mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-08-26 02:05:02 +00:00
Compare commits
600 Commits
haskell-up
...
python-upd
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
61b48aa20d | ||
|
|
b272417adb | ||
|
|
e32c7f646b | ||
|
|
5ce51871f1 | ||
|
|
4c8b3c949a | ||
|
|
e3d61b4a30 | ||
|
|
e1574ff116 | ||
|
|
93be76f22e | ||
|
|
fb55523cc9 | ||
|
|
499b069560 | ||
|
|
5ce79908e4 | ||
|
|
324d00771d | ||
|
|
ba0d9ac39e | ||
|
|
b195440c27 | ||
|
|
d9fb8767ea | ||
|
|
ec24eed6be | ||
|
|
368b4e3e8f | ||
|
|
f41f9e40ec | ||
|
|
d7799a5777 | ||
|
|
cacfd88b36 | ||
|
|
0b271e701f | ||
|
|
9626bfd0b3 | ||
|
|
ed753aa380 | ||
|
|
a22b968cde | ||
|
|
37a1386ae4 | ||
|
|
0bea3bc3bb | ||
|
|
b76a2e5d8a | ||
|
|
e662b812c2 | ||
|
|
26888d68cf | ||
|
|
f48b39f6e2 | ||
|
|
e2e3dfbe8b | ||
|
|
bb8f863ed5 | ||
|
|
4543a1076a | ||
|
|
1411e5f2e4 | ||
|
|
698e7f1bf8 | ||
|
|
6930f049f7 | ||
|
|
14979ee144 | ||
|
|
944f2aedef | ||
|
|
287e40969e | ||
|
|
78606619c9 | ||
|
|
e61bbe73d6 | ||
|
|
b60d32eaa0 | ||
|
|
52adf233e7 | ||
|
|
3545da3e6f | ||
|
|
5a385de6e6 | ||
|
|
3264dc441f | ||
|
|
26799bffc4 | ||
|
|
f40b43c757 | ||
|
|
f2b8b10dd2 | ||
|
|
eea26947e0 | ||
|
|
9124c445f9 | ||
|
|
dc303a6911 | ||
|
|
5b0714066b | ||
|
|
1c0485361e | ||
|
|
190f48674f | ||
|
|
dff4bac425 | ||
|
|
3647038b49 | ||
|
|
266771687d | ||
|
|
51c34c5cb0 | ||
|
|
3f88eca4ef | ||
|
|
cf6a587939 | ||
|
|
aa98290bd5 | ||
|
|
9db3a0f536 | ||
|
|
84e5bb992b | ||
|
|
5f7017d408 | ||
|
|
ab4633cdb5 | ||
|
|
0b8d1e228b | ||
|
|
791ccd6a86 | ||
|
|
d9576d7a6f | ||
|
|
86fc9e9ea6 | ||
|
|
821eced83d | ||
|
|
25254b4718 | ||
|
|
9c6107fafe | ||
|
|
ec5de6e3d8 | ||
|
|
8545db5000 | ||
|
|
4bd2c14901 | ||
|
|
692674689b | ||
|
|
c88cc0c63a | ||
|
|
6da65ad9af | ||
|
|
caf3208951 | ||
|
|
3ad2416d6e | ||
|
|
925aab1556 | ||
|
|
8982190615 | ||
|
|
f0aabcfb11 | ||
|
|
1f09b63abd | ||
|
|
f892aa56fe | ||
|
|
2d54c62f24 | ||
|
|
1469eabcde | ||
|
|
15cacb1fae | ||
|
|
e4dc456594 | ||
|
|
c067eaaa9b | ||
|
|
5718283335 | ||
|
|
c0ed90edb4 | ||
|
|
2b08ab0361 | ||
|
|
f01f9be291 | ||
|
|
3be7fd074e | ||
|
|
504c80164f | ||
|
|
a4a9a62690 | ||
|
|
863df2caa7 | ||
|
|
5dd1b9161b | ||
|
|
55d525b34d | ||
|
|
55b8e342d7 | ||
|
|
c61a66652f | ||
|
|
d3edbaeb90 | ||
|
|
7f57362882 | ||
|
|
d9598bee2f | ||
|
|
c050e495b9 | ||
|
|
2f332e5484 | ||
|
|
942423db98 | ||
|
|
9e53c77b61 | ||
|
|
19d1af29aa | ||
|
|
1b2a108956 | ||
|
|
2c77c60443 | ||
|
|
b55c0e5856 | ||
|
|
859d1bf0d5 | ||
|
|
f8f90eee14 | ||
|
|
e4c2e37eb7 | ||
|
|
49d5798f40 | ||
|
|
7516eee35a | ||
|
|
ba4f118c5e | ||
|
|
36f1637d2b | ||
|
|
ea48ece60c | ||
|
|
24c54a9513 | ||
|
|
6f8000896b | ||
|
|
f448359a18 | ||
|
|
e924a92468 | ||
|
|
7542cb50fb | ||
|
|
3db5a4aae5 | ||
|
|
bcab3054f9 | ||
|
|
d05fc64b89 | ||
|
|
e741a26ae6 | ||
|
|
4ae4a7ca67 | ||
|
|
57d8c9e9ad | ||
|
|
e8366ad33e | ||
|
|
86fa284ce3 | ||
|
|
89e73983c5 | ||
|
|
9d7d266930 | ||
|
|
5965e56fca | ||
|
|
bff998742b | ||
|
|
a1c2dc3534 | ||
|
|
3887b9156c | ||
|
|
041d3f0d94 | ||
|
|
b69582a642 | ||
|
|
60eb6176ca | ||
|
|
7c46d43b6c | ||
|
|
74f668d5f2 | ||
|
|
ade1d5dd46 | ||
|
|
670e6b39d2 | ||
|
|
da5861ef2b | ||
|
|
6786ea6325 | ||
|
|
0e683a4a39 | ||
|
|
1418a69d95 | ||
|
|
7463d02587 | ||
|
|
c7d342aae6 | ||
|
|
89e5386aee | ||
|
|
07be90df68 | ||
|
|
0a9ac260bc | ||
|
|
ee2fafe994 | ||
|
|
efb7906bf9 | ||
|
|
db90242296 | ||
|
|
f4657d0c3b | ||
|
|
f139a08c29 | ||
|
|
d8b83369ea | ||
|
|
9e3013116c | ||
|
|
d07b5a5113 | ||
|
|
64b62a5cb0 | ||
|
|
f1f96de800 | ||
|
|
eafd9c1e07 | ||
|
|
d2b366654a | ||
|
|
828beb3cdf | ||
|
|
0ed9752f34 | ||
|
|
40c53f986a | ||
|
|
51a395e432 | ||
|
|
b4f41c6e2f | ||
|
|
3031bc9c94 | ||
|
|
4403511ea5 | ||
|
|
7d9f2917ad | ||
|
|
ddf7e65a07 | ||
|
|
6ad413f34d | ||
|
|
a19a79870d | ||
|
|
7b00585e50 | ||
|
|
2ef8b564d4 | ||
|
|
4aa653f993 | ||
|
|
8a9c6b007b | ||
|
|
00c45fdb36 | ||
|
|
d13bf4b28a | ||
|
|
2faf0d8eaa | ||
|
|
0c88b229f8 | ||
|
|
a9e252e639 | ||
|
|
893e68d1c0 | ||
|
|
502f9cc1e9 | ||
|
|
19adc38062 | ||
|
|
3d6ee9bd0a | ||
|
|
1b5362f4b6 | ||
|
|
18f7864e80 | ||
|
|
ff7f396fec | ||
|
|
a8c7fb30b9 | ||
|
|
4677725164 | ||
|
|
85f00f3888 | ||
|
|
116a83ad8f | ||
|
|
184fa95254 | ||
|
|
2385946eb7 | ||
|
|
ac9a50f8e5 | ||
|
|
87d0c0243c | ||
|
|
e1b5c2f335 | ||
|
|
6451c5234e | ||
|
|
5119bea3bf | ||
|
|
386d5ff2fe | ||
|
|
0ae2782668 | ||
|
|
1f0faea2a4 | ||
|
|
5e20fb5c99 | ||
|
|
0de0f457a0 | ||
|
|
8d48b402a3 | ||
|
|
2be06dd200 | ||
|
|
540acca8ed | ||
|
|
d06a446383 | ||
|
|
d363998154 | ||
|
|
207d5c3c21 | ||
|
|
7ca2a73185 | ||
|
|
81dcaa099c | ||
|
|
1409fec3b6 | ||
|
|
57554f3957 | ||
|
|
9fe50455d2 | ||
|
|
f7a4954bf5 | ||
|
|
b15e1dd61f | ||
|
|
a1a8d2344c | ||
|
|
6ecbbd7ee2 | ||
|
|
7321cc4e38 | ||
|
|
9097373d6a | ||
|
|
8950825857 | ||
|
|
94e74097fc | ||
|
|
108906408a | ||
|
|
ef78334db4 | ||
|
|
a9f07cd22b | ||
|
|
a604d063ef | ||
|
|
16ea1b063e | ||
|
|
c56a021c54 | ||
|
|
f330d9a250 | ||
|
|
e6851865e1 | ||
|
|
681888fe13 | ||
|
|
9af19f0383 | ||
|
|
0dff61d866 | ||
|
|
92e582fc65 | ||
|
|
a784fc9480 | ||
|
|
ed2e3bd19b | ||
|
|
bbeefb4722 | ||
|
|
ece3343867 | ||
|
|
2acab174f1 | ||
|
|
47e041d7ef | ||
|
|
58bbcb4a0e | ||
|
|
3182fa4ff6 | ||
|
|
11659460f3 | ||
|
|
06b5cf8889 | ||
|
|
33384c706e | ||
|
|
847df597c0 | ||
|
|
876f68c957 | ||
|
|
77e8497dde | ||
|
|
6cc9fddf77 | ||
|
|
781d4f8d04 | ||
|
|
a291f75563 | ||
|
|
a705b6d7e9 | ||
|
|
caa4518896 | ||
|
|
02adbd6118 | ||
|
|
e5fbdd5244 | ||
|
|
40574a2d00 | ||
|
|
eebc652bbc | ||
|
|
83d990326f | ||
|
|
d824389ec6 | ||
|
|
b181a0f6b1 | ||
|
|
1cc834e9f1 | ||
|
|
af6552c7b1 | ||
|
|
801e8ee371 | ||
|
|
5c49c50e7d | ||
|
|
de4945c206 | ||
|
|
cafb11842a | ||
|
|
4706edac92 | ||
|
|
f4781e37ac | ||
|
|
54c7fef77a | ||
|
|
b36f03172c | ||
|
|
23f6d25717 | ||
|
|
3fd00ea287 | ||
|
|
975a364f9c | ||
|
|
b883d1fda7 | ||
|
|
97382f6c33 | ||
|
|
3212eb31aa | ||
|
|
f9d920fc24 | ||
|
|
fc75774074 | ||
|
|
b97f702f3a | ||
|
|
ef9fd1a677 | ||
|
|
5929c9cd9e | ||
|
|
a6f1baa456 | ||
|
|
587129f931 | ||
|
|
2794d8b25a | ||
|
|
79d9f29cf3 | ||
|
|
d5cd6246c9 | ||
|
|
e3eac307b2 | ||
|
|
7250d02ee5 | ||
|
|
bd6af361d3 | ||
|
|
a06546d85d | ||
