From 0e1cf19043e1de969d3f01db70173dbe982b27d6 Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Sun, 1 Dec 2019 16:20:00 -0500 Subject: [PATCH 1/5] buildGoModule: disable consult the checksum database on build Since Go 1.13, `GOSUMDB` defaults to "sum.golang.org", to consult the checksum database of the main module's go.sum. We already use the default behavior when building `go-modules`, but Go tries to consult the checksum database again when building the module, and fails because since it requires `cacert` and `git` which are not propagated when building the package. (cherry picked from commit c5733e7a0933b62144e17947176ebd2e871b4616) --- pkgs/development/go-modules/generic/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/go-modules/generic/default.nix b/pkgs/development/go-modules/generic/default.nix index 55fda78b03e3..4866878f563c 100644 --- a/pkgs/development/go-modules/generic/default.nix +++ b/pkgs/development/go-modules/generic/default.nix @@ -96,6 +96,7 @@ let export GOCACHE=$TMPDIR/go-cache export GOPATH="$TMPDIR/go" + export GOSUMDB=off export GOPROXY=file://${go-modules} runHook postConfigure From dd9a49399ea0e0fc06827e3fa3248a4eab11c396 Mon Sep 17 00:00:00 2001 From: Martin Baillie Date: Sun, 8 Mar 2020 17:47:50 +1100 Subject: [PATCH 2/5] tailscale: init at 0.96-33 Signed-off-by: Martin Baillie (cherry picked from commit 6e055c9f4a3734e1d1b8e9f55be68e6743bf59d3) --- maintainers/maintainer-list.nix | 6 +++ nixos/modules/module-list.nix | 1 + .../modules/services/networking/tailscale.nix | 46 +++++++++++++++++++ pkgs/servers/tailscale/default.nix | 35 ++++++++++++++ pkgs/top-level/all-packages.nix | 2 + 5 files changed, 90 insertions(+) create mode 100644 nixos/modules/services/networking/tailscale.nix create mode 100644 pkgs/servers/tailscale/default.nix diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 5f2b0894bf8a..920614f74193 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -3979,6 +3979,12 @@ githubId = 1269099; name = "Marius Bakke"; }; + mbaillie = { + email = "martin@baillie.email"; + github = "martinbaillie"; + githubId = 613740; + name = "Martin Baillie"; + }; mbbx6spp = { email = "me@susanpotter.net"; github = "mbbx6spp"; diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index 960ecacd8b1f..b4aaff834479 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -704,6 +704,7 @@ ./services/networking/syncthing.nix ./services/networking/syncthing-relay.nix ./services/networking/syncplay.nix + ./services/networking/tailscale.nix ./services/networking/tcpcrypt.nix ./services/networking/teamspeak3.nix ./services/networking/tedicross.nix diff --git a/nixos/modules/services/networking/tailscale.nix b/nixos/modules/services/networking/tailscale.nix new file mode 100644 index 000000000000..513c42b40117 --- /dev/null +++ b/nixos/modules/services/networking/tailscale.nix @@ -0,0 +1,46 @@ +{ config, lib, pkgs, ... }: + +with lib; + +let cfg = config.services.tailscale; +in { + meta.maintainers = with maintainers; [ danderson mbaillie ]; + + options.services.tailscale = { + enable = mkEnableOption "Tailscale client daemon"; + + port = mkOption { + type = types.port; + default = 41641; + description = "The port to listen on for tunnel traffic (0=autoselect)."; + }; + }; + + config = mkIf cfg.enable { + systemd.services.tailscale = { + description = "Tailscale client daemon"; + + after = [ "network-pre.target" ]; + wants = [ "network-pre.target" ]; + wantedBy = [ "multi-user.target" ]; + + unitConfig = { + StartLimitIntervalSec = 0; + StartLimitBurst = 0; + }; + + serviceConfig = { + ExecStart = + "${pkgs.tailscale}/bin/tailscaled --port ${toString cfg.port}"; + + RuntimeDirectory = "tailscale"; + RuntimeDirectoryMode = 755; + + StateDirectory = "tailscale"; + StateDirectoryMode = 700; + + Restart = "on-failure"; + }; + }; + }; +} diff --git a/pkgs/servers/tailscale/default.nix b/pkgs/servers/tailscale/default.nix new file mode 100644 index 000000000000..52b6f36dd020 --- /dev/null +++ b/pkgs/servers/tailscale/default.nix @@ -0,0 +1,35 @@ +{ lib, buildGoModule, fetchFromGitHub, makeWrapper, iptables, iproute }: + +buildGoModule rec { + pname = "tailscale"; + version = "0.96-33"; + + src = fetchFromGitHub { + owner = "tailscale"; + repo = "tailscale"; + rev = "19cc4f8b8ecfdc16136d8489a1c2b899f556fda7"; + sha256 = "0kcf3mz7fs15dm1dnkvrmdkm3agrl1zlg9ngb7cwfmvkkw1rkl6i"; + }; + + nativeBuildInputs = [ makeWrapper ]; + + CGO_ENABLED = 0; + + goPackagePath = "tailscale.com"; + modSha256 = "1pjqfzw411k6kw8hqf56irnlhnl8947p1ad8yd84zvqqpzfs3jmz"; + subPackages = [ "cmd/tailscale" "cmd/tailscaled" ]; + + postInstall = '' + wrapProgram $out/bin/tailscaled --prefix PATH : ${ + lib.makeBinPath [ iproute iptables ] + } + ''; + + meta = with lib; { + homepage = "https://tailscale.com"; + description = "The node agent for Tailscale, a mesh VPN built on WireGuard"; + platforms = platforms.linux; + license = licenses.bsd3; + maintainers = with maintainers; [ danderson mbaillie ]; + }; +} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 226051ed7bd4..043a5f0ec068 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -15254,6 +15254,8 @@ in syncserver = callPackage ../servers/syncserver { }; + tailscale = callPackage ../servers/tailscale { }; + thanos = callPackage ../servers/monitoring/thanos { }; inherit (callPackages ../servers/http/tomcat { }) From 65ff63723ec8236a021358036dbf26f0acb78bfb Mon Sep 17 00:00:00 2001 From: David Anderson Date: Tue, 17 Mar 2020 22:52:14 -0700 Subject: [PATCH 3/5] tailscale: 0.96-33 -> 0.97-0. Fixes a severe bug with subnet routing. Signed-off-by: David Anderson (cherry picked from commit f61f686dfea53a0e5bb3faf0a5307dcc8f8d03aa) --- pkgs/servers/tailscale/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/servers/tailscale/default.nix b/pkgs/servers/tailscale/default.nix index 52b6f36dd020..2fc08e754b18 100644 --- a/pkgs/servers/tailscale/default.nix +++ b/pkgs/servers/tailscale/default.nix @@ -2,13 +2,13 @@ buildGoModule rec { pname = "tailscale"; - version = "0.96-33"; + version = "0.97-0"; src = fetchFromGitHub { owner = "tailscale"; repo = "tailscale"; - rev = "19cc4f8b8ecfdc16136d8489a1c2b899f556fda7"; - sha256 = "0kcf3mz7fs15dm1dnkvrmdkm3agrl1zlg9ngb7cwfmvkkw1rkl6i"; + rev = "dd14b658a2f42a3b4d78682e4f4f82f730262c5c"; + sha256 = "0ckjqhj99c25h8xgyfkrd19nw5w4a7972nvba9r5faw5micjs02n"; }; nativeBuildInputs = [ makeWrapper ]; @@ -16,7 +16,7 @@ buildGoModule rec { CGO_ENABLED = 0; goPackagePath = "tailscale.com"; - modSha256 = "1pjqfzw411k6kw8hqf56irnlhnl8947p1ad8yd84zvqqpzfs3jmz"; + modSha256 = "0anpakcqz4irwxnm0iwm7wqzh84kv3yxxdvyr38154pbd0ys5pa2"; subPackages = [ "cmd/tailscale" "cmd/tailscaled" ]; postInstall = '' From 75569aa6e4b43f26caaf09aca4340471c4273b15 Mon Sep 17 00:00:00 2001 From: David Anderson Date: Mon, 23 Mar 2020 12:11:14 -0700 Subject: [PATCH 4/5] tailscale: switch version and git ref to use a tag. The tag points to the same commit hash, so the binary is unchanged. Signed-off-by: David Anderson (cherry picked from commit 3fa813e820a90b475e7144512070d7e55d93732e) --- pkgs/servers/tailscale/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/tailscale/default.nix b/pkgs/servers/tailscale/default.nix index 2fc08e754b18..e4cc0889c31f 100644 --- a/pkgs/servers/tailscale/default.nix +++ b/pkgs/servers/tailscale/default.nix @@ -2,12 +2,12 @@ buildGoModule rec { pname = "tailscale"; - version = "0.97-0"; + version = "0.97"; src = fetchFromGitHub { owner = "tailscale"; repo = "tailscale"; - rev = "dd14b658a2f42a3b4d78682e4f4f82f730262c5c"; + rev = "v${version}"; sha256 = "0ckjqhj99c25h8xgyfkrd19nw5w4a7972nvba9r5faw5micjs02n"; }; From 609a3da59e6491ea923e7a8aa25d946483d248ae Mon Sep 17 00:00:00 2001 From: David Anderson Date: Wed, 18 Mar 2020 00:28:53 -0700 Subject: [PATCH 5/5] tailscale: build using Go 1.13 explicitly. Tailscale does not support Go 1.12. Signed-off-by: David Anderson --- pkgs/servers/tailscale/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/tailscale/default.nix b/pkgs/servers/tailscale/default.nix index e4cc0889c31f..ebcd5d3b5617 100644 --- a/pkgs/servers/tailscale/default.nix +++ b/pkgs/servers/tailscale/default.nix @@ -1,6 +1,6 @@ -{ lib, buildGoModule, fetchFromGitHub, makeWrapper, iptables, iproute }: +{ lib, buildGo113Module, fetchFromGitHub, makeWrapper, iptables, iproute }: -buildGoModule rec { +buildGo113Module rec { pname = "tailscale"; version = "0.97";