diff --git a/pkgs/servers/http/nginx/generic.nix b/pkgs/servers/http/nginx/generic.nix index 52e09101fb9e..362a0defe732 100644 --- a/pkgs/servers/http/nginx/generic.nix +++ b/pkgs/servers/http/nginx/generic.nix @@ -51,11 +51,7 @@ outer@{ let - moduleNames = map ( - mod: - mod.name - or (throw "The nginx module with source ${toString mod.src} does not have a `name` attribute. This prevents duplicate module detection and is no longer supported.") - ) modules; + moduleNames = map (mod: mod.pname) modules; mapModules = attrPath: @@ -67,7 +63,7 @@ let if supports nginxVersion then mod.${attrPath} or [ ] else - throw "Module at ${toString mod.src} does not support nginx version ${nginxVersion}!" + throw "Module ${mod.name} does not support nginx version ${nginxVersion}!" ); in @@ -107,7 +103,7 @@ stdenv.mkDerivation { perl ] ++ buildInputs - ++ mapModules "inputs" + ++ mapModules "buildInputs" ++ lib.optional withGeoIP geoip ++ lib.optional withImageFilter gd; @@ -171,8 +167,7 @@ stdenv.mkDerivation { ++ lib.optional ( stdenv.buildPlatform != stdenv.hostPlatform ) "--crossbuild=${stdenv.hostPlatform.uname.system}::${stdenv.hostPlatform.uname.processor}" - ++ configureFlags - ++ map (mod: "--add-module=${mod.src}") modules; + ++ configureFlags; env = { NIX_CFLAGS_COMPILE = toString ( @@ -213,6 +208,15 @@ stdenv.mkDerivation { preConfigure = '' setOutputFlags= '' + # Make all modules source trees writable + + '' + for module in ${toString modules}; do + dst="$NIX_BUILD_TOP/$(basename "$module")" + cp --recursive "$module" "$dst" + chmod --recursive +w "$dst" + appendToVar configureFlags "--add-module=$dst" + done + '' + preConfigure + lib.concatMapStringsSep "\n" (mod: mod.preConfigure or "") modules; @@ -243,7 +247,7 @@ stdenv.mkDerivation { sha256 = "sha256-M7V3ZJfKImur2OoqXcoL+CbgFj/huWnfZ4xMCmvkqfc="; }) ] - ++ mapModules "patches" + ++ mapModules "nginxPatches" ) ++ extraPatches; diff --git a/pkgs/servers/http/nginx/modules.nix b/pkgs/servers/http/nginx/modules.nix deleted file mode 100644 index 5965512283cd..000000000000 --- a/pkgs/servers/http/nginx/modules.nix +++ /dev/null @@ -1,1124 +0,0 @@ -{ - lib, - config, - nixosTests, - applyPatches, - fetchFromGitHub, - fetchFromGitLab, - fetchhg, - fetchpatch, - runCommand, - stdenv, - - arpa2common, - brotli, - curl, - expat, - fdk_aac, - ffmpeg-headless, - ffmpeg_6-headless, - geoip, - libbsd, - libiconv, - libjpeg, - libkrb5, - libmaxminddb, - libmodsecurity, - libuuid, - libxml2, - lmdb, - luajit_openresty, - msgpuck, - openssl, - pam, - psol, - which, - yajl, - zlib, - zstd, -}: - -let - - http_proxy_connect_module_generic = patchName: rec { - name = "http_proxy_connect"; - src = fetchFromGitHub { - name = "http_proxy_connect_module_generic"; - owner = "chobits"; - repo = "ngx_http_proxy_connect_module"; - # 2023-06-19 - rev = "dcb9a2c614d376b820d774db510d4da12dfe1e5b"; - hash = "sha256-AzMhTSzmk3osSYy2q28/hko1v2AOTnY/dP5IprqGlQo="; - }; - - patches = [ - "${src}/patch/${patchName}.patch" - ]; - - meta = { - description = "Forward proxy module for CONNECT request handling"; - homepage = "https://github.com/chobits/ngx_http_proxy_connect_module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - -in - -let - self = { - akamai-token-validate = { - name = "akamai-token-validate"; - src = fetchFromGitHub { - name = "akamai-token-validate"; - owner = "kaltura"; - repo = "nginx-akamai-token-validate-module"; - rev = "34fd0c94d2c43c642f323491c4f4a226cd83b962"; - sha256 = "0yf34s11vgkcl03wbl6gjngm3p9hs8vvm7hkjkwhjh39vkk2a7cy"; - }; - - inputs = [ openssl ]; - - meta = { - description = "Validates Akamai v2 query string tokens"; - homepage = "https://github.com/kaltura/nginx-akamai-token-validate-module"; - license = lib.licenses.agpl3Only; - maintainers = [ ]; - }; - }; - - auth-a2aclr = { - name = "auth-a2aclr"; - src = fetchFromGitLab { - name = "auth-a2aclr"; - owner = "arpa2"; - repo = "nginx-auth-a2aclr"; - rev = "bbabf9480bb2b40ac581551883a18dfa6522dd63"; - sha256 = "sha256-h2LgMhreCgod+H/bNQzY9BvqG9ezkwikwWB3T6gHH04="; - }; - - inputs = [ - (arpa2common.overrideAttrs (old: rec { - version = "0.7.1"; - - src = fetchFromGitLab { - owner = "arpa2"; - repo = "arpa2common"; - rev = "v${version}"; - sha256 = "sha256-8zVsAlGtmya9EK4OkGUMu2FKJRn2Q3bg2QWGjqcii64="; - }; - })) - ]; - - meta = { - description = "Integrate ARPA2 Resource ACLs into nginx"; - homepage = "https://gitlab.com/arpa2/nginx-auth-a2aclr"; - license = lib.licenses.isc; - maintainers = [ ]; - }; - }; - - aws-auth = { - name = "aws-auth"; - src = fetchFromGitHub { - name = "aws-auth"; - owner = "anomalizer"; - repo = "ngx_aws_auth"; - rev = "2.1.1"; - sha256 = "10z67g40w7wpd13fwxyknkbg3p6hn61i4v8xw6lh27br29v1y6h9"; - }; - - meta = { - description = "Proxy to authenticated AWS services"; - homepage = "https://github.com/anomalizer/ngx_aws_auth"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - brotli = { - name = "brotli"; - src = - let - src' = fetchFromGitHub { - name = "brotli"; - owner = "google"; - repo = "ngx_brotli"; - rev = "6e975bcb015f62e1f303054897783355e2a877dc"; - sha256 = "sha256-G0IDYlvaQzzJ6cNTSGbfuOuSXFp3RsEwIJLGapTbDgo="; - }; - in - runCommand "brotli" { } '' - cp -a ${src'} $out - substituteInPlace $out/filter/config \ - --replace '$ngx_addon_dir/deps/brotli/c' ${lib.getDev brotli} - ''; - - inputs = [ brotli ]; - - meta = { - description = "Brotli compression"; - homepage = "https://github.com/google/ngx_brotli"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - cache-purge = { - name = "cache-purge"; - src = fetchFromGitHub { - name = "cache-purge"; - owner = "nginx-modules"; - repo = "ngx_cache_purge"; - rev = "2.5.1"; - sha256 = "0va4jz36mxj76nmq05n3fgnpdad30cslg7c10vnlhdmmic9vqncd"; - }; - - meta = { - description = "Adds ability to purge content from FastCGI, proxy, SCGI and uWSGI caches"; - homepage = "https://github.com/nginx-modules/ngx_cache_purge"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - coolkit = { - name = "coolkit"; - src = fetchFromGitHub { - name = "coolkit"; - owner = "FRiCKLE"; - repo = "ngx_coolkit"; - rev = "0.2"; - sha256 = "1idj0cqmfsdqawjcqpr1fsq670fdki51ksqk2lslfpcs3yrfjpqh"; - }; - - meta = { - description = "Collection of small and useful nginx add-ons"; - homepage = "https://github.com/FRiCKLE/ngx_coolkit"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - dav = { - name = "dav"; - src = fetchFromGitHub { - name = "dav"; - owner = "arut"; - repo = "nginx-dav-ext-module"; - rev = "v3.0.0"; - sha256 = "000dm5zk0m1hm1iq60aff5r6y8xmqd7djrwhgnz9ig01xyhnjv9w"; - }; - - inputs = [ expat ]; - - meta = { - description = "WebDAV PROPFIND,OPTIONS,LOCK,UNLOCK support"; - homepage = "https://github.com/arut/nginx-dav-ext-module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - develkit = { - name = "develkit"; - src = fetchFromGitHub { - name = "develkit"; - owner = "vision5"; - repo = "ngx_devel_kit"; - rev = "v0.3.3"; - hash = "sha256-/RQUVHwIdNqm3UemQ/oNs2ksg8beziA4Pxejd5Yg0Pg="; - }; - - meta = { - description = "Adds additional generic tools that module developers can use in their own modules"; - homepage = "https://github.com/vision5/ngx_devel_kit"; - license = lib.licenses.bsd3; - maintainers = [ ]; - }; - }; - - echo = rec { - name = "echo"; - version = "0.63"; - - src = fetchFromGitHub { - name = "echo"; - owner = "openresty"; - repo = "echo-nginx-module"; - rev = "v${version}"; - hash = "sha256-K7oOE0yxPYLf+3YMVbBsncpHRpGHXjs/8B5QPO3MQC4="; - }; - - meta = { - description = "Brings echo, sleep, time, exec and more shell-style goodies to Nginx"; - homepage = "https://github.com/openresty/echo-nginx-module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - fancyindex = { - name = "fancyindex"; - src = fetchFromGitHub { - name = "fancyindex"; - owner = "aperezdc"; - repo = "ngx-fancyindex"; - rev = "v0.5.2"; - sha256 = "0nar45lp3jays3p6b01a78a6gwh6v0snpzcncgiphcqmj5kw8ipg"; - }; - - meta = { - description = "Fancy indexes module"; - homepage = "https://github.com/aperezdc/ngx-fancyindex"; - license = lib.licenses.bsd2; - maintainers = with lib.maintainers; [ aneeshusa ]; - }; - }; - - fluentd = { - name = "fluentd"; - src = fetchFromGitHub { - name = "fluentd"; - owner = "fluent"; - repo = "nginx-fluentd-module"; - rev = "8af234043059c857be27879bc547c141eafd5c13"; - sha256 = "1ycb5zd9sw60ra53jpak1m73zwrjikwhrrh9q6266h1mlyns7zxm"; - }; - - meta = { - description = "Fluentd data collector"; - homepage = "https://github.com/fluent/nginx-fluentd-module"; - license = lib.licenses.asl20; - maintainers = [ ]; - }; - }; - - geoip2 = { - name = "geoip2"; - src = fetchFromGitHub { - name = "geoip2"; - owner = "leev"; - repo = "ngx_http_geoip2_module"; - rev = "3.4"; - sha256 = "CAs1JZsHY7RymSBYbumC2BENsXtZP3p4ljH5QKwz5yg="; - }; - - inputs = [ libmaxminddb ]; - - meta = { - description = "Creates variables with values from the maxmind geoip2 databases"; - homepage = "https://github.com/leev/ngx_http_geoip2_module"; - license = lib.licenses.bsd2; - maintainers = with lib.maintainers; [ pinpox ]; - }; - }; - - http_proxy_connect_module_v24 = - http_proxy_connect_module_generic "proxy_connect_rewrite_102101" - // { - supports = with lib.versions; version: major version == "1" && minor version == "24"; - }; - - http_proxy_connect_module_v25 = - http_proxy_connect_module_generic "proxy_connect_rewrite_102101" - // { - supports = with lib.versions; version: major version == "1" && minor version == "25"; - }; - - ipscrub = { - name = "ipscrub"; - src = - fetchFromGitHub { - name = "ipscrub"; - owner = "masonicboom"; - repo = "ipscrub"; - rev = "v1.0.1"; - sha256 = "0qcx15c8wbsmyz2hkmyy5yd7qn1n84kx9amaxnfxkpqi05vzm1zz"; - } - + "/ipscrub"; - - inputs = [ libbsd ]; - - meta = { - description = "IP address anonymizer"; - homepage = "https://github.com/masonicboom/ipscrub"; - license = lib.licenses.bsd3; - maintainers = [ ]; - }; - }; - - limit-speed = { - name = "limit-speed"; - src = fetchFromGitHub { - name = "limit-speed"; - owner = "yaoweibin"; - repo = "nginx_limit_speed_module"; - rev = "f77ad4a56fbb134878e75827b40cf801990ed936"; - sha256 = "0kkrd08zpcwx938i2is07vq6pgjkvn97xzjab0g4zaz8bivgmjp8"; - }; - - meta = { - description = "Limit the total speed from the specific user"; - homepage = "https://github.com/yaoweibin/nginx_limit_speed_module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - live = { - name = "live"; - src = fetchFromGitHub { - name = "live"; - owner = "arut"; - repo = "nginx-live-module"; - rev = "5e4a1e3a718e65e5206c24eba00d42b0d1c4b7dd"; - sha256 = "1kpnhl4b50zim84z22ahqxyxfq4jv8ab85kzsy2n5ciqbyg491lz"; - }; - - meta = { - description = "HTTP live module"; - homepage = "https://github.com/arut/nginx-live-module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - lua = rec { - name = "lua"; - version = "0.10.29"; - - src = fetchFromGitHub { - name = "lua"; - owner = "openresty"; - repo = "lua-nginx-module"; - rev = "v${version}"; - hash = "sha256-z62Vwrthl1FJiTdrdhifZZe6crdi8c6sTkUim6KmVlU="; - }; - - inputs = [ luajit_openresty ]; - - preConfigure = '' - export LUAJIT_LIB="${luajit_openresty}/lib" - export LUAJIT_INC="$(realpath ${luajit_openresty}/include/luajit-*)" - - # make source directory writable to allow generating src/ngx_http_lua_autoconf.h - lua_src=$TMPDIR/lua-src - cp -r "${src}/" "$lua_src" - chmod -R +w "$lua_src" - export configureFlags="''${configureFlags//"${src}"/"$lua_src"}" - unset lua_src - ''; - - allowMemoryWriteExecute = true; - - meta = { - description = "Embed the Power of Lua"; - homepage = "https://github.com/openresty/lua-nginx-module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - lua-upstream = { - name = "lua-upstream"; - src = fetchFromGitHub { - name = "lua-upstream"; - owner = "openresty"; - repo = "lua-upstream-nginx-module"; - rev = "v0.07"; - sha256 = "1gqccg8airli3i9103zv1zfwbjm27h235qjabfbfqk503rjamkpk"; - }; - - inputs = [ luajit_openresty ]; - allowMemoryWriteExecute = true; - - meta = { - description = "Expose Lua API to ngx_lua for Nginx upstreams"; - homepage = "https://github.com/openresty/lua-upstream-nginx-module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - modsecurity = { - name = "modsecurity"; - src = fetchFromGitHub { - name = "modsecurity-nginx"; - owner = "owasp-modsecurity"; - repo = "ModSecurity-nginx"; - # unstable 2025-02-17 - rev = "0b4f0cf38502f34a30c8543039f345cfc075670d"; - hash = "sha256-P3IwKFR4NbaMXYY+O9OHfZWzka4M/wr8sJpX94LzQTU="; - }; - - inputs = [ - curl - geoip - libmodsecurity - libxml2 - lmdb - yajl - ]; - - meta = { - description = "Open source, cross platform web application firewall (WAF)"; - homepage = "https://github.com/SpiderLabs/ModSecurity"; - license = lib.licenses.asl20; - maintainers = [ ]; - }; - }; - - moreheaders = { - name = "moreheaders"; - src = fetchFromGitHub { - name = "moreheaders"; - owner = "openresty"; - repo = "headers-more-nginx-module"; - rev = "v0.36"; - sha256 = "sha256-X+ygIesQ9PGm5yM+u1BOLYVpm1172P8jWwXNr3ixFY4="; - }; - - meta = { - description = "Set, add, and clear arbitrary output headers"; - homepage = "https://github.com/openresty/headers-more-nginx-module"; - license = lib.licenses.bsd2; - maintainers = with lib.maintainers; [ SuperSandro2000 ]; - }; - }; - - mpeg-ts = { - name = "mpeg-ts"; - src = fetchFromGitHub { - name = "mpeg-ts"; - owner = "arut"; - repo = "nginx-ts-module"; - rev = "v0.1.1"; - sha256 = "12dxcyy6wna1fccl3a9lnsbymd6p4apnwz6c24w74v97qvpfdxqd"; - }; - - meta = { - description = "MPEG-TS Live Module"; - homepage = "https://github.com/arut/nginx-ts-module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - naxsi = { - name = "naxsi"; - src = - fetchFromGitHub { - name = "naxsi"; - owner = "nbs-system"; - repo = "naxsi"; - rev = "95ac520eed2ea04098a76305fd0ad7e9158840b7"; - sha256 = "0b5pnqkgg18kbw5rf2ifiq7lsx5rqmpqsql6hx5ycxjzxj6acfb3"; - } - + "/naxsi_src"; - - meta = { - description = "Open-source, high performance, low rules maintenance WAF"; - homepage = "https://github.com/nbs-system/naxsi"; - license = lib.licenses.gpl3; - maintainers = [ ]; - }; - }; - - njs = rec { - name = "njs"; - src = fetchFromGitHub { - owner = "nginx"; - repo = "njs"; - tag = "0.9.4"; - hash = "sha256-Ee55QKaeZ0mYGKUroKr/AYGoOCakEonU483qkhmZdzU="; - }; - - # njs module sources have to be writable during nginx build, so we copy them - # to a temporary directory and change the module path in the configureFlags - preConfigure = '' - NJS_SOURCE_DIR=$(readlink -m "$TMPDIR/${src}") - mkdir -p "$(dirname "$NJS_SOURCE_DIR")" - cp --recursive "${src}" "$NJS_SOURCE_DIR" - chmod -R u+rwX,go+rX "$NJS_SOURCE_DIR" - export configureFlags="''${configureFlags/"${src}"/"$NJS_SOURCE_DIR/nginx"} --with-ld-opt='-lz'" - unset NJS_SOURCE_DIR - ''; - - inputs = [ - which - zlib - ]; - - passthru.tests = nixosTests.nginx-njs; - - meta = { - description = "Subset of the JavaScript language that allows extending nginx functionality"; - homepage = "https://nginx.org/en/docs/njs/"; - license = lib.licenses.bsd2; - maintainers = with lib.maintainers; [ jvanbruegge ]; - }; - }; - - pagespeed = { - name = "pagespeed"; - src = - let - moduleSrc = fetchFromGitHub { - name = "pagespeed"; - owner = "apache"; - repo = "incubator-pagespeed-ngx"; - rev = "v${psol.version}-stable"; - sha256 = "0ry7vmkb2bx0sspl1kgjlrzzz6lbz07313ks2lr80rrdm2zb16wp"; - }; - in - runCommand "ngx_pagespeed" - { - meta = { - description = "PageSpeed module for Nginx"; - homepage = "https://developers.google.com/speed/pagespeed/module/"; - license = lib.licenses.asl20; - }; - } - '' - cp -r "${moduleSrc}" "$out" - chmod -R +w "$out" - ln -s "${psol}" "$out/psol" - ''; - - inputs = [ - zlib - libuuid - ]; # psol deps - allowMemoryWriteExecute = true; - - meta = { - description = "Automatic PageSpeed optimization"; - homepage = "https://github.com/apache/incubator-pagespeed-ngx"; - license = lib.licenses.asl20; - maintainers = [ ]; - }; - }; - - pam = { - name = "pam"; - src = fetchFromGitHub { - name = "pam"; - owner = "sto"; - repo = "ngx_http_auth_pam_module"; - rev = "v1.5.3"; - sha256 = "sha256:09lnljdhjg65643bc4535z378lsn4llbq67zcxlln0pizk9y921a"; - }; - - inputs = [ pam ]; - - meta = { - description = "Use PAM for simple http authentication"; - homepage = "https://github.com/sto/ngx_http_auth_pam_module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - pinba = { - name = "pinba"; - src = fetchFromGitHub { - name = "pinba"; - owner = "tony2001"; - repo = "ngx_http_pinba_module"; - rev = "28131255d4797a7e2f82a6a35cf9fc03c4678fe6"; - sha256 = "00fii8bjvyipq6q47xhjhm3ylj4rhzmlk3qwxmfpdn37j7bc8p8c"; - }; - - meta = { - description = "Pinba module for nginx"; - homepage = "https://github.com/tony2001/ngx_http_pinba_module"; - license = lib.licenses.unfree; # no license in repo - maintainers = [ ]; - }; - }; - - push-stream = { - name = "push-stream"; - src = fetchFromGitHub { - name = "push-stream"; - owner = "wandenberg"; - repo = "nginx-push-stream-module"; - rev = "1cdc01521ed44dc614ebb5c0d19141cf047e1f90"; - sha256 = "0ijka32b37dl07k2jl48db5a32ix43jaczrpjih84cvq8yph0jjr"; - }; - - meta = { - description = "Pure stream http push technology"; - homepage = "https://github.com/wandenberg/nginx-push-stream-module"; - license = lib.licenses.gpl3; - maintainers = [ ]; - }; - }; - - rtmp = { - name = "rtmp"; - src = applyPatches { - src = fetchFromGitHub { - name = "rtmp"; - owner = "arut"; - repo = "nginx-rtmp-module"; - rev = "v1.2.2"; - sha256 = "0y45bswk213yhkc2v1xca2rnsxrhx8v6azxz9pvi71vvxcggqv6h"; - }; - - patches = [ - # GCC 16's improved unused variable analysis detects some unused - # variables which were fixed upstream but not released. - (fetchpatch { - name = "remove-unused-variables-ngx-rtmp-handler.patch"; - url = "https://github.com/arut/nginx-rtmp-module/commit/6c7719d0ba32e00b563ec70bd43dad11960fa9c4.patch"; - hash = "sha256-c2hSp4CamBYMwkU9EOUSnfXvCYVOIxm1WzMR/M7Ojcc="; - }) - (fetchpatch { - name = "remove-unused-variables-ngx-rtmp-eval.patch"; - url = "https://github.com/arut/nginx-rtmp-module/commit/c56fd73def3eb407155ecebc28af84ea83dc99e5.patch"; - hash = "sha256-APXdEsRp3SSUKM9ud8tbZEPsfOe/055TRD7FFHE2k9w="; - }) - ]; - }; - - meta = { - description = "Media Streaming Server"; - homepage = "https://github.com/arut/nginx-rtmp-module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - secure-token = rec { - name = "secure-token"; - version = "1.5"; - src = fetchFromGitHub { - name = "secure-token"; - owner = "kaltura"; - repo = "nginx-secure-token-module"; - tag = version; - hash = "sha256-qYTjGS9pykRqMFmNls52YKxEdXYhHw+18YC2zzdjEpU="; - }; - - inputs = [ openssl ]; - - meta = { - description = "Generates CDN tokens, either as a cookie or as a query string parameter"; - homepage = "https://github.com/kaltura/nginx-secure-token-module"; - license = lib.licenses.agpl3Only; - maintainers = [ ]; - }; - }; - - set-misc = { - name = "set-misc"; - src = fetchFromGitHub { - name = "set-misc"; - owner = "openresty"; - repo = "set-misc-nginx-module"; - rev = "v0.33"; - hash = "sha256-jMMj3Ki1uSfQzagoB/O4NarxPjiaF9YRwjSKo+cgMxo="; - }; - - meta = { - description = "Various set_xxx directives added to the rewrite module (md5/sha1, sql/json quoting and many more)"; - homepage = "https://github.com/openresty/set-misc-nginx-module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - shibboleth = { - name = "shibboleth"; - src = fetchFromGitHub { - name = "shibboleth"; - owner = "nginx-shib"; - repo = "nginx-http-shibboleth"; - rev = "3f5ff4212fa12de23cb1acae8bf3a5a432b3f43b"; - sha256 = "136zjipaz7iikgcgqwdv1mrh3ya996zyzbkdy6d4k07s2h9g7hy6"; - }; - - meta = { - description = "Shibboleth auth request"; - homepage = "https://github.com/nginx-shib/nginx-http-shibboleth"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - sla = { - name = "sla"; - src = fetchFromGitHub { - name = "sla"; - owner = "goldenclone"; - repo = "nginx-sla"; - rev = "7778f0125974befbc83751d0e1cadb2dcea57601"; - sha256 = "1x5hm6r0dkm02ffny8kjd7mmq8przyd9amg2qvy5700x6lb63pbs"; - }; - - meta = { - description = "Implements a collection of augmented statistics based on HTTP-codes and upstreams response time"; - homepage = "https://github.com/goldenclone/nginx-sla"; - license = lib.licenses.unfree; # no license in repo - maintainers = [ ]; - }; - }; - - slowfs-cache = { - name = "slowfs-cache"; - src = fetchFromGitHub { - name = "slowfs-cache"; - owner = "FRiCKLE"; - repo = "ngx_slowfs_cache"; - rev = "1.10"; - sha256 = "1gyza02pcws3zqm1phv3ag50db5gnapxyjwy8skjmvawz7p5bmxr"; - }; - - meta = { - description = "Adds ability to cache static files"; - homepage = "https://github.com/friCKLE/ngx_slowfs_cache"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - sorted-querystring = { - name = "sorted-querystring"; - src = fetchFromGitHub { - name = "sorted-querystring"; - owner = "wandenberg"; - repo = "nginx-sorted-querystring-module"; - rev = "0.3"; - sha256 = "0p6b0hcws39n27fx4xp9k4hb3pcv7b6kah4qqaj0pzjy3nbp4gj7"; - }; - - meta = { - description = "Expose querystring parameters sorted in a variable"; - homepage = "https://github.com/wandenberg/nginx-sorted-querystring-module"; - license = lib.licenses.mit; - maintainers = [ ]; - }; - }; - - spnego-http-auth = { - name = "spnego-http-auth"; - src = fetchFromGitHub { - name = "spnego-http-auth"; - owner = "stnoonan"; - repo = "spnego-http-auth-nginx-module"; - rev = "3575542b3147bd03a6c68a750c3662b0d72ed94e"; - hash = "sha256-s0m5h7m7dsPD5o2SvBb9L2kB57jwXZK5SkdkGuOmlgs="; - }; - - inputs = [ libkrb5 ]; - - meta = { - description = "SPNEGO HTTP Authentication Module"; - homepage = "https://github.com/stnoonan/spnego-http-auth-nginx-module"; - license = lib.licenses.bsd2; - maintainers = with lib.maintainers; [ - de11n - despsyched - ]; - }; - }; - - statsd = { - name = "statsd"; - src = fetchFromGitHub { - name = "statsd"; - owner = "harvesthq"; - repo = "nginx-statsd"; - rev = "b970e40467a624ba710c9a5106879a0554413d15"; - sha256 = "1x8j4i1i2ahrr7qvz03vkldgdjdxi6mx75mzkfizfcc8smr4salr"; - }; - - meta = { - description = "Send statistics to statsd"; - homepage = "https://github.com/harvesthq/nginx-statsd"; - license = lib.licenses.bsd3; - maintainers = [ ]; - }; - }; - - stream-sts = { - name = "stream-sts"; - src = fetchFromGitHub { - name = "stream-sts"; - owner = "vozlt"; - repo = "nginx-module-stream-sts"; - rev = "v0.1.1"; - sha256 = "1jdj1kik6l3rl9nyx61xkqk7hmqbncy0rrqjz3dmjqsz92y8zaya"; - }; - - meta = { - description = "Stream server traffic status core module"; - homepage = "https://github.com/vozlt/nginx-module-stream-sts"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - sts = { - name = "sts"; - src = fetchFromGitHub { - name = "sts"; - owner = "vozlt"; - repo = "nginx-module-sts"; - rev = "v0.1.1"; - sha256 = "0nvb29641x1i7mdbydcny4qwlvdpws38xscxirajd2x7nnfdflrk"; - }; - - meta = { - description = "Stream server traffic status module"; - homepage = "https://github.com/vozlt/nginx-module-sts"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - subsFilter = { - name = "subsFilter"; - src = fetchFromGitHub { - name = "subsFilter"; - owner = "yaoweibin"; - repo = "ngx_http_substitutions_filter_module"; - rev = "e12e965ac1837ca709709f9a26f572a54d83430e"; - sha256 = "sha256-3sWgue6QZYwK69XSi9q8r3WYGVyMCIgfqqLvPBHqJKU="; - }; - - meta = { - description = "Filter module which can do both regular expression and fixed string substitutions"; - homepage = "https://github.com/yaoweibin/ngx_http_substitutions_filter_module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - sysguard = { - name = "sysguard"; - src = fetchFromGitHub { - name = "sysguard"; - owner = "vozlt"; - repo = "nginx-module-sysguard"; - rev = "e512897f5aba4f79ccaeeebb51138f1704a58608"; - sha256 = "19c6w6wscbq9phnx7vzbdf4ay6p2ys0g7kp2rmc9d4fb53phrhfx"; - }; - - meta = { - description = "Nginx sysguard module"; - homepage = "https://github.com/vozlt/nginx-module-sysguard"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - upload = { - name = "upload"; - src = fetchFromGitHub { - name = "upload"; - owner = "fdintino"; - repo = "nginx-upload-module"; - rev = "2.3.0"; - sha256 = "8veZP516oC7TESO368ZsZreetbDt+1eTcamk7P1kWjU="; - }; - - meta = { - description = "Handle file uploads using multipart/form-data encoding and resumable uploads"; - homepage = "https://github.com/fdintino/nginx-upload-module"; - license = lib.licenses.bsd3; - maintainers = [ ]; - }; - }; - - upstream-check = { - name = "upstream-check"; - src = fetchFromGitHub { - name = "upstream-check"; - owner = "yaoweibin"; - repo = "nginx_upstream_check_module"; - rev = "e538034b6ad7992080d2403d6d3da56e4f7ac01e"; - sha256 = "06y7k04072xzqyqyb08m0vaaizkp4rfwm0q7i735imbzw2rxb74l"; - }; - - meta = { - description = "Support upstream health check"; - homepage = "https://github.com/yaoweibin/nginx_upstream_check_module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - upstream-tarantool = { - name = "upstream-tarantool"; - src = fetchFromGitHub { - name = "upstream-tarantool"; - owner = "tarantool"; - repo = "nginx_upstream_module"; - rev = "v2.7.1"; - sha256 = "0ya4330in7zjzqw57djv4icpk0n1j98nvf0f8v296yi9rjy054br"; - }; - - inputs = [ - msgpuck.dev - yajl - ]; - - meta = { - description = "Tarantool NginX upstream module (REST, JSON API, websockets, load balancing)"; - homepage = "https://github.com/tarantool/nginx_upstream_module"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - url = { - name = "url"; - src = fetchFromGitHub { - name = "url"; - owner = "vozlt"; - repo = "nginx-module-url"; - rev = "9299816ca6bc395625c3683fbd2aa7b916bfe91e"; - sha256 = "0mk1gjmfnry6hgdsnlavww9bn7223idw50jlkhh5k00q5509w4ip"; - }; - - meta = { - description = "URL encoding converting module"; - homepage = "https://github.com/vozlt/nginx-module-url"; - license = lib.licenses.bsd2; - maintainers = [ ]; - }; - }; - - video-thumbextractor = rec { - name = "video-thumbextractor"; - version = "1.0.0"; - src = fetchFromGitHub { - name = "video-thumbextractor"; - owner = "wandenberg"; - repo = "nginx-video-thumbextractor-module"; - tag = version; - hash = "sha256-F2cuzCbJdGYX0Zmz9MSXTB7x8+FBR6pPpXtLlDRCcj8="; - }; - - inputs = [ - ffmpeg-headless - libjpeg - ]; - - meta = { - description = "Extract thumbs from a video file"; - homepage = "https://github.com/wandenberg/nginx-video-thumbextractor-module"; - license = lib.licenses.gpl3; - maintainers = [ ]; - }; - }; - - vod = rec { - name = "vod"; - version = "1.7.0"; - - src = applyPatches { - name = "vod"; - src = fetchFromGitHub { - owner = "dio-az"; - repo = "nginx-vod-module"; - tag = "v${version}"; - hash = "sha256-IcXbbmAs16F9qOEJWgH6XqP5sBMYszclGByVghj0eBM="; - }; - - postPatch = '' - substituteInPlace vod/media_set.h \ - --replace-fail "MAX_CLIPS (128)" "MAX_CLIPS (1024)" - ''; - }; - - inputs = [ - ffmpeg-headless - fdk_aac - openssl - libxml2 - libiconv - ]; - - passthru.tests = nixosTests.frigate; - - meta = { - description = "VOD packager"; - homepage = "https://github.com/kaltura/nginx-vod-module"; - license = lib.licenses.agpl3Only; - maintainers = [ ]; - }; - }; - - vts = { - name = "vts"; - src = fetchFromGitHub { - name = "vts"; - owner = "vozlt"; - repo = "nginx-module-vts"; - rev = "v0.2.2"; - sha256 = "sha256-ReTmYGVSOwtnYDMkQDMWwxw09vT4iHYfYZvgd8iBotk="; - }; - - meta = { - description = "Virtual host traffic status module"; - homepage = "https://github.com/vozlt/nginx-module-vts"; - license = lib.licenses.bsd2; - maintainers = with lib.maintainers; [ SuperSandro2000 ]; - }; - }; - - zip = { - name = "zip"; - src = fetchFromGitHub { - name = "zip"; - owner = "evanmiller"; - repo = "mod_zip"; - rev = "8e65b82c82c7890f67a6107271c127e9881b6313"; - hash = "sha256-2bUyGsLSaomzaijnAcHQV9TNSuV7Z3G9EUbrZzLG+mk="; - }; - - meta = { - description = "Streaming ZIP archiver for nginx"; - homepage = "https://github.com/evanmiller/mod_zip"; - license = lib.licenses.bsd3; - broken = stdenv.hostPlatform.isDarwin; - maintainers = with lib.maintainers; [ - DutchGerman - friedow - ]; - }; - }; - - zstd = { - name = "zstd"; - src = fetchFromGitHub { - name = "zstd"; - owner = "tokers"; - repo = "zstd-nginx-module"; - rev = "f4ba115e0b0eaecde545e5f37db6aa18917d8f4b"; - hash = "sha256-N8D3KRpd79O8sdlPngtK9Ii7XT2imS4F+nkqsHMHw/w="; - }; - - inputs = [ zstd ]; - - meta = { - description = "Nginx modules for the Zstandard compression"; - homepage = "https://github.com/tokers/zstd-nginx-module"; - license = lib.licenses.bsd2; - maintainers = with lib.maintainers; [ SuperSandro2000 ]; - }; - }; - }; -in -self -// lib.optionalAttrs config.allowAliases { - # deprecated or renamed packages - modsecurity-nginx = self.modsecurity; - fastcgi-cache-purge = throw "fastcgi-cache-purge was renamed to cache-purge"; - ngx_aws_auth = throw "ngx_aws_auth was renamed to aws-auth"; - opentracing = throw "opentracing-cpp was removed because opentracing as been archived upstream"; # Added 2025-10-19 -} diff --git a/pkgs/servers/http/nginx/modules/akamai-token-validate/package.nix b/pkgs/servers/http/nginx/modules/akamai-token-validate/package.nix new file mode 100644 index 000000000000..68e250681e19 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/akamai-token-validate/package.nix @@ -0,0 +1,27 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, + openssl, +}: + +mkNginxPlugin (finalAttrs: { + pname = "akamai-token-validate"; + version = "0-unstable-2026-06-26"; + + src = fetchFromGitHub { + owner = "kaltura"; + repo = "nginx-akamai-token-validate-module"; + rev = "34fd0c94d2c43c642f323491c4f4a226cd83b962"; + hash = "sha256-nh0l5txpQAn5lBOeujfSMN1Rn5XP0MUHoGy+HYImw3k="; + }; + + buildInputs = [ openssl ]; + + meta = { + description = "Validates Akamai v2 query string tokens"; + homepage = "https://github.com/kaltura/nginx-akamai-token-validate-module"; + license = lib.licenses.agpl3Only; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/aliases.nix b/pkgs/servers/http/nginx/modules/aliases.nix new file mode 100644 index 000000000000..6d2c8b0a279d --- /dev/null +++ b/pkgs/servers/http/nginx/modules/aliases.nix @@ -0,0 +1,14 @@ +# Removed or renamed nginx modules + +self: { + # keep-sorted start case=no numeric=yes block=yes + + fastcgi-cache-purge = throw "fastcgi-cache-purge was renamed to cache-purge"; + http_proxy_connect_module_v24 = throw "http_proxy_connect_module_v24 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29 + http_proxy_connect_module_v25 = throw "http_proxy_connect_module_v25 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29 + modsecurity-nginx = self.modsecurity; + ngx_aws_auth = throw "ngx_aws_auth was renamed to aws-auth"; + opentracing = throw "opentracing-cpp was removed because opentracing as been archived upstream"; # Added 2025-10-19 + statsd = throw "statsd was removed because its upstream source vanished"; # Added 2026-07-28 + # keep-sorted end +} diff --git a/pkgs/servers/http/nginx/modules/auth-a2aclr/package.nix b/pkgs/servers/http/nginx/modules/auth-a2aclr/package.nix new file mode 100644 index 000000000000..69ce5288d03c --- /dev/null +++ b/pkgs/servers/http/nginx/modules/auth-a2aclr/package.nix @@ -0,0 +1,39 @@ +{ + fetchFromGitLab, + lib, + mkNginxPlugin, + arpa2common, +}: + +mkNginxPlugin (finalAttrs: { + pname = "auth-a2aclr"; + version = "0-unstable-2020-08-03"; + + src = fetchFromGitLab { + owner = "arpa2"; + repo = "nginx-auth-a2aclr"; + rev = "bbabf9480bb2b40ac581551883a18dfa6522dd63"; + hash = "sha256-h2LgMhreCgod+H/bNQzY9BvqG9ezkwikwWB3T6gHH04="; + }; + + buildInputs = [ + (arpa2common.overrideAttrs (old: rec { + version = "0.7.1"; + + src = fetchFromGitLab { + owner = "arpa2"; + repo = "arpa2common"; + rev = "v${version}"; + hash = "sha256-8zVsAlGtmya9EK4OkGUMu2FKJRn2Q3bg2QWGjqcii64="; + }; + })) + ]; + + meta = { + broken = true; # overridden arpa2common package fails to build + description = "Integrate ARPA2 Resource ACLs into nginx"; + homepage = "https://gitlab.com/arpa2/nginx-auth-a2aclr"; + license = lib.licenses.isc; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/aws-auth/package.nix b/pkgs/servers/http/nginx/modules/aws-auth/package.nix new file mode 100644 index 000000000000..5499a506a3b8 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/aws-auth/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "aws-auth"; + version = "2.1.1"; + + src = fetchFromGitHub { + owner = "anomalizer"; + repo = "ngx_aws_auth"; + tag = finalAttrs.version; + hash = "sha256-CRofdhJ5HQGp4R1tEoOx0Nzx1rTTd+5GaJcfDsg75oM="; + }; + + meta = { + description = "Proxy to authenticated AWS services"; + homepage = "https://github.com/anomalizer/ngx_aws_auth"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/brotli/package.nix b/pkgs/servers/http/nginx/modules/brotli/package.nix new file mode 100644 index 000000000000..1b2747af8207 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/brotli/package.nix @@ -0,0 +1,32 @@ +{ + brotli, + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "brotli"; + version = "1.0.0rc-unstable-2022-04-29"; + + src = fetchFromGitHub { + owner = "google"; + repo = "ngx_brotli"; + rev = "6e975bcb015f62e1f303054897783355e2a877dc"; + hash = "sha256-G0IDYlvaQzzJ6cNTSGbfuOuSXFp3RsEwIJLGapTbDgo="; + }; + + postPatch = '' + substituteInPlace filter/config \ + --replace-fail '$ngx_addon_dir/deps/brotli/c' ${lib.getDev brotli} + ''; + + buildInputs = [ brotli ]; + + meta = { + description = "Brotli compression"; + homepage = "https://github.com/google/ngx_brotli"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/builder.nix b/pkgs/servers/http/nginx/modules/builder.nix new file mode 100644 index 000000000000..9289199c96f1 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/builder.nix @@ -0,0 +1,51 @@ +{ + lib, + stdenv, + nix-update-script, + nginx, +}: + +# This builder provides a thin facade that wraps the fod into a derivation +# so that plugins can be picked up for automated updates. The actual build +# happens when they are passed into the nginx build, which is why there is +# no need to build these in hydra. + +lib.extendMkDerivation { + constructDrv = stdenv.mkDerivation; + extendDrvArgs = finalAttrs: args: { + name = "nginx-mod-${args.pname}-${args.version}"; + dontConfigure = true; + dontBuild = true; + dontFixup = true; + + installPhase = '' + runHook preInstall + cp \ + --recursive \ + --no-preserve=ownership \ + . \ + "$out" + runHook postInstall + ''; + + passthru = args.passthru or { } // { + updateScript = + args.passthru.updateScript or (nix-update-script { + extraArgs = [ "--version=stable" ]; + }); + tests = { + nginx = nginx.override { + modules = [ finalAttrs.finalPackage ]; + }; + } + // args.passthru.tests or { }; + }; + + meta = ( + args.meta or { } + // { + hydraPlatforms = [ ]; + } + ); + }; +} diff --git a/pkgs/servers/http/nginx/modules/cache-purge/package.nix b/pkgs/servers/http/nginx/modules/cache-purge/package.nix new file mode 100644 index 000000000000..8e2211d8b05d --- /dev/null +++ b/pkgs/servers/http/nginx/modules/cache-purge/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "cache-purge"; + version = "2.5.1"; + + src = fetchFromGitHub { + owner = "nginx-modules"; + repo = "ngx_cache_purge"; + tag = finalAttrs.version; + hash = "sha256-jVm8E4u1NkjtBoGdRzUDo6l27XPDFoCrNUf2asaXRG0="; + }; + + meta = { + description = "Adds ability to purge content from FastCGI, proxy, SCGI and uWSGI caches"; + homepage = "https://github.com/nginx-modules/ngx_cache_purge"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/coolkit/package.nix b/pkgs/servers/http/nginx/modules/coolkit/package.nix new file mode 100644 index 000000000000..74c234f1cfb5 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/coolkit/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "coolkit"; + version = "0.2"; + + src = fetchFromGitHub { + owner = "FRiCKLE"; + repo = "ngx_coolkit"; + tag = finalAttrs.version; + hash = "sha256-EF/psh+aXUc1FRPrGUqczYFjsHYhX8wkV7hpVzEDssU="; + }; + + meta = { + description = "Collection of small and useful nginx add-ons"; + homepage = "https://github.com/FRiCKLE/ngx_coolkit"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/dav/package.nix b/pkgs/servers/http/nginx/modules/dav/package.nix new file mode 100644 index 000000000000..0ca2af925244 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/dav/package.nix @@ -0,0 +1,27 @@ +{ + lib, + fetchFromGitHub, + mkNginxPlugin, + expat, +}: + +mkNginxPlugin (finalAttrs: { + pname = "dav"; + version = "3.0.0"; + + src = fetchFromGitHub { + owner = "arut"; + repo = "nginx-dav-ext-module"; + tag = "v${finalAttrs.version}"; + sha256 = "000dm5zk0m1hm1iq60aff5r6y8xmqd7djrwhgnz9ig01xyhnjv9w"; + }; + + buildInputs = [ expat ]; + + meta = { + description = "WebDAV PROPFIND,OPTIONS,LOCK,UNLOCK support"; + homepage = "https://github.com/arut/nginx-dav-ext-module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/develkit/package.nix b/pkgs/servers/http/nginx/modules/develkit/package.nix new file mode 100644 index 000000000000..cb2fceae3cdf --- /dev/null +++ b/pkgs/servers/http/nginx/modules/develkit/package.nix @@ -0,0 +1,24 @@ +{ + lib, + fetchFromGitHub, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "develkit"; + version = "0.3.3"; + + src = fetchFromGitHub { + owner = "vision5"; + repo = "ngx_devel_kit"; + tag = "v${finalAttrs.version}"; + hash = "sha256-/RQUVHwIdNqm3UemQ/oNs2ksg8beziA4Pxejd5Yg0Pg="; + }; + + meta = { + description = "Adds additional generic tools that module developers can use in their own modules"; + homepage = "https://github.com/vision5/ngx_devel_kit"; + license = lib.licenses.bsd3; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/echo/package.nix b/pkgs/servers/http/nginx/modules/echo/package.nix new file mode 100644 index 000000000000..ea4a748cc50f --- /dev/null +++ b/pkgs/servers/http/nginx/modules/echo/package.nix @@ -0,0 +1,25 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "echo"; + version = "0.63"; + + src = fetchFromGitHub { + name = "echo"; + owner = "openresty"; + repo = "echo-nginx-module"; + tag = "v${finalAttrs.version}"; + hash = "sha256-K7oOE0yxPYLf+3YMVbBsncpHRpGHXjs/8B5QPO3MQC4="; + }; + + meta = { + description = "Brings echo, sleep, time, exec and more shell-style goodies to Nginx"; + homepage = "https://github.com/openresty/echo-nginx-module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/fancyindex/package.nix b/pkgs/servers/http/nginx/modules/fancyindex/package.nix new file mode 100644 index 000000000000..e91359568288 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/fancyindex/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "fancyindex"; + version = "0.5.2"; + + src = fetchFromGitHub { + owner = "aperezdc"; + repo = "ngx-fancyindex"; + tag = "v${finalAttrs.version}"; + hash = "sha256-70bEZ5EVM3jjY5b9azXYBvJnFDoqgGXu0F7JcWkhWVk="; + }; + + meta = { + description = "Fancy indexes module"; + homepage = "https://github.com/aperezdc/ngx-fancyindex"; + license = lib.licenses.bsd2; + maintainers = with lib.maintainers; [ aneeshusa ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/fluentd/package.nix b/pkgs/servers/http/nginx/modules/fluentd/package.nix new file mode 100644 index 000000000000..57cd3676de7c --- /dev/null +++ b/pkgs/servers/http/nginx/modules/fluentd/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "fluentd"; + version = "0.3-unstable-2014-03-28"; + + src = fetchFromGitHub { + owner = "fluent"; + repo = "nginx-fluentd-module"; + rev = "8af234043059c857be27879bc547c141eafd5c13"; + hash = "sha256-tf+jrac1QGOEwQnmDPmMMvM/Tg1TXTmKysBwndovi/k="; + }; + + meta = { + description = "Fluentd data collector"; + homepage = "https://github.com/fluent/nginx-fluentd-module"; + license = lib.licenses.asl20; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/geoip2/package.nix b/pkgs/servers/http/nginx/modules/geoip2/package.nix new file mode 100644 index 000000000000..2f961b4ecdf9 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/geoip2/package.nix @@ -0,0 +1,27 @@ +{ + fetchFromGitHub, + lib, + libmaxminddb, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "geoip2"; + version = "3.4"; + + src = fetchFromGitHub { + owner = "leev"; + repo = "ngx_http_geoip2_module"; + tag = finalAttrs.version; + hash = "sha256-CAs1JZsHY7RymSBYbumC2BENsXtZP3p4ljH5QKwz5yg="; + }; + + buildInputs = [ libmaxminddb ]; + + meta = { + description = "Creates variables with values from the maxmind geoip2 databases"; + homepage = "https://github.com/leev/ngx_http_geoip2_module"; + license = lib.licenses.bsd2; + maintainers = with lib.maintainers; [ pinpox ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/ipscrub/package.nix b/pkgs/servers/http/nginx/modules/ipscrub/package.nix new file mode 100644 index 000000000000..4df0a250122a --- /dev/null +++ b/pkgs/servers/http/nginx/modules/ipscrub/package.nix @@ -0,0 +1,29 @@ +{ + fetchFromGitHub, + lib, + libbsd, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "ipscrub"; + version = "1.0.1"; + + src = fetchFromGitHub { + owner = "masonicboom"; + repo = "ipscrub"; + tag = "v${finalAttrs.version}"; + hash = "sha256-/4f6dwER39md7aqq1CdBNlh8mi/e1wnF91UvjlgJnWE="; + }; + + sourceRoot = "${finalAttrs.src.name}/ipscrub"; + + buildInputs = [ libbsd ]; + + meta = { + description = "IP address anonymizer"; + homepage = "https://github.com/masonicboom/ipscrub"; + license = lib.licenses.bsd3; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/limit-speed/package.nix b/pkgs/servers/http/nginx/modules/limit-speed/package.nix new file mode 100644 index 000000000000..41ccaaa2a14c --- /dev/null +++ b/pkgs/servers/http/nginx/modules/limit-speed/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "limit-speed"; + version = "0.1-unstable-2014-03-21"; + + src = fetchFromGitHub { + owner = "yaoweibin"; + repo = "nginx_limit_speed_module"; + rev = "f77ad4a56fbb134878e75827b40cf801990ed936"; + hash = "sha256-6Mr6dlzoq08eWEr+fpLdU75r8D5ARxHRSJ2z+xFoeU4="; + }; + + meta = { + description = "Limit the total speed from the specific user"; + homepage = "https://github.com/yaoweibin/nginx_limit_speed_module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/live/package.nix b/pkgs/servers/http/nginx/modules/live/package.nix new file mode 100644 index 000000000000..47348080bc28 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/live/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "live"; + version = "0-unstable-2018-11-18"; + + src = fetchFromGitHub { + owner = "arut"; + repo = "nginx-live-module"; + rev = "5e4a1e3a718e65e5206c24eba00d42b0d1c4b7dd"; + hash = "sha256-n4ZEnl84smKF138WtBTakmDXfcdQCfEJqvGDsgiF9s4="; + }; + + meta = { + description = "HTTP live module"; + homepage = "https://github.com/arut/nginx-live-module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/lua-upstream/package.nix b/pkgs/servers/http/nginx/modules/lua-upstream/package.nix new file mode 100644 index 000000000000..5d2eaa351c44 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/lua-upstream/package.nix @@ -0,0 +1,30 @@ +{ + fetchFromGitHub, + lib, + luajit_openresty, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "lua-upstream"; + version = "0.07"; + + src = fetchFromGitHub { + name = "lua-upstream"; + owner = "openresty"; + repo = "lua-upstream-nginx-module"; + tag = "v${finalAttrs.version}"; + hash = "sha256-886qZB6gTOyWW0riMgQ8osrF3Q/7DxBSHJHmqNBjDL8="; + }; + + buildInputs = [ luajit_openresty ]; + + allowMemoryWriteExecute = true; + + meta = { + description = "Expose Lua API to ngx_lua for Nginx upstreams"; + homepage = "https://github.com/openresty/lua-upstream-nginx-module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/lua/package.nix b/pkgs/servers/http/nginx/modules/lua/package.nix new file mode 100644 index 000000000000..58c3094376ad --- /dev/null +++ b/pkgs/servers/http/nginx/modules/lua/package.nix @@ -0,0 +1,34 @@ +{ + fetchFromGitHub, + lib, + luajit_openresty, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "lua"; + version = "0.10.29"; + + src = fetchFromGitHub { + owner = "openresty"; + repo = "lua-nginx-module"; + rev = "v${finalAttrs.version}"; + hash = "sha256-z62Vwrthl1FJiTdrdhifZZe6crdi8c6sTkUim6KmVlU="; + }; + + buildInputs = [ luajit_openresty ]; + + preConfigure = '' + export LUAJIT_LIB="${luajit_openresty}/lib" + export LUAJIT_INC="$(realpath ${luajit_openresty}/include/luajit-*)" + ''; + + allowMemoryWriteExecute = true; + + meta = { + description = "Embed the Power of Lua"; + homepage = "https://github.com/openresty/lua-nginx-module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/modsecurity/package.nix b/pkgs/servers/http/nginx/modules/modsecurity/package.nix new file mode 100644 index 000000000000..43b18cb900a4 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/modsecurity/package.nix @@ -0,0 +1,39 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, + curl, + geoip, + libmodsecurity, + libxml2, + lmdb, + yajl, +}: + +mkNginxPlugin (finalAttrs: { + pname = "modsecurity"; + version = "1.0.3-unstable-2025-02-17"; + + src = fetchFromGitHub { + owner = "owasp-modsecurity"; + repo = "ModSecurity-nginx"; + rev = "0b4f0cf38502f34a30c8543039f345cfc075670d"; + hash = "sha256-P3IwKFR4NbaMXYY+O9OHfZWzka4M/wr8sJpX94LzQTU="; + }; + + buildInputs = [ + curl + geoip + libmodsecurity + libxml2 + lmdb + yajl + ]; + + meta = { + description = "Open source, cross platform web application firewall (WAF)"; + homepage = "https://github.com/owasp-modsecurity/ModSecurity"; + license = lib.licenses.asl20; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/moreheaders/package.nix b/pkgs/servers/http/nginx/modules/moreheaders/package.nix new file mode 100644 index 000000000000..051206ac8db2 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/moreheaders/package.nix @@ -0,0 +1,24 @@ +{ + lib, + fetchFromGitHub, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "moreheaders"; + version = "0.36"; + + src = fetchFromGitHub { + owner = "openresty"; + repo = "headers-more-nginx-module"; + tag = "v${finalAttrs.version}"; + sha256 = "sha256-X+ygIesQ9PGm5yM+u1BOLYVpm1172P8jWwXNr3ixFY4="; + }; + + meta = { + description = "Set, add, and clear arbitrary output headers"; + homepage = "https://github.com/openresty/headers-more-nginx-module"; + license = lib.licenses.bsd2; + maintainers = with lib.maintainers; [ SuperSandro2000 ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/mpeg-ts/package.nix b/pkgs/servers/http/nginx/modules/mpeg-ts/package.nix new file mode 100644 index 000000000000..6e91ed228dd0 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/mpeg-ts/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "mpeg-ts"; + version = "0.1.1"; + + src = fetchFromGitHub { + owner = "arut"; + repo = "nginx-ts-module"; + tag = "v${finalAttrs.version}"; + hash = "sha256-Dffm7sYnbXI4Ecx8bq8i17Tql7Y0qUEZc0FZbrxnvYk="; + }; + + meta = { + description = "MPEG-TS Live Module"; + homepage = "https://github.com/arut/nginx-ts-module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/naxsi/package.nix b/pkgs/servers/http/nginx/modules/naxsi/package.nix new file mode 100644 index 000000000000..c1af28a7d076 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/naxsi/package.nix @@ -0,0 +1,26 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "naxsi"; + version = "1.0-unstable-2020-09-10"; + + src = fetchFromGitHub { + owner = "nbs-system"; + repo = "naxsi"; + rev = "95ac520eed2ea04098a76305fd0ad7e9158840b7"; + sha256 = "0b5pnqkgg18kbw5rf2ifiq7lsx5rqmpqsql6hx5ycxjzxj6acfb3"; + }; + + sourceRoot = "${finalAttrs.src.name}/naxsi_src"; + + meta = { + description = "Open-source, high performance, low rules maintenance WAF"; + homepage = "https://github.com/nbs-system/naxsi"; + license = lib.licenses.gpl3; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/njs/package.nix b/pkgs/servers/http/nginx/modules/njs/package.nix new file mode 100644 index 000000000000..a6b3af2f36ff --- /dev/null +++ b/pkgs/servers/http/nginx/modules/njs/package.nix @@ -0,0 +1,39 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, + nixosTests, + which, + zlib, +}: + +mkNginxPlugin (finalAttrs: { + pname = "njs"; + version = "0.9.4"; + + src = fetchFromGitHub { + owner = "nginx"; + repo = "njs"; + tag = finalAttrs.version; + hash = "sha256-Ee55QKaeZ0mYGKUroKr/AYGoOCakEonU483qkhmZdzU="; + }; + + preConfigure = '' + configureFlags="''${configureFlags/--add-module=*nginx-mod-${finalAttrs.pname}-${finalAttrs.version}/&/nginx}" + + appendToVar configureFlags "--with-ld-opt=-lz" + ''; + + buildInputs = [ + which + zlib + ]; + + passthru.tests = nixosTests.nginx-njs; + meta = { + description = "Subset of the JavaScript language that allows extending nginx functionality"; + homepage = "https://nginx.org/en/docs/njs/"; + license = lib.licenses.bsd2; + maintainers = with lib.maintainers; [ jvanbruegge ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/pagespeed/package.nix b/pkgs/servers/http/nginx/modules/pagespeed/package.nix new file mode 100644 index 000000000000..696bdfdde986 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/pagespeed/package.nix @@ -0,0 +1,51 @@ +{ + fetchFromGitHub, + lib, + libuuid, + mkNginxPlugin, + psol, + runCommand, + zlib, +}: + +mkNginxPlugin (finalAttrs: { + pname = "pagespeed"; + version = psol.version; + + src = + let + moduleSrc = fetchFromGitHub { + owner = "apache"; + repo = "incubator-pagespeed-ngx"; + rev = "v${psol.version}-stable"; + sha256 = "0ry7vmkb2bx0sspl1kgjlrzzz6lbz07313ks2lr80rrdm2zb16wp"; + }; + in + runCommand "ngx_pagespeed" + { + meta = { + description = "PageSpeed module for Nginx"; + homepage = "https://developers.google.com/speed/pagespeed/module/"; + license = lib.licenses.asl20; + }; + } + '' + cp -r "${moduleSrc}" "$out" + chmod -R +w "$out" + ln -s "${psol}" "$out/psol" + ''; + + buildInputs = [ + zlib + libuuid + ]; # psol deps + + allowMemoryWriteExecute = true; + + meta = { + description = "Automatic PageSpeed optimization"; + homepage = "https://github.com/apache/incubator-pagespeed-ngx"; + license = lib.licenses.asl20; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/pam/package.nix b/pkgs/servers/http/nginx/modules/pam/package.nix new file mode 100644 index 000000000000..bb2bb00331b8 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/pam/package.nix @@ -0,0 +1,27 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, + pam, +}: + +mkNginxPlugin (finalAttrs: { + pname = "pam"; + version = "1.5.3"; + + src = fetchFromGitHub { + owner = "sto"; + repo = "ngx_http_auth_pam_module"; + tag = "v${finalAttrs.version}"; + hash = "sha256-Kojk0/zxAktpZ/8YvCglVlN0xi+jELYGMcU8CZukliY="; + }; + + buildInputs = [ pam ]; + + meta = { + description = "Use PAM for simple http authentication"; + homepage = "https://github.com/sto/ngx_http_auth_pam_module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/pinba/package.nix b/pkgs/servers/http/nginx/modules/pinba/package.nix new file mode 100644 index 000000000000..69be9eeb5709 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/pinba/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "pinba"; + version = "0-unstable-2019-05-13"; + + src = fetchFromGitHub { + owner = "tony2001"; + repo = "ngx_http_pinba_module"; + rev = "28131255d4797a7e2f82a6a35cf9fc03c4678fe6"; + sha256 = "00fii8bjvyipq6q47xhjhm3ylj4rhzmlk3qwxmfpdn37j7bc8p8c"; + }; + + meta = { + description = "Pinba module for nginx"; + homepage = "https://github.com/tony2001/ngx_http_pinba_module"; + license = lib.licenses.unfree; # no license in repo + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/push-stream/package.nix b/pkgs/servers/http/nginx/modules/push-stream/package.nix new file mode 100644 index 000000000000..8d9df1b59130 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/push-stream/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "push-stream"; + version = "0.5.4-unstable-2020-05-03"; + + src = fetchFromGitHub { + owner = "wandenberg"; + repo = "nginx-push-stream-module"; + rev = "1cdc01521ed44dc614ebb5c0d19141cf047e1f90"; + hash = "sha256-WUoAr0d4M4JglDd/puQgPYqhymqIUCnmAbSdscRQU0Y="; + }; + + meta = { + description = "Pure stream http push technology"; + homepage = "https://github.com/wandenberg/nginx-push-stream-module"; + license = lib.licenses.gpl3; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/rtmp/package.nix b/pkgs/servers/http/nginx/modules/rtmp/package.nix new file mode 100644 index 000000000000..3b51a1838329 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/rtmp/package.nix @@ -0,0 +1,40 @@ +{ + lib, + fetchFromGitHub, + fetchpatch, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "rtmp"; + version = "1.2.2"; + + src = fetchFromGitHub { + owner = "arut"; + repo = "nginx-rtmp-module"; + tag = "v${finalAttrs.version}"; + sha256 = "0y45bswk213yhkc2v1xca2rnsxrhx8v6azxz9pvi71vvxcggqv6h"; + }; + + patches = [ + # GCC 16's improved unused variable analysis detects some unused + # variables which were fixed upstream but not released. + (fetchpatch { + name = "remove-unused-variables-ngx-rtmp-handler.patch"; + url = "https://github.com/arut/nginx-rtmp-module/commit/6c7719d0ba32e00b563ec70bd43dad11960fa9c4.patch"; + hash = "sha256-c2hSp4CamBYMwkU9EOUSnfXvCYVOIxm1WzMR/M7Ojcc="; + }) + (fetchpatch { + name = "remove-unused-variables-ngx-rtmp-eval.patch"; + url = "https://github.com/arut/nginx-rtmp-module/commit/c56fd73def3eb407155ecebc28af84ea83dc99e5.patch"; + hash = "sha256-APXdEsRp3SSUKM9ud8tbZEPsfOe/055TRD7FFHE2k9w="; + }) + ]; + + meta = { + description = "Media Streaming Server"; + homepage = "https://github.com/arut/nginx-rtmp-module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/secure-token/package.nix b/pkgs/servers/http/nginx/modules/secure-token/package.nix new file mode 100644 index 