|
|
e5aedf1290 | ||
|
|
95bb57062a | ||
|
|
a4a950b6a2 | ||
|
|
6b24ce981f | ||
|
|
9d02bb22de | ||
|
|
a0ae440586 | ||
|
|
6a8d5fb088 | ||
|
|
867828012b | ||
|
|
56e0323aca | ||
|
|
d158c0f829 | ||
|
|
babbd29a31 | ||
|
|
33d44ea844 | ||
|
|
ed99820e7c | ||
|
|
444623526a | ||
|
|
7a50c8902c | ||
|
|
cbfc11cf20 | ||
|
|
a4387e8de4 | ||
|
|
186e316b6e | ||
|
|
26b83d4b38 | ||
|
|
8e12cc5caf | ||
|
|
8ba376e900 | ||
|
|
b61328ad76 | ||
|
|
69e30b8505 | ||
|
|
ea4927edc4 | ||
|
|
a7441b6046 | ||
|
|
41e74b8988 | ||
|
|
8f4a4de9be | ||
|
|
7f8e7883da | ||
|
|
b921db5753 | ||
|
|
cffa7f5c84 | ||
|
|
3c4071c408 | ||
|
|
73f1682660 | ||
|
|
b07ecf1f95 | ||
|
|
4793b25276 | ||
|
|
812803d34f | ||
|
|
e25490001d | ||
|
|
a4821e4327 | ||
|
|
209819ee59 | ||
|
|
33e595486f | ||
|
|
79a5400a42 | ||
|
|
39f5970748 | ||
|
|
6b9565d1f7 | ||
|
|
7a00ab8f5c | ||
|
|
27b000ab98 | ||
|
|
03570f0fe0 | ||
|
|
fe7ec9aca8 | ||
|
|
570151cab6 | ||
|
|
f736366402 | ||
|
|
6ccddc4a29 | ||
|
|
60db2bac75 | ||
|
|
8b54bad9b2 | ||
|
|
11392a43ac | ||
|
|
0be3a54895 | ||
|
|
47ba4c4c41 | ||
|
|
094eab3263 | ||
|
|
fc178263ab | ||
|
|
c7bbc03790 | ||
|
|
326e2efdf7 | ||
|
|
21fc5f6c96 | ||
|
|
7ef8c98605 | ||
|
|
bea8e2c42d | ||
|
|
e7075b33df | ||
|
|
5588a4114c | ||
|
|
ef497fb4dd | ||
|
|
344b5e4a23 | ||
|
|
f652472d44 | ||
|
|
71e141a939 | ||
|
|
fa1ad4bf50 | ||
|
|
ead2ca9748 | ||
|
|
70a9024554 | ||
|
|
42b54470e1 | ||
|
|
4f4f833f03 | ||
|
|
9020c570ba | ||
|
|
8771698a5b | ||
|
|
29b449bb9c | ||
|
|
dc2287720e | ||
|
|
b1eb1d5ac4 | ||
|
|
d7192ca583 | ||
|
|
fa0e9d1707 | ||
|
|
26525e318e | ||
|
|
0a5ae99be7 | ||
|
|
98a4ac41e7 | ||
|
|
b83cd70661 | ||
|
|
1a00846a6d | ||
|
|
8d77c864bc | ||
|
|
395954da3c | ||
|
|
58f85b60ba | ||
|
|
8b804bca84 | ||
|
|
fad29117cd | ||
|
|
c1528dcf18 | ||
|
|
45c6c0dacf | ||
|
|
c3f54a0fe7 | ||
|
|
525c922663 | ||
|
|
5445e5568b | ||
|
|
9701f215b6 | ||
|
|
40367998de | ||
|
|
d86838c3ce | ||
|
|
a26bbefab7 | ||
|
|
463b92737c | ||
|
|
6d526ea03e | ||
|
|
3d3e7772be | ||
|
|
462ab4e903 | ||
|
|
73e1150055 | ||
|
|
cea8a31013 | ||
|
|
c1eb87ac8c | ||
|
|
c9eaea5c59 | ||
|
|
378034f39b | ||
|
|
f4437c20a3 | ||
|
|
326ed4a489 | ||
|
|
03bec812cf | ||
|
|
08ed330284 | ||
|
|
341b0f006f | ||
|
|
7b950c35ea | ||
|
|
170e2c53c2 | ||
|
|
18d22c296f | ||
|
|
f5419112b3 | ||
|
|
76fc62a4ff | ||
|
|
f1c8a9dccf | ||
|
|
243023c59f | ||
|
|
61426b952c | ||
|
|
2d72859977 | ||
|
|
092b81d1b2 | ||
|
|
607b78b8d6 | ||
|
|
15d87a6f6a | ||
|
|
3a75353415 | ||
|
|
20cb1af78e | ||
|
|
d4c3de4fee | ||
|
|
b1e3176308 | ||
|
|
7b3757289d | ||
|
|
16ca00d858 | ||
|
|
3cb612acb8 | ||
|
|
347ed477a4 | ||
|
|
864b6b274b | ||
|
|
18fea87be1 | ||
|
|
86cc2ec0bb | ||
|
|
563e58a579 | ||
|
|
da790a532a | ||
|
|
34623b1337 | ||
|
|
c3e2ca860c | ||
|
|
40cd37e2e7 | ||
|
|
1cedc5c564 | ||
|
|
ee8846f1ef | ||
|
|
401ac6a1d5 | ||
|
|
ffd93b67a1 | ||
|
|
31a7d3558e | ||
|
|
f0c4efeff2 | ||
|
|
5dc7bd083a | ||
|
|
2b68575862 | ||
|
|
cf46a560b4 | ||
|
|
3c6c57a723 | ||
|
|
186cec7145 | ||
|
|
bf5197a65e | ||
|
|
4f8b588c9b | ||
|
|
268af4fa13 | ||
|
|
9389f532c8 | ||
|
|
b06f598d96 | ||
|
|
2cd69df9e2 | ||
|
|
d7e449dd55 | ||
|
|
676e32f018 | ||
|
|
a8f84fd85f | ||
|
|
15c7bd4ac0 | ||
|
|
09cbb7889c | ||
|
|
ce3d864a96 | ||
|
|
5a2006a03f | ||
|
|
835b4eae9b | ||
|
|
a276ae0a21 | ||
|
|
e4243618e5 | ||
|
|
63566738ae | ||
|
|
9362859ce4 | ||
|
|
0f3cfe4f81 | ||
|
|
25ae24bb9b | ||
|
|
5c0064324e | ||
|
|
2481a68a59 | ||
|
|
2a85e1db6c | ||
|
|
29a5aa357c | ||
|
|
b195596045 | ||
|
|
94846c88fb | ||
|
|
54022c9502 | ||
|
|
475a60b7d5 | ||
|
|
6e837cd77c | ||
|
|
9a2f606c8d | ||
|
|
70df608e3b | ||
|
|
bfd2076960 | ||
|
|
b3741499c4 | ||
|
|
b1f7cfc432 | ||
|
|
a9ab24dcfd | ||
|
|
8266a99042 | ||
|
|
b0c27a86e1 | ||
|
|
49476baf49 | ||
|
|
489ac8d8f7 | ||
|
|
6cdf08861c | ||
|
|
08994be3c7 | ||
|
|
ffe2e13bad | ||
|
|
77f0199bcc | ||
|
|
ad2f178027 | ||
|
|
214edf7b8c | ||
|
|
880c342134 | ||
|
|
2bb81d73ef | ||
|
|
48cf1eb80f | ||
|
|
7d4f096a7b | ||
|
|
0935c8e495 | ||
|
|
930c8e9e26 | ||
|
|
7d5dbca098 | ||
|
|
9d44cfba88 | ||
|
|
84969077c1 | ||
|
|
642695ad83 | ||
|
|
4ad3307df7 | ||
|
|
18677e9005 | ||
|
|
26f6991cfc | ||
|
|
418eb2c39d | ||
|
|
4fb106f289 | ||
|
|
52397d834f | ||
|
|
bf398265a0 | ||
|
|
19e416de15 | ||
|
|
eb901e94ce | ||
|
|
71d4a58a41 | ||
|
|
01723ab80a | ||
|
|
5925682b6f | ||
|
|
1f97a2fd4a | ||
|
|
2e96796e37 | ||
|
|
97597dff04 | ||
|
|
b56a009699 | ||
|
|
7a7f5fc993 | ||
|
|
f3c2483e0a | ||
|
|
a68bcae7ee | ||
|
|
9e685a1586 | ||
|
|
fb1b7e0c3e | ||
|
|
a795a02721 | ||
|
|
03820fd8ab | ||
|
|
c74a434f78 | ||
|
|
01f25a11a1 | ||
|
|
675324c7eb | ||
|
|
bdd1e3b62f | ||
|
|
0a4e563665 | ||
|
|
570eb566b4 | ||
|
|
72a971ab03 | ||
|
|
8d7caaea50 | ||
|
|
7db9c7ebeb | ||
|
|
fbd0a0633c | ||
|
|
60ce0f7db6 | ||
|
|
8e5cbfaf7b | ||
|
|
ed06a13e39 | ||
|
|
21b180eb4b | ||
|
|
64bf2cc093 | ||
|
|
0ee5d59d1f | ||
|
|
729fcd8f10 | ||
|
|
6db1e0933c | ||
|
|
6dc31cd4da | ||
|
|
5f30573fb4 | ||
|
|
0c2e350997 | ||
|
|
fcef5e359b | ||
|
|
df3ff49869 | ||
|
|
1c04b95b22 | ||
|
|
c6065371e2 | ||
|
|
5df83b898c | ||
|
|
eab3108172 | ||
|
|
d6fdead0f3 | ||
|
|
4808572dcf | ||
|
|
0b59eab01f | ||
|
|
3103284e5a | ||
|
|
85e756065e | ||
|
|
72422068fd | ||
|
|
8c3cd1a2c2 | ||
|
|
9d00d91c87 | ||
|
|
f2a5ca8a20 | ||
|
|
c9638bd7c9 | ||
|
|
b573b7b695 | ||
|
|
c6fce33b87 | ||
|
|
ebc38fa795 | ||
|
|
a1a232b471 | ||
|
|
9522bf9d6c | ||
|
|
564da11dd4 | ||
|
|
ef0f2bf210 | ||
|
|
52a58e6465 | ||
|
|
b59a36d874 | ||
|
|
9d99444486 | ||
|
|
a910fbf5ed | ||
|
|
62b5ec0cef | ||
|
|
f5073d3a8a | ||
|
|
a084ca2557 | ||
|
|
ae380da2fc | ||
|
|
27f0b4544f | ||
|
|
30d64aed75 | ||
|
|
313c73971c | ||
|
|
7f5d8d1888 | ||
|
|
10705c93fd | ||
|
|
4899257e7a | ||
|
|
38691da286 | ||
|
|
36d4dc7578 | ||
|
|
0fe60f516e | ||
|
|
1df6920fa9 | ||
|
|
6f9e207dc9 | ||
|
|
a79457f0e9 | ||
|
|
13d2ccfaaf | ||
|
|
6612bf03f4 | ||
|
|
b40c514e9a | ||
|
|
d3731cb537 | ||
|
|
3bb433eb16 | ||
|
|
dd909fe254 | ||
|
|
bdd04fd7e8 | ||
|
|
afd722eb9e |
@@ -79,7 +79,7 @@ indent_size = unset
|
||||
trim_trailing_whitespace = true
|
||||
|
||||
# binaries
|
||||
[*.{nib,torrent}]
|
||||
