKeysFile}"; + ExecStart = startupScript; DynamicUser = true; RestartSec = 3; Restart = "on-failure"; diff --git a/nixos/tests/warpgate.nix b/nixos/tests/warpgate.nix index d8e2c8e70c1c..518fcbcd7733 100644 --- a/nixos/tests/warpgate.nix +++ b/nixos/tests/warpgate.nix @@ -1,3 +1,4 @@ +{ pkgs, ... }: { name = "warpgate"; @@ -9,14 +10,29 @@ }; machine2 = { - environment.etc."warpgate-db-url".text = "database_url: sqlite:/var/lib/warpgate/db/"; + environment.etc."warpgate-db-url".text = + "database_url: postgresql://warpgate:warpgate@localhost:5432/warpgate"; + environment.etc."warpgate-db-enc".text = + "WARPGATE_ENCRYPTION_KEY=QVJBTkRPTTMyQ0hBUkFDVEVSU0VOQ1JZUFRJT05LRVk="; services.warpgate = { enable = true; databaseUrlFile = "/etc/warpgate-db-url"; + databaseEncryptionKeysFile = "/etc/warpgate-db-enc"; settings = { database_url = null; }; }; + services.postgresql = { + enable = true; + initialScript = pkgs.writeText "psql-init" '' + CREATE ROLE warpgate WITH LOGIN PASSWORD 'warpgate'; + CREATE DATABASE warpgate WITH OWNER warpgate; + ''; + }; + systemd.services.warpgate = { + after = [ "postgresql.target" ]; + requires = [ "postgresql.target" ]; + }; }; machine3 = { From ab373569a379d85eacdd404853673443b7da8f28 Mon Sep 17 00:00:00 2001 From: Lemon Lam Date: Fri, 21 Aug 2026 23:18:04 +0800 Subject: [PATCH 9/9] warpgate: 0.28.0 -> 0.28.4 --- pkgs/by-name/wa/warpgate/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/wa/warpgate/package.nix b/pkgs/by-name/wa/warpgate/package.nix index 8672b035d5bf..b61d13c757d3 100644 --- a/pkgs/by-name/wa/warpgate/package.nix +++ b/pkgs/by-name/wa/warpgate/package.nix @@ -24,7 +24,7 @@ rustPlatform.buildRustPackage ( ./web-ui-package-json.patch ]; - npmDepsHash = "sha256-x3N5fW7g1wyXvTcLdZBcg1Rv57o2dyqIaEyDiZK0T14="; + npmDepsHash = "sha256-BfmYRfsxdJZuS/c7bGccXXYktsjQ76mjwTFKLvNsGAg="; nativeBuildInputs = [ openapi-generator-cli ]; @@ -39,16 +39,16 @@ rustPlatform.buildRustPackage ( in { pname = "warpgate"; - version = "0.28.0"; + version = "0.28.4"; src = fetchFromGitHub { owner = "warp-tech"; repo = "warpgate"; tag = "v${finalAttrs.version}"; - hash = "sha256-yRm8c/SZ0SvDsRkJlGNJOMtl2iOqfqxJskceQFp+zkw="; + hash = "sha256-BWfkStxPi4LucoADK1YwRZaQwObPtq08eEVK9XG7vfU="; }; - cargoHash = "sha256-RPARpBFnQbDKy/uXM150nf0xJqOU0Nbw2b6e0Ch61Uw="; + cargoHash = "sha256-TVNOCMmL8ICtQImA39jhlfCnghvV90NlRBdSol2MGtY="; patches = [ (replaceVars ./hardcode-version.patch { inherit (finalAttrs) version; })