000000000000..e0a4303e0212 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/secure-token/package.nix @@ -0,0 +1,27 @@ +{ + lib, + fetchFromGitHub, + mkNginxPlugin, + openssl, +}: + +mkNginxPlugin (finalAttrs: { + pname = "secure-token"; + version = "1.5"; + + src = fetchFromGitHub { + owner = "kaltura"; + repo = "nginx-secure-token-module"; + tag = finalAttrs.version; + hash = "sha256-qYTjGS9pykRqMFmNls52YKxEdXYhHw+18YC2zzdjEpU="; + }; + + buildInputs = [ openssl ]; + + meta = { + description = "Generates CDN tokens, either as a cookie or as a query string parameter"; + homepage = "https://github.com/kaltura/nginx-secure-token-module"; + license = lib.licenses.agpl3Only; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/set-misc/package.nix b/pkgs/servers/http/nginx/modules/set-misc/package.nix new file mode 100644 index 000000000000..0f299ad65240 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/set-misc/package.nix @@ -0,0 +1,33 @@ +{ + lib, + fetchFromGitHub, + mkNginxPlugin, + nginx, + nginxModules, +}: + +mkNginxPlugin (finalAttrs: { + pname = "set-misc"; + version = "0.33"; + + src = fetchFromGitHub { + owner = "openresty"; + repo = "set-misc-nginx-module"; + tag = "v${finalAttrs.version}"; + hash = "sha256-jMMj3Ki1uSfQzagoB/O4NarxPjiaF9YRwjSKo+cgMxo="; + }; + + passthru.tests.nginx = nginx.override { + modules = [ + nginxModules.develkit + finalAttrs.finalPackage + ]; + }; + + meta = { + description = "Various set_xxx directives added to the rewrite module (md5/sha1, sql/json quoting and many more)"; + homepage = "https://github.com/openresty/set-misc-nginx-module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/shibboleth/package.nix b/pkgs/servers/http/nginx/modules/shibboleth/package.nix new file mode 100644 index 000000000000..061783d0fb99 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/shibboleth/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "shibboleth"; + version = "2.0.1-unstable-2020-09-04"; + + src = fetchFromGitHub { + owner = "nginx-shib"; + repo = "nginx-http-shibboleth"; + rev = "3f5ff4212fa12de23cb1acae8bf3a5a432b3f43b"; + hash = "sha256-xsPzEhT6gEma8W2u779JSfkBcw27cfzYmzGer26U34w="; + }; + + meta = { + description = "Shibboleth auth request"; + homepage = "https://github.com/nginx-shib/nginx-http-shibboleth"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/sla/package.nix b/pkgs/servers/http/nginx/modules/sla/package.nix new file mode 100644 index 000000000000..e3d3cdd57716 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/sla/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "sla"; + version = "0-unstable-2015-09-21"; + + src = fetchFromGitHub { + owner = "goldenclone"; + repo = "nginx-sla"; + rev = "7778f0125974befbc83751d0e1cadb2dcea57601"; + sha256 = "1x5hm6r0dkm02ffny8kjd7mmq8przyd9amg2qvy5700x6lb63pbs"; + }; + + meta = { + description = "Implements a collection of augmented statistics based on HTTP-codes and upstreams response time"; + homepage = "https://github.com/goldenclone/nginx-sla"; + license = lib.licenses.unfree; # no license in repo + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/slowfs-cache/package.nix b/pkgs/servers/http/nginx/modules/slowfs-cache/package.nix new file mode 100644 index 000000000000..9affd94a69dc --- /dev/null +++ b/pkgs/servers/http/nginx/modules/slowfs-cache/package.nix @@ -0,0 +1,25 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "slowfs-cache"; + version = "1.10"; + + src = fetchFromGitHub { + owner = "FRiCKLE"; + repo = "ngx_slowfs_cache"; + tag = finalAttrs.version; + hash = "sha256-uddV7vlc7SqnRp5L36+yr6wGylNjwxsq/kNzdgVQ378="; + }; + + meta = { + description = "Adds ability to cache static files"; + homepage = "https://github.com/friCKLE/ngx_slowfs_cache"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; + +}) diff --git a/pkgs/servers/http/nginx/modules/sorted-querystring/package.nix b/pkgs/servers/http/nginx/modules/sorted-querystring/package.nix new file mode 100644 index 000000000000..6e9dc33ddf6e --- /dev/null +++ b/pkgs/servers/http/nginx/modules/sorted-querystring/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "sorted-querystring"; + version = "0.3"; + + src = fetchFromGitHub { + owner = "wandenberg"; + repo = "nginx-sorted-querystring-module"; + tag = finalAttrs.version; + hash = "sha256-Rz5ylx1e/gukwphANc06m92xIJnpdtLdETYNzRkEy1w="; + }; + + meta = { + description = "Expose querystring parameters sorted in a variable"; + homepage = "https://github.com/wandenberg/nginx-sorted-querystring-module"; + license = lib.licenses.mit; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/spnego-http-auth/package.nix b/pkgs/servers/http/nginx/modules/spnego-http-auth/package.nix new file mode 100644 index 000000000000..fcc8cfc0556f --- /dev/null +++ b/pkgs/servers/http/nginx/modules/spnego-http-auth/package.nix @@ -0,0 +1,30 @@ +{ + fetchFromGitHub, + lib, + libkrb5, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "spnego-http-auth"; + version = "1.1.1-unstable-2023-04-14"; + + src = fetchFromGitHub { + owner = "stnoonan"; + repo = "spnego-http-auth-nginx-module"; + rev = "3575542b3147bd03a6c68a750c3662b0d72ed94e"; + hash = "sha256-s0m5h7m7dsPD5o2SvBb9L2kB57jwXZK5SkdkGuOmlgs="; + }; + + buildInputs = [ libkrb5 ]; + + meta = { + description = "SPNEGO HTTP Authentication Module"; + homepage = "https://github.com/stnoonan/spnego-http-auth-nginx-module"; + license = lib.licenses.bsd2; + maintainers = with lib.maintainers; [ + de11n + despsyched + ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/stream-sts/package.nix b/pkgs/servers/http/nginx/modules/stream-sts/package.nix new file mode 100644 index 000000000000..831b82bdb13d --- /dev/null +++ b/pkgs/servers/http/nginx/modules/stream-sts/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "stream-sts"; + version = "0.1.1"; + + src = fetchFromGitHub { + owner = "vozlt"; + repo = "nginx-module-stream-sts"; + tag = "v${finalAttrs.version}"; + hash = "sha256-yquPvEhfY1nb+BLnDDyzC1d4Jp49mO5tonlQM+MMssk="; + }; + + meta = { + description = "Stream server traffic status core module"; + homepage = "https://github.com/vozlt/nginx-module-stream-sts"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/sts/package.nix b/pkgs/servers/http/nginx/modules/sts/package.nix new file mode 100644 index 000000000000..33899501dae0 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/sts/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "sts"; + version = "0.1.1"; + + src = fetchFromGitHub { + owner = "vozlt"; + repo = "nginx-module-sts"; + tag = "v${finalAttrs.version}"; + hash = "sha256-M1PXnLWniyZVjp3pjobmt23KMfGWNb9aPTH0QEwSa1s="; + }; + + meta = { + description = "Stream server traffic status module"; + homepage = "https://github.com/vozlt/nginx-module-sts"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/subsFilter/package.nix b/pkgs/servers/http/nginx/modules/subsFilter/package.nix new file mode 100644 index 000000000000..d45359fd3a88 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/subsFilter/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "subsFilter"; + version = "0.6.4-unstable-2022-01-24"; + + src = fetchFromGitHub { + owner = "yaoweibin"; + repo = "ngx_http_substitutions_filter_module"; + rev = "e12e965ac1837ca709709f9a26f572a54d83430e"; + hash = "sha256-3sWgue6QZYwK69XSi9q8r3WYGVyMCIgfqqLvPBHqJKU="; + }; + + meta = { + description = "Filter module which can do both regular expression and fixed string substitutions"; + homepage = "https://github.com/yaoweibin/ngx_http_substitutions_filter_module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/sysguard/package.nix b/pkgs/servers/http/nginx/modules/sysguard/package.nix new file mode 100644 index 000000000000..7ed1535a2b42 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/sysguard/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "sysguard"; + version = "0-unstable-2017-03-21"; + + src = fetchFromGitHub { + owner = "vozlt"; + repo = "nginx-module-sysguard"; + rev = "e512897f5aba4f79ccaeeebb51138f1704a58608"; + sha256 = "19c6w6wscbq9phnx7vzbdf4ay6p2ys0g7kp2rmc9d4fb53phrhfx"; + }; + + meta = { + description = "Nginx sysguard module"; + homepage = "https://github.com/vozlt/nginx-module-sysguard"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/upload/package.nix b/pkgs/servers/http/nginx/modules/upload/package.nix new file mode 100644 index 000000000000..52075d9ee2dc --- /dev/null +++ b/pkgs/servers/http/nginx/modules/upload/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "upload"; + version = "2.3.0"; + + src = fetchFromGitHub { + owner = "fdintino"; + repo = "nginx-upload-module"; + tag = finalAttrs.version; + hash = "sha256-8veZP516oC7TESO368ZsZreetbDt+1eTcamk7P1kWjU="; + }; + + meta = { + description = "Handle file uploads using multipart/form-data encoding and resumable uploads"; + homepage = "https://github.com/fdintino/nginx-upload-module"; + license = lib.licenses.bsd3; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/upstream-check/package.nix b/pkgs/servers/http/nginx/modules/upstream-check/package.nix new file mode 100644 index 000000000000..b91fd1190405 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/upstream-check/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "upstream-check"; + version = "0.3.0-unstable-2019-11-03"; + + src = fetchFromGitHub { + owner = "yaoweibin"; + repo = "nginx_upstream_check_module"; + rev = "e538034b6ad7992080d2403d6d3da56e4f7ac01e"; + hash = "sha256-lJzVs+B/1VjGiQeDyl0md/6o1AYVgeWxx7+LAwiYxxs="; + }; + + meta = { + description = "Support upstream health check"; + homepage = "https://github.com/yaoweibin/nginx_upstream_check_module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/upstream-tarantool/package.nix b/pkgs/servers/http/nginx/modules/upstream-tarantool/package.nix new file mode 100644 index 000000000000..fa7c35dd1422 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/upstream-tarantool/package.nix @@ -0,0 +1,32 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, + msgpuck, + yajl, +}: + +mkNginxPlugin (finalAttrs: { + pname = "upstream-tarantool"; + version = "2.7.1"; + + src = fetchFromGitHub { + owner = "tarantool"; + repo = "nginx_upstream_module"; + tag = "v${finalAttrs.version}"; + sha256 = "0ya4330in7zjzqw57djv4icpk0n1j98nvf0f8v296yi9rjy054br"; + }; + + buildInputs = [ + msgpuck.dev + yajl + ]; + + meta = { + description = "Tarantool NginX upstream module (REST, JSON API, websockets, load balancing)"; + homepage = "https://github.com/tarantool/nginx_upstream_module"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; + +}) diff --git a/pkgs/servers/http/nginx/modules/url/package.nix b/pkgs/servers/http/nginx/modules/url/package.nix new file mode 100644 index 000000000000..14895761a41a --- /dev/null +++ b/pkgs/servers/http/nginx/modules/url/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "url"; + version = "0-unstable-2017-03-21"; + + src = fetchFromGitHub { + owner = "vozlt"; + repo = "nginx-module-url"; + rev = "9299816ca6bc395625c3683fbd2aa7b916bfe91e"; + sha256 = "0mk1gjmfnry6hgdsnlavww9bn7223idw50jlkhh5k00q5509w4ip"; + }; + + meta = { + description = "URL encoding converting module"; + homepage = "https://github.com/vozlt/nginx-module-url"; + license = lib.licenses.bsd2; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix b/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix new file mode 100644 index 000000000000..54070a0ea7e0 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix @@ -0,0 +1,31 @@ +{ + fetchFromGitHub, + mkNginxPlugin, + lib, + ffmpeg-headless, + libjpeg, +}: + +mkNginxPlugin (finalAttrs: { + pname = "video-thumbextractor"; + version = "1.0.0"; + + src = fetchFromGitHub { + owner = "wandenberg"; + repo = "nginx-video-thumbextractor-module"; + tag = finalAttrs.version; + hash = "sha256-F2cuzCbJdGYX0Zmz9MSXTB7x8+FBR6pPpXtLlDRCcj8="; + }; + + buildInputs = [ + ffmpeg-headless + libjpeg + ]; + + meta = { + description = "Extract thumbs from a video file"; + homepage = "https://github.com/wandenberg/nginx-video-thumbextractor-module"; + license = lib.licenses.gpl3; + maintainers = [ ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/vod/package.nix b/pkgs/servers/http/nginx/modules/vod/package.nix new file mode 100644 index 000000000000..29ac8fdf85c3 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/vod/package.nix @@ -0,0 +1,46 @@ +{ + lib, + fetchFromGitHub, + mkNginxPlugin, + ffmpeg-headless, + fdk_aac, + openssl, + libxml2, + libiconv, + nixosTests, +}: + +mkNginxPlugin (finalAttrs: { + pname = "vod"; + version = "1.9.1"; + + src = fetchFromGitHub { + owner = "dio-az"; + repo = "nginx-vod-module"; + tag = "v${finalAttrs.version}"; + hash = "sha256-18LA3Thiz4EnVkRp6j5BuTyIcd0zXgyyvW6yuzm7vRs="; + }; + + postPatch = '' + substituteInPlace vod/media_set.h \ + --replace-fail "MAX_CLIPS (128)" "MAX_CLIPS (1024)" + ''; + + buildInputs = [ + ffmpeg-headless + fdk_aac + openssl + libxml2 + libiconv + ]; + + passthru.tests = { inherit (nixosTests) frigate; }; + + meta = { + changelog = "https://github.com/dio-az/nginx-vod-module/releases/tag/${finalAttrs.src.tag}"; + description = "VOD packager"; + homepage = "https://github.com/dio-az/nginx-vod-module"; + license = lib.licenses.agpl3Only; + maintainers = [ lib.maintainers.hexa ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/vts/package.nix b/pkgs/servers/http/nginx/modules/vts/package.nix new file mode 100644 index 000000000000..fffb783fd6fe --- /dev/null +++ b/pkgs/servers/http/nginx/modules/vts/package.nix @@ -0,0 +1,24 @@ +{ + fetchFromGitHub, + lib, + mkNginxPlugin, +}: + +mkNginxPlugin (finalAttrs: { + pname = "vts"; + version = "0.2.2"; + + src = fetchFromGitHub { + owner = "vozlt"; + repo = "nginx-module-vts"; + tag = "v${finalAttrs.version}"; + hash = "sha256-ReTmYGVSOwtnYDMkQDMWwxw09vT4iHYfYZvgd8iBotk="; + }; + + meta = { + description = "Virtual host traffic status module"; + homepage = "https://github.com/vozlt/nginx-module-vts"; + license = lib.licenses.bsd2; + maintainers = with lib.maintainers; [ SuperSandro2000 ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/zip/package.nix b/pkgs/servers/http/nginx/modules/zip/package.nix new file mode 100644 index 000000000000..1ff4e5bf658a --- /dev/null +++ b/pkgs/servers/http/nginx/modules/zip/package.nix @@ -0,0 +1,38 @@ +{ + fetchFromGitHub, + fetchpatch, + lib, + mkNginxPlugin, + stdenv, +}: + +mkNginxPlugin (finalAttrs: { + pname = "zip"; + version = "1.3.0"; + + src = fetchFromGitHub { + owner = "evanmiller"; + repo = "mod_zip"; + tag = finalAttrs.version; + hash = "sha256-Q5Z/0uVa8nVoQGH1Pfow9KHgnZdTGN8crbgWi/xCH/c="; + }; + + patches = [ + (fetchpatch { + name = "fix-upstream-subrequest-crc-calculation.patch"; + url = "https://github.com/evanmiller/mod_zip/commit/8e65b82c82c7890f67a6107271c127e9881b6313.patch"; + hash = "sha256-rPmdWlTJID/GoS3Ud8S7DM93icA9zWTJ1a4DIVzH5Ug="; + }) + ]; + + meta = { + description = "Streaming ZIP archiver for nginx"; + homepage = "https://github.com/evanmiller/mod_zip"; + license = lib.licenses.bsd3; + broken = stdenv.hostPlatform.isDarwin; + maintainers = with lib.maintainers; [ + DutchGerman + friedow + ]; + }; +}) diff --git a/pkgs/servers/http/nginx/modules/zstd/package.nix b/pkgs/servers/http/nginx/modules/zstd/package.nix new file mode 100644 index 000000000000..012ae4695367 --- /dev/null +++ b/pkgs/servers/http/nginx/modules/zstd/package.nix @@ -0,0 +1,36 @@ +{ + fetchFromGitHub, + fetchpatch, + lib, + mkNginxPlugin, + zstd, +}: + +mkNginxPlugin (finalAttrs: { + pname = "zstd"; + version = "0.1.1"; + + src = fetchFromGitHub { + owner = "tokers"; + repo = "zstd-nginx-module"; + tag = finalAttrs.version; + hash = "sha256-1gCV7uUsuYnZfb9e8VfjWkUloVINOUH5qzeJ03kIHgs="; + }; + + patches = [ + (fetchpatch { + name = "fix-module-order.patch"; + url = "https://github.com/tokers/zstd-nginx-module/commit/f4ba115e0b0eaecde545e5f37db6aa18917d8f4b.patch"; + hash = "sha256-QCd/oBqAAdKpze903Cd119I+FSVYoEW+j38Hhg45hL8="; + }) + ]; + + buildInputs = [ zstd ]; + + meta = { + description = "Nginx modules for the Zstandard compression"; + homepage = "https://github.com/tokers/zstd-nginx-module"; + license = lib.licenses.bsd2; + maintainers = with lib.maintainers; [ SuperSandro2000 ]; + }; +}) diff --git a/pkgs/servers/http/tengine/default.nix b/pkgs/servers/http/tengine/default.nix index 615404118e76..c6a7aabab8f3 100644 --- a/pkgs/servers/http/tengine/default.nix +++ b/pkgs/servers/http/tengine/default.nix @@ -47,7 +47,7 @@ stdenv.mkDerivation rec { gperftools jemalloc ] - ++ lib.concatMap (mod: mod.inputs or [ ]) modules; + ++ lib.concatMap (mod: mod.buildInputs or [ ]) modules; patches = [ ../nginx/nix-etag-1.15.4.patch @@ -129,7 +129,7 @@ stdenv.mkDerivation rec { ] ++ optional (gd != null) "--with-http_image_filter_module" ++ optional (with stdenv.hostPlatform; isLinux || isFreeBSD) "--with-file-aio" - ++ map (mod: "--add-module=${mod.src}") modules; + ++ map (mod: "--add-module=${mod}") modules; env.NIX_CFLAGS_COMPILE = "-I${libxml2.dev}/include/libxml2 -Wno-error=implicit-fallthrough -Wno-unterminated-string-initialization" diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index fbd50102e4eb..648fa88bff55 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -7460,7 +7460,21 @@ with pkgs; ]; }; - nginxModules = recurseIntoAttrs (callPackage ../servers/http/nginx/modules.nix { }); + mkNginxPlugin = callPackage ../servers/http/nginx/modules/builder.nix { }; + nginxModules = recurseIntoAttrs ( + lib.makeExtensible ( + self: + let + packages = lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ../servers/http/nginx/modules; + }; + + aliases = import ../servers/http/nginx/modules/aliases.nix self; + in + packages // (lib.optionalAttrs config.allowAliases aliases) + ) + ); # We should move to dynamic modules and create a nginxFull package with all modules nginxShibboleth = nginxStable.override {