[*.nib]
|
||||
end_of_line = unset
|
||||
insert_final_newline = unset
|
||||
trim_trailing_whitespace = unset
|
||||
|
||||
3
.gitattributes
vendored
3
.gitattributes
vendored
@@ -62,6 +62,3 @@ ci/OWNERS linguist-language=CODEOWNERS
|
||||
# patching CRLF line endings from an upstream source package.
|
||||
*.diff !text !eol
|
||||
*.patch !text !eol
|
||||
|
||||
# Torrent files are binary files and should not be re-encoded.
|
||||
*.torrent !text !eol
|
||||
|
||||
2
.github/workflows/build.yml
vendored
2
.github/workflows/build.yml
vendored
@@ -59,7 +59,7 @@ jobs:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
with:
|
||||
# Sandbox is disabled on MacOS by default.
|
||||
extra_nix_config: sandbox = true
|
||||
|
||||
32
.github/workflows/check.yml
vendored
32
.github/workflows/check.yml
vendored
@@ -134,35 +134,6 @@ jobs:
|
||||
GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }}
|
||||
run: gh api /rate_limit | jq
|
||||
|
||||
github-script:
|
||||
runs-on: ubuntu-24.04-arm
|
||||
timeout-minutes: 5
|
||||
steps:
|
||||
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
||||
with:
|
||||
persist-credentials: false
|
||||
sparse-checkout: .github/actions
|
||||
|
||||
- name: Checkout merge and target commits
|
||||
uses: ./.github/actions/checkout
|
||||
with:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- name: Install dependencies to trusted/
|
||||
run: |
|
||||
npm ci --package-lock-only=false
|
||||
echo "$PWD/node_modules/.bin" >> "$GITHUB_PATH"
|
||||
working-directory: nixpkgs/trusted/ci/github-script
|
||||
|
||||
- name: Link trusted/ dependencies to untrusted/
|
||||
run: ln -s "$PWD/trusted/ci/github-script/node_modules" untrusted/ci/github-script/node_modules
|
||||
working-directory: nixpkgs
|
||||
|
||||
- name: Type-check ci/github-script
|
||||
run: tsc --build
|
||||
working-directory: nixpkgs/untrusted/ci/github-script
|
||||
|
||||
owners:
|
||||
runs-on: ubuntu-24.04-arm
|
||||
timeout-minutes: 5
|
||||
@@ -171,14 +142,13 @@ jobs:
|
||||
with:
|
||||
persist-credentials: false
|
||||
sparse-checkout: .github/actions
|
||||
|
||||
- name: Checkout merge and target commits
|
||||
uses: ./.github/actions/checkout
|
||||
with:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
|
||||
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
|
||||
continue-on-error: true
|
||||
|
||||
8
.github/workflows/eval.yml
vendored
8
.github/workflows/eval.yml
vendored
@@ -139,7 +139,7 @@ jobs:
|
||||
core.info(`Found pinned.json commit: ${ciPinBumpCommit}`)
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
|
||||
- name: Load supported versions
|
||||
id: versions
|
||||
@@ -187,7 +187,7 @@ jobs:
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
|
||||
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
|
||||
continue-on-error: true
|
||||
@@ -277,7 +277,7 @@ jobs:
|
||||
merge-multiple: true
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
|
||||
- name: Combine all output paths and eval stats
|
||||
run: |
|
||||
@@ -486,7 +486,7 @@ jobs:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
|
||||
- name: Install Nix
|
||||
uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
|
||||
- name: Ensure flake outputs on all systems still evaluate
|
||||
run: nix flake check --all-systems --no-build './nixpkgs/untrusted?shallow=1'
|
||||
|
||||
6
.github/workflows/lint.yml
vendored
6
.github/workflows/lint.yml
vendored
@@ -35,7 +35,7 @@ jobs:
|
||||
with:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
|
||||
# TODO: Figure out how to best enable caching for the treefmt job. Cachix won't work well,
|
||||
# because the cache would be invalidated on every commit - treefmt checks every file.
|
||||
@@ -70,7 +70,7 @@ jobs:
|
||||
with:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
|
||||
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
|
||||
continue-on-error: true
|
||||
@@ -100,7 +100,7 @@ jobs:
|
||||
merged-as-untrusted-at: ${{ inputs.mergedSha }}
|
||||
target-as-trusted-at: ${{ inputs.targetSha }}
|
||||
|
||||
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
|
||||
|
||||
- uses: cachix/cachix-action@5f2d7c5294214f71b873db4b969586b980625e71 # v17
|
||||
continue-on-error: true
|
||||
|
||||
1
.mailmap
1
.mailmap
@@ -6,7 +6,6 @@ Christina Sørensen <christina@cafkafk.com> <christinaafk@gmail.com>
|
||||
Christina Sørensen <christina@cafkafk.com> <89321978+cafkafk@users.noreply.github.com>
|
||||
Daniel Løvbrøtte Olsen <me@dandellion.xyz> <daniel.olsen99@gmail.com>
|
||||
Ethan Carter Edwards <ethan@ethancedwards.com> Ethan Edwards <ethancarteredwards@gmail.com>
|
||||
Ethan Carter Edwards <ethan@ethancedwards.com> <ethancedwards8@users.noreply.github.com>
|
||||
Fabian Affolter <mail@fabian-affolter.ch> <fabian@affolter-engineering.ch>
|
||||
Fiona Behrens <me@kloenk.dev>
|
||||
Fiona Behrens <me@kloenk.dev> <me@kloenk.de>
|
||||
|
||||
@@ -957,6 +957,7 @@ The following situations are fully or partially exempt:
|
||||
|
||||
If you believe that someone is using automation without appropriate disclosure and review, you can politely ask them if that’s the case and point them to this policy as appropriate.
|
||||
Please assume good faith and remain civil; it’s not always possible to determine, and it is more likely that someone overlooked this policy than deliberately violated it.
|
||||
If you think someone is continuing to break the policy after this, please escalate to the [Nixpkgs core team](https://nixos.org/community/teams/nixpkgs-core/) rather than fighting over it.
|
||||
|
||||
If a contribution is clearly in violation of the policy (e.g. the contributor admits it was not followed, or there are AI tool attributions that do not meet our required format), it can be closed or hidden, preferably after informing the contributor of the policy and giving them a chance to address the violations.
|
||||
Deliberate violations of this policy are considered to break the [Code of Conduct](https://github.com/NixOS/.github/blob/master/CODE_OF_CONDUCT.md) clause against “Wasting other people’s time with low quality contributions, including but not limited to LLM and bot spam”.
|
||||
|
||||
@@ -361,10 +361,7 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt
|
||||
/pkgs/applications/editors/kakoune @philiptaron
|
||||
|
||||
# LuaPackages
|
||||
/pkgs/development/interpreters/lua-5 @NixOS/lua
|
||||
/pkgs/development/interpreters/luajit @NixOS/lua
|
||||
/pkgs/development/lua-modules @NixOS/lua
|
||||
/pkgs/top-level/lua-packages.nix @NixOS/lua
|
||||
|
||||
# Neovim
|
||||
/pkgs/applications/editors/neovim @NixOS/neovim
|
||||
|
||||
1
ci/github-script/.gitignore
vendored
1
ci/github-script/.gitignore
vendored
@@ -2,4 +2,3 @@ comparison
|
||||
comparison.zip
|
||||
node_modules
|
||||
step-summary.md
|
||||
*.tsbuildinfo
|
||||
|
||||
@@ -31,7 +31,6 @@ runCommand "nixpkgs-vet"
|
||||
env.NIXPKGS_VET_NIX_PACKAGE = nix;
|
||||
}
|
||||
''
|
||||
export NIX_STORE_DIR=$(mktemp -d)
|
||||
export NIX_STATE_DIR=$(mktemp -d)
|
||||
$NIXPKGS_VET_NIX_PACKAGE/bin/nix-store --init
|
||||
|
||||
|
||||
@@ -988,20 +988,6 @@ fetchRadiclePatch {
|
||||
}
|
||||
```
|
||||
|
||||
## `fetchFromTangled` {#fetchfromtangled}
|
||||
|
||||
This is to be used with tangled repositories. `fetchFromTangled` works with
|
||||
very similar arguments to `fetchFromGithub`. However, instead of a `owner` and
|
||||
`repo`, a `did` argument is expected.
|
||||
|
||||
```nix
|
||||
fetchFromTangled {
|
||||
did = "did:plc:jj6ajj6duxnlthwtnob4qyuv"; # tranquil.farm/tranquil-pds
|
||||
tag = "v6.6.0";
|
||||
hash = "sha256-cfTsjmK/IMqT5kMKOGpwwWbBlvtrCDOerUJJ8AVI3kY=";
|
||||
}
|
||||
```
|
||||
|
||||
## `requireFile` {#requirefile}
|
||||
|
||||
`requireFile` allows requesting files that cannot be fetched automatically, but whose content is known.
|
||||
|
||||
3
doc/hooks/ghc.section.md
Normal file
3
doc/hooks/ghc.section.md
Normal file
@@ -0,0 +1,3 @@
|
||||
# GHC {#ghc}
|
||||
|
||||
Creates a temporary package database and registers every Haskell build input in it (TODO: how?).
|
||||
@@ -17,6 +17,7 @@ check-phase-thread-limit-hook.section.md
|
||||
cmake.section.md
|
||||
desktop-file-utils.section.md
|
||||
gdk-pixbuf.section.md
|
||||
ghc.section.md
|
||||
gnome.section.md
|
||||
haredo.section.md
|
||||
installShellFiles.section.md
|
||||
|
||||
@@ -34,21 +34,17 @@ Inside each package set are:
|
||||
- builders: mixRelease, buildRebar3, etc
|
||||
- hooks: for composing builders and packages
|
||||
|
||||
The package set is the only place Erlang and Elixir versions are chosen. Builders such as `mixRelease`, `fetchMixDeps` and `buildMix` take them from the set they are called from, and do not accept `erlang`, `elixir` or `hex` arguments.
|
||||
|
||||
To use a non-default Elixir, derive a new set with `overrideScope`. This keeps the rest of the set consistent, so every builder picks up the overridden Elixir:
|
||||
To use a non-default Elixir it's important to keep the rest of the package set consistent, so it's recommended to use `.extend`. This ensures that builders like `mixRelease`, `fetchMixDeps`, and `buildMix` all pick up the overridden Elixir:
|
||||
|
||||
```nix
|
||||
let
|
||||
beamPackages = beam27Packages.overrideScope (final: prev: { elixir = final.elixir_1_18; });
|
||||
beamPackages = beam27Packages.extend (self: super: { elixir = self.elixir_1_18; });
|
||||
in
|
||||
beamPackages.mixRelease {
|
||||
# ...
|
||||
}
|
||||
```
|
||||
|
||||
`erlang` can be replaced the same way, which is useful for a patched OTP. Every member of the set is built from the set's own `erlang`, so overriding it rebuilds Elixir, Rebar3 and the rest against it.
|
||||
|
||||
## Build Tools {#beam-build-tools}
|
||||
|
||||
### Rebar3 {#beam-build-tools-rebar3}
|
||||
@@ -336,8 +332,8 @@ Usually, we need to create a `shell.nix` file and do our development inside the
|
||||
|
||||
with pkgs;
|
||||
let
|
||||
# pin OTP via beam27Packages/beam28Packages/... and Elixir via overrideScope
|
||||
beamPackages = beam27Packages.overrideScope (final: prev: { elixir = final.elixir_1_18; });
|
||||
# pin OTP via beam27Packages/beam28Packages/... and Elixir via .extend
|
||||
beamPackages = beam27Packages.extend (self: super: { elixir = self.elixir_1_18; });
|
||||
in
|
||||
mkShell { buildInputs = [ beamPackages.elixir ]; }
|
||||
```
|
||||
@@ -372,8 +368,8 @@ Here is an example `shell.nix`.
|
||||
with import <nixpkgs> { };
|
||||
|
||||
let
|
||||
# pin OTP via beam27Packages/beam28Packages/... and Elixir via overrideScope
|
||||
beamPackages = beam27Packages.overrideScope (final: prev: { elixir = final.elixir_1_18; });
|
||||
# pin OTP via beam27Packages/beam28Packages/... and Elixir via .extend
|
||||
beamPackages = beam27Packages.extend (self: super: { elixir = self.elixir_1_18; });
|
||||
|
||||
# define packages to install
|
||||
basePackages = [
|
||||
|
||||
@@ -1,30 +1,49 @@
|
||||
# JavaScript {#language-javascript}
|
||||
# Javascript {#language-javascript}
|
||||
|
||||
## Introduction {#javascript-introduction}
|
||||
|
||||
Package JavaScript applications with the tools below.
|
||||
This contains instructions on how to package JavaScript applications.
|
||||
|
||||
The various tools available will be listed in the [tools-overview](#javascript-tools-overview).
|
||||
Some general principles for packaging will follow.
|
||||
Finally, some tool-specific instructions will be given.
|
||||
|
||||
## Getting unstuck / finding code examples {#javascript-finding-examples}
|
||||
|
||||
If you find you are lacking inspiration for packaging JavaScript applications, the links below might prove useful.
|
||||
Searching online for prior art can be helpful if you are running into solved problems.
|
||||
|
||||
### Github {#javascript-finding-examples-github}
|
||||
|
||||
- Searching Nix files for `yarnConfigHook`: <https://github.com/search?q=yarnConfigHook+language%3ANix&type=code>
|
||||
- Searching just `flake.nix` files for `yarnConfigHook`: <https://github.com/search?q=yarnConfigHook+path%3A**%2Fflake.nix&type=code>
|
||||
|
||||
### Gitlab {#javascript-finding-examples-gitlab}
|
||||
|
||||
- Searching Nix files for `yarnConfigHook`: <https://gitlab.com/search?scope=blobs&search=yarnConfigHook+extension%3Anix>
|
||||
- Searching just `flake.nix` files for `yarnConfigHook`: <https://gitlab.com/search?scope=blobs&search=yarnConfigHook+filename%3Aflake.nix>
|
||||
|
||||
## Tools overview {#javascript-tools-overview}
|
||||
|
||||
## General principles {#javascript-general-principles}
|
||||
|
||||
The principles below are ordered by importance.
|
||||
The following principles are given in order of importance with potential exceptions.
|
||||
|
||||
### Use the project's Node.js version {#javascript-upstream-node-version}
|
||||
### Try to use the same node version used upstream {#javascript-upstream-node-version}
|
||||
|
||||
It is often not documented which Node.js version the project uses, but if it is, use the same version when packaging.
|
||||
It is often not documented which node version is used upstream, but if it is, try to use the same version when packaging.
|
||||
|
||||
This can be a problem if the project uses the latest and greatest and you are trying to use an earlier version of Node.js.
|
||||
This can be a problem if upstream is using the latest and greatest and you are trying to use an earlier version of node.
|
||||
Some cryptic errors regarding V8 may appear.
|
||||
|
||||
### Use the project's package manager and lock file {#javascript-upstream-package-manager}
|
||||
### Try to respect the package manager originally used by upstream (and use the upstream lock file) {#javascript-upstream-package-manager}
|
||||
|
||||
A lock file (package-lock.json, yarn.lock...) is supposed to make reproducible installations of `node_modules` for each tool.
|
||||
|
||||
Package manager guidelines recommend committing those lock files to the repository.
|
||||
If a particular lock file is present, it is a strong indication of which package manager the project uses.
|
||||
Guidelines of package managers, recommend to commit those lock files to the repos.
|
||||
If a particular lock file is present, it is a strong indication of which package manager is used upstream.
|
||||
|
||||
Use a Nix tool that understands the lock file.
|
||||
It's better to try to use a Nix tool that understands the lock file.
|
||||
Using a different tool might give you a hard-to-understand error because different packages have been installed.
|
||||
|
||||
Using a different tool forces you to commit a lock file to the repository.
|
||||
@@ -32,16 +51,16 @@ These files are fairly large, so when packaging for nixpkgs, this approach does
|
||||
|
||||
Exceptions to this rule are:
|
||||
|
||||
- When you encounter one of the bugs from a Nix tool. In each of the tool-specific instructions, known problems are detailed. If a tool has a problem, try another. You may have to re-create a lock file and commit it to Nixpkgs.
|
||||
- Some lock files contain a particular version of a package that has been pulled off npm for some reason. In that case, you can recreate the lock file (by removing the original and running `npm install`, `yarn`, etc.) and commit this to Nixpkgs.
|
||||
- When you encounter one of the bugs from a Nix tool. In each of the tool-specific instructions, known problems will be detailed. If you have a problem with a particular tool, then it's best to try another tool, even if this means you will have to re-create a lock file and commit it to Nixpkgs.
|
||||
- Some lock files contain particular version of a package that has been pulled off npm for some reason. In that case, you can recreate upstream lock (by removing the original and `npm install`, `yarn`, ...) and commit this to nixpkgs.
|
||||
|
||||
### Use the project's `package.json` {#javascript-upstream-package-json}
|
||||
### Try to use upstream package.json {#javascript-upstream-package-json}
|
||||
|
||||
Exceptions to this rule are:
|
||||
|
||||
- Sometimes the project assumes some dependencies are installed globally. Add them to the `package.json` manually (`yarn add xxx` or `npm install xxx`). Run locally installed CLI tools with `npx`, for example `npx postcss`. That is how you call them in the phases.
|
||||
- Sometimes the upstream repo assumes some dependencies should be installed globally. In that case, you can add them manually to the upstream `package.json` (`yarn add xxx` or `npm install xxx`, ...). Dependencies that are installed locally can be executed with `npx` for CLI tools (e.g. `npx postcss ...`, this is how you can call those dependencies in the phases).
|
||||
- Sometimes there is a version conflict between some dependency requirements. In that case you can fix a version by removing the `^`.
|
||||
- Sometimes a script in `package.json` does not work as is. It might call a CLI tool that is not available, or `cd` into a directory with a different `package.json`, which is common with workspaces. Read what the script does. Reproduce it in the build phases. For example, a `build` script may call `build:ui` and `build:server` in turn. If one fails, split them into separate steps.
|
||||
- Sometimes the script defined in the package.json does not work as is. Some scripts for example use CLI tools that might not be available, or cd in directory with a different package.json (for workspaces notably). In that case, it's perfectly fine to look at what the particular script is doing and break this down in the phases. In the build script you can see `build:*` calling in turns several other build scripts like `build:ui` or `build:server`. If one of those fails, you can try to separate those into,
|
||||
|
||||
```sh
|
||||
yarn build:ui
|
||||
@@ -51,7 +70,7 @@ Exceptions to this rule are:
|
||||
npm run build:server
|
||||
```
|
||||
|
||||
When you need to override `package.json`, it is best to use the one from the project and make explicit overrides. Here is an example:
|
||||
when you need to override a package.json. It's nice to use the one from the upstream source and do some explicit override. Here is an example:
|
||||
|
||||
```nix
|
||||
{
|
||||
@@ -63,22 +82,22 @@ Exceptions to this rule are:
|
||||
}
|
||||
```
|
||||
|
||||
You still need to commit the modified version of the lock files, but at least the overrides are explicit for everyone to see.
|
||||
You will still need to commit the modified version of the lock files, but at least the overrides are explicit for everyone to see.
|
||||
|
||||
### Use `node_modules` directly {#javascript-using-node_modules}
|
||||
### Using node_modules directly {#javascript-using-node_modules}
|
||||
|
||||
Each tool has an abstraction to build the node_modules (dependencies) directory.
|
||||
Each tool has an abstraction to just build the node_modules (dependencies) directory.
|
||||
You can always use the `stdenv.mkDerivation` with the node_modules to build the package (symlink the node_modules directory and then use the package build command).
|
||||
The `node_modules` abstraction can also be used to build some web framework frontends.
|
||||
For an example of this, see how [plausible](https://github.com/NixOS/nixpkgs/blob/master/pkgs/by-name/pl/plausible/package.nix) is built.
|
||||
Then, when building the frontend, you can symlink the `node_modules` directory.
|
||||
The node_modules abstraction can be also used to build some web framework frontends.
|
||||
For an example of this see how [plausible](https://github.com/NixOS/nixpkgs/blob/master/pkgs/by-name/pl/plausible/package.nix) is built.
|
||||
Then when building the frontend you can just symlink the node_modules directory.
|
||||
|
||||
## Tool-specific instructions {#javascript-tool-specific}
|
||||
|
||||
### buildNpmPackage {#javascript-buildNpmPackage}
|
||||
|
||||
`buildNpmPackage` packages npm-based projects in Nixpkgs without the use of an auto-generated dependencies file.
|
||||
It uses npm's cache. It builds a reproducible cache of the project's dependencies and points npm at it.
|
||||
`buildNpmPackage` allows you to package npm-based projects in Nixpkgs without the use of an auto-generated dependencies file.
|
||||
It works by utilizing npm's cache functionality -- creating a reproducible cache that contains the dependencies of a project, and pointing npm to it.
|
||||
|
||||
Here's an example:
|
||||
|
||||
@@ -116,9 +135,9 @@ buildNpmPackage (finalAttrs: {
|
||||
})
|
||||
```
|
||||
|
||||
In the default `installPhase` set by `buildNpmPackage`, it uses `npm pack --json --dry-run` to decide what files to install. They go in `$out/lib/node_modules/$name/`, where `$name` is the `name` string in the package's `package.json`.
|
||||
In the default `installPhase` set by `buildNpmPackage`, it uses `npm pack --json --dry-run` to decide what files to install in `$out/lib/node_modules/$name/`, where `$name` is the `name` string defined in the package's `package.json`.
|
||||
Additionally, the `bin` and `man` keys in the source's `package.json` are used to decide what binaries and manpages are supposed to be installed.
|
||||
If these are not defined, `npm pack` may miss some files, and no binaries are produced.
|
||||
If these are not defined, `npm pack` may miss some files, and no binaries will be produced.
|
||||
|
||||
#### Arguments {#javascript-buildNpmPackage-arguments}
|
||||
|
||||
@@ -153,8 +172,8 @@ sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
|
||||
|
||||
`fetchNpmDeps` is a Nix function that requires the following mandatory arguments:
|
||||
|
||||
- `src`: A directory or tarball with a `package-lock.json` file
|
||||
- `hash`: The output hash of the dependencies defined in `package-lock.json`.
|
||||
- `src`: A directory / tarball with `package-lock.json` file
|
||||
- `hash`: The output hash of the node dependencies defined in `package-lock.json`.
|
||||
|
||||
It returns a derivation with all `package-lock.json` dependencies downloaded into `$out/`, usable as an npm cache.
|
||||
|
||||
@@ -168,7 +187,7 @@ There is no need to specify a `hash`, since it relies entirely on the integrity
|
||||
|
||||
##### Inputs {#javascript-buildNpmPackage-inputs}
|
||||
|
||||
- `npmRoot`: Path to the package directory containing the source tree.
|
||||
- `npmRoot`: Path to package directory containing the source tree.
|
||||
If this is omitted, the `package` and `packageLock` arguments must be specified instead.
|
||||
- `package`: Parsed contents of `package.json`
|
||||
- `packageLock`: Parsed contents of `package-lock.json`
|
||||
@@ -176,7 +195,7 @@ There is no need to specify a `hash`, since it relies entirely on the integrity
|
||||
- `version`: Package version
|
||||
- `fetcherOpts`: An attribute set of arguments forwarded to the underlying fetcher.
|
||||
|
||||
It returns a derivation with a patched `package.json` and `package-lock.json` with all dependencies resolved to Nix store paths.
|
||||
It returns a derivation with a patched `package.json` & `package-lock.json` with all dependencies resolved to Nix store paths.
|
||||
|
||||
:::{.note}
|
||||
`npmHooks.npmConfigHook` cannot be used with `importNpmLock`.
|
||||
@@ -238,18 +257,18 @@ buildNpmPackage {
|
||||
|
||||
`importNpmLock.buildNodeModules` returns a derivation with a pre-built `node_modules` directory, as imported by `importNpmLock`.
|
||||
|
||||
This is to be used together with `importNpmLock.hooks.linkNodeModulesHook` to support `nix-shell`/`nix develop` development workflows.
|
||||
This is to be used together with `importNpmLock.hooks.linkNodeModulesHook` to facilitate `nix-shell`/`nix develop` based development workflows.
|
||||
|
||||
It accepts an argument with the following attributes:
|
||||
|
||||
`npmRoot` (Path; optional)
|
||||
: Path to the package directory containing the source tree. If not specified, the `package` and `packageLock` arguments must both be specified.
|
||||
: Path to package directory containing the source tree. If not specified, the `package` and `packageLock` arguments must both be specified.
|
||||
|
||||
`package` (Attrset; optional)
|
||||
: Parsed contents of `package.json`, as returned by `lib.importJSON ./my-package.json`. If not specified, the `package.json` in `npmRoot` is used.
|
||||
|
||||
`packageLock` (Attrset; optional)
|
||||
: Parsed contents of `package-lock.json`, as returned by `lib.importJSON ./my-package-lock.json`. If not specified, the `package-lock.json` in `npmRoot` is used.
|
||||
: Parsed contents of `package-lock.json`, as returned `lib.importJSON ./my-package-lock.json`. If not specified, the `package-lock.json` in `npmRoot` is used.
|
||||
|
||||
`derivationArgs` (`mkDerivation` attrset; optional)
|
||||
: Arguments passed to `stdenv.mkDerivation`
|
||||
@@ -269,26 +288,26 @@ pkgs.mkShell {
|
||||
};
|
||||
}
|
||||
```
|
||||
creates a development shell where a `node_modules` directory is created and packages are symlinked to the Nix store when activated.
|
||||
will create a development shell where a `node_modules` directory is created & packages symlinked to the Nix store when activated.
|
||||
|
||||
:::{.note}
|
||||
Commands like `npm install` and `npm add` that write packages and executables need to be used with `--package-lock-only`.
|
||||
Commands like `npm install` & `npm add` that write packages & executables need to be used with `--package-lock-only`.
|
||||
|
||||
This means `npm` installs dependencies by writing into `package-lock.json` without modifying the `node_modules` folder. It installs by reloading the devShell.
|
||||
This gives the `nix shell` near-exclusive ownership over your `node_modules` folder.
|
||||
This means `npm` installs dependencies by writing into `package-lock.json` without modifying the `node_modules` folder. Installation happens through reloading the devShell.
|
||||
This might be best practice since it gives the `nix shell` virtually exclusive ownership over your `node_modules` folder.
|
||||
|
||||
Set `package-lock-only = true` in your project-local [`.npmrc`](https://docs.npmjs.com/cli/v11/configuring-npm/npmrc).
|
||||
It's recommended to set `package-lock-only = true` in your project-local [`.npmrc`](https://docs.npmjs.com/cli/v11/configuring-npm/npmrc).
|
||||
:::
|
||||
|
||||
### corepack {#javascript-corepack}
|
||||
|
||||
This package puts the corepack wrappers for pnpm and yarn in your PATH, and they honor the `packageManager` setting in the `package.json`.
|
||||
This package puts the corepack wrappers for pnpm and yarn in your PATH, and they will honor the `packageManager` setting in the `package.json`.
|
||||
|
||||
### pnpm {#javascript-pnpm}
|
||||
|
||||
pnpm is available as the top-level package `pnpm`. Additionally, there are variants pinned to certain major versions, like `pnpm_9`, `pnpm_10`, `pnpm_10_29_2` and `pnpm_11`, which support different sets of lock file versions.
|
||||
|
||||
When packaging an application that includes a `pnpm-lock.yaml`, you need to fetch the pnpm store for that project using a fixed-output-derivation. The function `fetchPnpmDeps` can create this pnpm store derivation. In conjunction, the setup hook `pnpmConfigHook` prepares the build environment to install the pre-fetched dependencies store. The example below uses the fetcher and setup hook for a package that has `package.json` and `pnpm-lock.yaml`:
|
||||
When packaging an application that includes a `pnpm-lock.yaml`, you need to fetch the pnpm store for that project using a fixed-output-derivation. The function `fetchPnpmDeps` can create this pnpm store derivation. In conjunction, the setup hook `pnpmConfigHook` will prepare the build environment to install the pre-fetched dependencies store. Here is an example for a package that contains `package.json` and a `pnpm-lock.yaml` files using the fetcher and setup hook above:
|
||||
|
||||
There is also the [`pnpmBuildHook`](#pnpm-build-hook) for building packages with `pnpm`, as seen in [](#ex-pnpm-build-hook).
|
||||
|
||||
@@ -331,7 +350,7 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
})
|
||||
```
|
||||
|
||||
Use a pinned version of pnpm (for example `pnpm_9` or `pnpm_10`) to increase reproducibility. An older version may be required if the package needs a certain lock file version. To do so, pass the `pnpm` argument to `fetchPnpmDeps`. Then override the `pnpm` arg in `pnpmConfigHook`. Here are the changes in the example above to use a pinned pnpm version:
|
||||
It is highly recommended to use a pinned version of pnpm (i.e., `pnpm_9` or `pnpm_10`), to increase future reproducibility. It might also be required to use an older version if the package needs support for a certain lock file version. To do so, you can pass the `pnpm` argument to `fetchPnpmDeps` and override the `pnpm` arg in `pnpmConfigHook`. Here are the changes in the example above to use a pinned pnpm version:
|
||||
|
||||
<!-- TODO: Does splicing still work when overriding in nativeBuildInputs here? -->
|
||||
|
||||
@@ -373,7 +392,7 @@ Use a pinned version of pnpm (for example `pnpm_9` or `pnpm_10`) to increase rep
|
||||
})
|
||||
```
|
||||
|
||||
In case you are patching `package.json` or `pnpm-lock.yaml`, make sure to pass `finalAttrs.patches` to the function as well (i.e., `inherit (finalAttrs) patches`).
|
||||
In case you are patching `package.json` or `pnpm-lock.yaml`, make sure to pass `finalAttrs.patches` to the function as well (i.e., `inherit (finalAttrs) patches`.
|
||||
|
||||
`pnpmConfigHook` supports adding additional `pnpm install` flags via `pnpmInstallFlags` which can be set to a Nix string array:
|
||||
|
||||
@@ -389,14 +408,14 @@ In case you are patching `package.json` or `pnpm-lock.yaml`, make sure to pass `
|
||||
}
|
||||
```
|
||||
|
||||
If needed, set `dontPnpmConfigure = true;` to fully disable `pnpmConfigHook` without removing it from inputs manually.
|
||||
If needed, `dontPnpmConfigure = true;` can be used to fully disable `pnpmConfigHook` without manually removing it from inputs.
|
||||
|
||||
#### Dealing with `sourceRoot` {#javascript-pnpm-sourceRoot}
|
||||
|
||||
If the pnpm project is in a subdirectory, you can define `sourceRoot` or `setSourceRoot` for `fetchPnpmDeps`.
|
||||
If `sourceRoot` is different between the parent derivation and `fetchPnpmDeps`, you have to set `pnpmRoot` to effectively be the same location as it is in `fetchPnpmDeps`.
|
||||
If the pnpm project is in a subdirectory, you can just define `sourceRoot` or `setSourceRoot` for `fetchPnpmDeps`.
|
||||
If `sourceRoot` is different between the parent derivation and `fetchPnpmDeps`, you will have to set `pnpmRoot` to effectively be the same location as it is in `fetchPnpmDeps`.
|
||||
|
||||
Assuming the directory structure below, you can define `sourceRoot` and `pnpmRoot`:
|
||||
Assuming the following directory structure, we can define `sourceRoot` and `pnpmRoot` as follows:
|
||||
|
||||
```
|
||||
.
|
||||
@@ -420,9 +439,10 @@ Assuming the directory structure below, you can define `sourceRoot` and `pnpmRoo
|
||||
}
|
||||
```
|
||||
|
||||
#### pnpm workspaces {#javascript-pnpm-workspaces}
|
||||
#### PNPM Workspaces {#javascript-pnpm-workspaces}
|
||||
|
||||
For a pnpm workspace, set `pnpmWorkspaces = [ "<workspace project name 1>" "<workspace project name 2>" ]` in your `fetchPnpmDeps` call. pnpm then installs only the dependencies for those workspace packages.
|
||||
If you need to use a PNPM workspace for your project, then set `pnpmWorkspaces = [ "<workspace project name 1>" "<workspace project name 2>" ]`, etc, in your `fetchPnpmDeps` call,
|
||||
which will make PNPM only install dependencies for those workspace packages.
|
||||
|
||||
For example:
|
||||
|
||||
@@ -438,9 +458,9 @@ For example:
|
||||
```
|
||||
|
||||
The above would make `fetchPnpmDeps` call only install dependencies for the `@astrojs/language-server` workspace package.
|
||||
You do not need to set `sourceRoot` to make this work.
|
||||
Note that you do not need to set `sourceRoot` to make this work.
|
||||
|
||||
For these projects, build with `pnpm --filter=<pnpm workspace name> build`, because `npmHooks.npmBuildHook` may not work. The example below fits most workspace projects:
|
||||
Usually, in such cases, you'd want to use `pnpm --filter=<pnpm workspace name> build` to build your project, as `npmHooks.npmBuildHook` probably won't work. A `buildPhase` based on the following example will probably fit most workspace projects:
|
||||
|
||||
```nix
|
||||
{
|
||||
@@ -454,9 +474,9 @@ For these projects, build with `pnpm --filter=<pnpm workspace name> build`, beca
|
||||
}
|
||||
```
|
||||
|
||||
#### Additional pnpm commands and settings {#javascript-pnpm-extraCommands}
|
||||
#### Additional PNPM Commands and settings {#javascript-pnpm-extraCommands}
|
||||
|
||||
If you require setting an additional pnpm configuration setting (such as `dedupe-peer-dependents` or similar),
|
||||
If you require setting an additional PNPM configuration setting (such as `dedupe-peer-dependents` or similar),
|
||||
set `prePnpmInstall` to the right commands to run. For example:
|
||||
|
||||
```nix
|
||||
@@ -471,11 +491,11 @@ set `prePnpmInstall` to the right commands to run. For example:
|
||||
}
|
||||
```
|
||||
|
||||
In this example, `prePnpmInstall` runs in both `pnpmConfigHook` and the `fetchPnpmDeps` builder.
|
||||
In this example, `prePnpmInstall` will be run by both `pnpmConfigHook` and by the `fetchPnpmDeps` builder.
|
||||
|
||||
#### pnpm `fetcherVersion` {#javascript-pnpm-fetcherVersion}
|
||||
|
||||
This is the version of the output of `fetchPnpmDeps`. Use `4` for new packages:
|
||||
This is the version of the output of `fetchPnpmDeps`. New packages should use `4`:
|
||||
|
||||
```nix
|
||||
{
|
||||
@@ -491,7 +511,7 @@ This is the version of the output of `fetchPnpmDeps`. Use `4` for new packages:
|
||||
When upgrading to a newer `fetcherVersion`, you need to regenerate the hash.
|
||||
|
||||
This variable ensures that we can make changes to the output of `fetchPnpmDeps` without breaking existing hashes.
|
||||
Changes can include workarounds or bug fixes to existing pnpm issues.
|
||||
Changes can include workarounds or bug fixes to existing PNPM issues.
|
||||
|
||||
##### Version history {#javascript-pnpm-fetcherVersion-versionHistory}
|
||||
|
||||
@@ -504,9 +524,9 @@ Version 3 is the minimum supported value. Versions 1 and 2 were removed in the 2
|
||||
|
||||
### Yarn {#javascript-yarn}
|
||||
|
||||
Yarn-based projects use a `yarn.lock` file instead of a `package-lock.json` to pin dependencies.
|
||||
Yarn based projects use a `yarn.lock` file instead of a `package-lock.json` to pin dependencies.
|
||||
|
||||
To package Yarn-based applications, you need to distinguish by the version pointers in the `yarn.lock` file. See the following sections.
|
||||
To package yarn-based applications, you need to distinguish by the version pointers in the `yarn.lock` file. See the following sections.
|
||||
|
||||
#### Yarn v1 {#javascript-yarn-v1}
|
||||
|
||||
@@ -575,12 +595,12 @@ This script by default runs `yarn --offline build`, and it relies upon the proje
|
||||
|
||||
##### `yarnInstallHook` arguments {#javascript-yarninstallhook}
|
||||
|
||||
To install the package, `yarnInstallHook` uses both `npm` and `yarn` to clean up project files and dependencies. To disable this phase, you can set `dontYarnInstall = true` or override the `installPhase`. Below is a list of additional `mkDerivation` arguments read by this hook:
|
||||
To install the package `yarnInstallHook` uses both `npm` and `yarn` to cleanup project files and dependencies. To disable this phase, you can set `dontYarnInstall = true` or override the `installPhase`. Below is a list of additional `mkDerivation` arguments read by this hook:
|
||||
|
||||
- `yarnKeepDevDeps`: Disables the removal of devDependencies from `node_modules` before installation.
|
||||
|
||||
#### Yarn Berry v3/v4 {#javascript-yarn-v3-v4}
|
||||
Yarn Berry (v3 / v4) versions have similar formats. They start with blocks like these:
|
||||
Yarn Berry (v3 / v4) have similar formats, they start with blocks like these:
|
||||
|
||||
```yaml
|
||||
__metadata:
|
||||
@@ -600,7 +620,7 @@ For these packages, we have some helpers exposed under the respective `yarn-berr
|
||||
- `fetchYarnBerryDeps`
|
||||
- `yarnBerryConfigHook`
|
||||
|
||||
Explicitly pin the major version. For example, capture the `yarn-berry_Xn` argument and re-define it as a `yarn-berry` `let` binding.
|
||||
It's recommended to ensure you're explicitly pinning the major version used, for example by capturing the `yarn-berry_Xn` argument and then re-defining it as a `yarn-berry` `let` binding.
|
||||
|
||||
```nix
|
||||
{
|
||||
@@ -636,26 +656,26 @@ stdenv.mkDerivation (finalAttrs: {
|
||||
##### `yarn-berry_X.fetchYarnBerryDeps` {#javascript-fetchYarnBerryDeps}
|
||||
`fetchYarnBerryDeps` runs `yarn-berry-fetcher fetch` in a fixed-output-derivation. It is a custom fetcher designed to reproducibly download all files in the `yarn.lock` file, validating their hashes in the process. For git dependencies, it creates a checkout at `${offlineCache}/checkouts/<40-character-commit-hash>` (relying on the git commit hash to describe the contents of the checkout).
|
||||
|
||||
To produce the `hash` argument for the `fetchYarnBerryDeps` call, run `yarn-berry-fetcher prefetch`:
|
||||
To produce the `hash` argument for `fetchYarnBerryDeps` function call, the `yarn-berry-fetcher prefetch` command can be used:
|
||||
|
||||
```console
|
||||
$ yarn-berry-fetcher prefetch </path/to/yarn.lock> [/path/to/missing-hashes.json]
|
||||
```
|
||||
|
||||
This prints the hash to stdout. Use it in update scripts to recalculate the hash for a new `yarn.lock`.
|
||||
This prints the hash to stdout and can be used in update scripts to recalculate the hash for a new version of `yarn.lock`.
|
||||
|
||||
##### `yarn-berry_X.yarnBerryConfigHook` {#javascript-yarnBerryConfigHook}
|
||||
`yarnBerryConfigHook` uses the store path `offlineCache` points to, to run a `yarn install` during the build, producing a usable `node_modules` directory from the downloaded dependencies.
|
||||
|
||||
Internally, this uses a patched version of Yarn to ensure git dependencies are re-packed and any attempted downloads fail immediately.
|
||||
|
||||
##### Patching the project's `package.json` or `yarn.lock` files {#javascript-yarnBerry-patching}
|
||||
In case patching the project's `package.json` or `yarn.lock` is needed, it's important to pass `finalAttrs.patches` to `fetchYarnBerryDeps` as well, so the patched variants are picked up (i.e., `inherit (finalAttrs) patches`).
|
||||
##### Patching upstream `package.json` or `yarn.lock` files {#javascript-yarnBerry-patching}
|
||||
In case patching the upstream `package.json` or `yarn.lock` is needed, it's important to pass `finalAttrs.patches` to `fetchYarnBerryDeps` as well, so the patched variants are picked up (i.e., `inherit (finalAttrs) patches`.
|
||||
|
||||
##### Missing hashes in the `yarn.lock` file {#javascript-yarnBerry-missing-hashes}
|
||||
Unfortunately, `yarn.lock` files do not include hashes for optional/platform-specific dependencies. This is [by design](https://github.com/yarnpkg/berry/issues/6759).
|
||||
|
||||
To compensate for this, run the `yarn-berry-fetcher missing-hashes` subcommand to produce all missing hashes. These are stored in a `missing-hashes.json` file, which needs to be passed to both the build itself, as well as the `fetchYarnBerryDeps` helper:
|
||||
To compensate for this, the `yarn-berry-fetcher missing-hashes` subcommand can be used to produce all missing hashes. These are usually stored in a `missing-hashes.json` file, which needs to be passed to both the build itself, as well as the `fetchYarnBerryDeps` helper:
|
||||
|
||||
```nix
|
||||
{
|
||||
@@ -698,7 +718,7 @@ If you are packaging something outside Nixpkgs, consider the following:
|
||||
|
||||
### npmlock2nix {#javascript-npmlock2nix}
|
||||
|
||||
[npmlock2nix](https://github.com/nix-community/npmlock2nix) aims at building `node_modules` without code generation. It hasn't reached v1 yet; the API may change.
|
||||
[npmlock2nix](https://github.com/nix-community/npmlock2nix) aims at building `node_modules` without code generation. It hasn't reached v1 yet, the API might be subject to change.
|
||||
|
||||
#### Pitfalls {#javascript-npmlock2nix-pitfalls}
|
||||
|
||||
@@ -706,7 +726,7 @@ There are some [problems with npm v7](https://github.com/tweag/npmlock2nix/issue
|
||||
|
||||
### nix-npm-buildpackage {#javascript-nix-npm-buildpackage}
|
||||
|
||||
[nix-npm-buildpackage](https://github.com/serokell/nix-npm-buildpackage) aims at building `node_modules` without code generation. It hasn't reached v1 yet; the API may change. It supports both `package-lock.json` and yarn.lock.
|
||||
[nix-npm-buildpackage](https://github.com/serokell/nix-npm-buildpackage) aims at building `node_modules` without code generation. It hasn't reached v1 yet, the API might change. It supports both `package-lock.json` and yarn.lock.
|
||||
|
||||
#### Pitfalls {#javascript-nix-npm-buildpackage-pitfalls}
|
||||
|
||||
|
||||
@@ -143,9 +143,6 @@
|
||||
"ex-writeShellApplication": [
|
||||
"index.html#ex-writeShellApplication"
|
||||
],
|
||||
"fetchfromtangled": [
|
||||
"index.html#fetchfromtangled"
|
||||
],
|
||||
"first-package-go": [
|
||||
"index.html#first-package-go"
|
||||
],
|
||||
@@ -2801,6 +2798,9 @@
|
||||
"glycin-dont-wrap": [
|
||||
"index.html#glycin-dont-wrap"
|
||||
],
|
||||
"ghc": [
|
||||
"index.html#ghc"
|
||||
],
|
||||
"gnome-platform": [
|
||||
"index.html#gnome-platform"
|
||||
],
|
||||
@@ -3648,8 +3648,7 @@
|
||||
"index.html#hareHook-cross-compilation"
|
||||
],
|
||||
"haskell": [
|
||||
"index.html#haskell",
|
||||
"index.html#ghc"
|
||||
"index.html#haskell"
|
||||
],
|
||||
"haskell-available-packages": [
|
||||
"index.html#haskell-available-packages"
|
||||
@@ -3778,9 +3777,15 @@
|
||||
"index.html#language-javascript"
|
||||
],
|
||||
"javascript-introduction": [
|
||||
"index.html#javascript-introduction",
|
||||
"index.html#javascript-finding-examples",
|
||||
"index.html#javascript-finding-examples-github",
|
||||
"index.html#javascript-introduction"
|
||||
],
|
||||
"javascript-finding-examples": [
|
||||
"index.html#javascript-finding-examples"
|
||||
],
|
||||
"javascript-finding-examples-github": [
|
||||
"index.html#javascript-finding-examples-github"
|
||||
],
|
||||
"javascript-finding-examples-gitlab": [
|
||||
"index.html#javascript-finding-examples-gitlab"
|
||||
],
|
||||
"javascript-tools-overview": [
|
||||
|
||||
@@ -72,8 +72,6 @@
|
||||
|
||||
- `alps` has been rewritten upstream, see [upstream repository](https://github.com/migadu/alps) for documentation.
|
||||
|
||||
- `writers.makeDataWriter` has been removed. It has been deprecated since 2023. Use `pkgs.writeTextFile` instead.
|
||||
|
||||
- `bosun` has been removed as it is no longer maintained upstream. the corresponding monitoring options has been removed.
|
||||
|
||||
- `uhttpmock` providing 0.0 ABI was removed. `uhttpmock_1_0` providing 1.0 ABI was renamed to `uhttpmock` and `uhttpmock_1_0` was kept as an alias.
|
||||
@@ -84,6 +82,8 @@
|
||||
|
||||
- `nix-serve-ng` (and `haskellPackages.nix-serve-ng`) is now built against Lix instead of CppNix, following upstream which has switched to Lix as its supported Nix implementation.
|
||||
|
||||
- `buildPythonPackage` and `buildPythonApplication` now set `__structuredAttrs = true` by default. You can explicitly set `__structuredAttrs = false` in packages broken by this change.
|
||||
|
||||
- Linux kernel configuration has been moved out of the `linux-kernel` field of the platform structure into the kernel builders:
|
||||
- `linux-kernel.name` has been removed.
|
||||
- `linux-kernel.target` is available as the `target` parameter and passthru attribute on the kernel builders.
|
||||
@@ -101,8 +101,6 @@
|
||||
|
||||
- `pdns` has been updated from `5.0.x` to `5.1.x`. Please be sure to review the [Upgrade Notes](https://doc.powerdns.com/authoritative/upgrading.html#to-5-1-0) before upgrading. Namely LUA record updates are no longer allowed by default, and the embedded webserver no longer includes a `access-control-allow-origin: *` header by default.
|
||||
|
||||
- LibreOffice upstream switched from Fresh/Still stable branches to a single Stable branch; `libreoffice` and `libreoffice-qt` work as before, but more specific aliases like `libreoffice-fresh` should be replaced.
|
||||
|
||||
- `davmail` no longer supports building with GTK 2, and the `preferGtk3` override flag has been removed as GTK 3 is always used.
|
||||
|
||||
- Support for the legacy U‐Boot image format has been removed from the Linux kernel builders, as it is deprecated upstream and no longer used by any platform in Nixpkgs.
|
||||
@@ -163,8 +161,6 @@
|
||||
|
||||
- `buildFHSEnv`, `appimageTools.wrapAppImage`, and `appimageTools.wrapType2` now support the `finalAttrs` pattern. When using `wrapAppImage`, it is now recommended to pass the extracted AppImage to the `contents` attribute (instead of `src`), to avoid shadowing `src`. Passing the extracted contents to `src` is now deprecated and will be removed in a future release.
|
||||
|
||||
- All databases of the MySQL family – `mysql`, `mariadb` and `percona` – now provide a client-only package `client` sub-attribute. Use the `<dbname>.client` package if the server components are not needed. The main package continues to ship the client binaries as well.
|
||||
|
||||
- Package-URL (PURL, https://github.com/package-url/purl-spec) metadata identifier has been added for `fetchgit`, `fetchpypi` and `fetchFromGithub` fetchers.
|
||||
`mkDerivation` has been adjusted to reuse this information.
|
||||
Package-URLs allow reliably identifying and locating software packages.
|
||||
|
||||
@@ -508,7 +508,6 @@ A number between 0 and 7 indicating how much information to log. If set to 1 or
|
||||
#### `enableParallelBuilding` {#var-stdenv-enableParallelBuilding}
|
||||
|
||||
If set to `true`, `stdenv` will pass specific flags to `make` and other build tools to enable parallel building with up to `build-cores` workers.
|
||||
Can be overridden for a specific phase using `enableParallelInstalling` or `enableParallelChecking`.
|
||||
|
||||
Unless set to `false`, some build systems with good support for parallel building including `cmake`, `meson`, and `qmake` will set it to `true`.
|
||||
|
||||
|
||||
@@ -283,12 +283,6 @@ lib.mapAttrs mkLicense (
|
||||
fullName = "BSD 3-Clause Tso variant";
|
||||
};
|
||||
|
||||
bsdAskToEndorse = {
|
||||
#spdxId = "BSD-ask-to-endorse"; # Accepted to SPDX waiting on next SPDX release
|
||||
fullName = "BSD - ask to endorse";
|
||||
url = "https://github.com/sudo-project/sudo/blob/c1307ea9ff340ce0538779f8e456501461fc44b7/plugins/sudoers/redblack.c#L24-L43";
|
||||
};
|
||||
|
||||
bsdAxisNoDisclaimerUnmodified = {
|
||||
fullName = "BSD-Axis without Warranty Disclaimer with Unmodified requirement";
|
||||
url = "https://scancode-licensedb.aboutcode.org/bsd-no-disclaimer-unmodified.html";
|
||||
@@ -715,11 +709,6 @@ lib.mapAttrs mkLicense (
|
||||
url = "https://geant4.web.cern.ch/geant4/license/LICENSE.html";
|
||||
};
|
||||
|
||||
gccException20 = {
|
||||
spdxId = "GCC-exception-2.0";
|
||||
fullName = "GCC Runtime Library exception 2.0";
|
||||
};
|
||||
|
||||
gccException31 = {
|
||||
spdxId = "GCC-exception-3.1";
|
||||
fullName = "GCC Runtime Library exception 3.1";
|
||||
@@ -1295,11 +1284,6 @@ lib.mapAttrs mkLicense (
|
||||
fullName = "Open Data Commons Open Database License v1.0";
|
||||
};
|
||||
|
||||
ofl10 = {
|
||||
spdxId = "OFL-1.0";
|
||||
fullName = "SIL Open Font License 1.0";
|
||||
};
|
||||
|
||||
ofl = {
|
||||
spdxId = "OFL-1.1";
|
||||
fullName = "SIL Open Font License 1.1";
|
||||
@@ -1486,6 +1470,12 @@ lib.mapAttrs mkLicense (
|
||||
fullName = "MIT-STK License";
|
||||
};
|
||||
|
||||
sudo = {
|
||||
shortName = "sudo";
|
||||
fullName = "Sudo License (ISC-style)";
|
||||
url = "https://www.sudo.ws/about/license/";
|
||||
};
|
||||
|
||||
sustainableUse = {
|
||||
spdxId = "SUL-1.0";
|
||||
fullName = "Sustainable Use License";
|
||||
@@ -1653,8 +1643,6 @@ lib.mapAttrs mkLicense (
|
||||
vol-sl = {
|
||||
fullName = "Volatility Software License, Version 1.0";
|
||||
url = "https://www.volatilityfoundation.org/license/vsl-v1.0";
|
||||
free = false;
|
||||
redistributable = true;
|
||||
};
|
||||
|
||||
vsl10 = {
|
||||
|
||||
@@ -161,12 +161,14 @@ let
|
||||
(with final; isWindows && isAarch64);
|
||||
|
||||
# Use the split GCC package set (`gccNGPackages`) instead of the
|
||||
# monolithic `gcc`.
|
||||
# monolithic `gcc`. No platform selects it yet; it is opt-in, set
|
||||
# explicitly on a platform spec, so that the split set can be exercised
|
||||
# before anything depends on it.
|
||||
#
|
||||
# I (@Ericson2314) plan on making more obscure low-tier
|
||||
# platforms (e.g. NetBSD) use it soon, so we can dogfood GCC NG
|
||||
# and thereby iron out its bugs.
|
||||
useGccNG = final.isCygwin;
|
||||
# I (@Ericson2314) plan on making obscure low-tier platforms (e.g.
|
||||
# NetBSD) use it soon, so we can dogfood GCC NG and thereby iron out its
|
||||
# bugs.
|
||||
useGccNG = false;
|
||||
|
||||
libc =
|
||||
if final.isDarwin then
|
||||
|
||||
@@ -262,7 +262,6 @@
|
||||
"stephenstubbs": 18033664,
|
||||
"t-monaghan": 62273348,
|
||||
"thefloweringash": 42933,
|
||||
"thtrf": 82712122,
|
||||
"tricktron": 16036882,
|
||||
"uncenter": 47499684,
|
||||
"usertam": 22500027,
|
||||
@@ -658,6 +657,7 @@
|
||||
"djacu": 7043297
|
||||
},
|
||||
"members": {
|
||||
"Sigmanificient": 53050011,
|
||||
"flyfloh": 74379,
|
||||
"thilobillerbeck": 7442383
|
||||
},
|
||||
@@ -694,8 +694,8 @@
|
||||
"eclairevoyant": 848000
|
||||
},
|
||||
"members": {
|
||||
"daylinmorgan": 47667941,
|
||||
"eveeifyeve": 88671402
|
||||
"Eveeifyeve": 88671402,
|
||||
"daylinmorgan": 47667941
|
||||
},
|
||||
"name": "nim"
|
||||
},
|
||||
@@ -788,11 +788,10 @@
|
||||
"description": "Maintain Pantheon desktop environment and platform",
|
||||
"id": 4786995,
|
||||
"maintainers": {
|
||||
"bobby285271": 20080233,
|
||||
"davidak": 91113
|
||||
},
|
||||
"members": {
|
||||
"amz-x": 18249234
|
||||
"bobby285271": 20080233
|
||||
},
|
||||
"name": "Pantheon"
|
||||
},
|
||||
@@ -856,7 +855,6 @@
|
||||
"lorenzleutgeb": 542154
|
||||
},
|
||||
"members": {
|
||||
"Mic92": 96200,
|
||||
"ju1m": 21160136,
|
||||
"matthiasbeyer": 427866
|
||||
},
|
||||
@@ -897,6 +895,7 @@
|
||||
"0x4A6F": 9675338
|
||||
},
|
||||
"members": {
|
||||
"DarkKirb": 23011243,
|
||||
"dramforever": 2818072,
|
||||
"fgaz": 8182846,
|
||||
"jonhermansen": 660911
|
||||
|
||||
@@ -3694,6 +3694,13 @@
|
||||
githubId = 185443;
|
||||
name = "Alexey Lebedeff";
|
||||
};
|
||||
binary-eater = {
|
||||
email = "sergeantsagara@protonmail.com";
|
||||
github = "Binary-Eater";
|
||||
githubId = 10691440;
|
||||
name = "Rahul Rameshbabu";
|
||||
keys = [ { fingerprint = "678A 8DF1 D9F2 B51B 7110 BE53 FF24 7B3E 5411 387B"; } ];
|
||||
};
|
||||
binarycat = {
|
||||
email = "binarycat@envs.net";
|
||||
github = "lolbinarycat";
|
||||
@@ -4878,12 +4885,6 @@
|
||||
githubId = 543423;
|
||||
name = "Alex Wied";
|
||||
};
|
||||
ceridwen15 = {
|
||||
email = "me@cdwn.gay";
|
||||
github = "NonsensicalNickname";
|
||||
githubId = 118519066;
|
||||
name = "Ceridwen Weaving";
|
||||
};
|
||||
cfouche = {
|
||||
email = "chaddai.fouche@gmail.com";
|
||||
github = "Chaddai";
|
||||
@@ -5424,12 +5425,6 @@
|
||||
githubId = 69784758;
|
||||
matrix = "@clot27:matrix.org";
|
||||
};
|
||||
cloudglides = {
|
||||
name = "Cloud";
|
||||
email = "cloudglides@proton.me";
|
||||
github = "cloudglides";
|
||||
githubId = 111557161;
|
||||
};
|
||||
cloudripper = {
|
||||
email = "dev+nixpkgs@cldrpr.com";
|
||||
github = "cloudripper";
|
||||
@@ -5622,12 +5617,6 @@
|
||||
githubId = 327028;
|
||||
name = "Cole Mickens";
|
||||
};
|
||||
colepearson27 = {
|
||||
name = "Cole Pearson";
|
||||
email = "colepearson27@gmail.com";
|
||||
github = "colepearson27";
|
||||
githubId = 113060096;
|
||||
};
|
||||
colescott = {
|
||||
email = "colescottsf@gmail.com";
|
||||
github = "colescott";
|
||||
@@ -8028,12 +8017,6 @@
|
||||
githubId = 63352906;
|
||||
keys = [ { fingerprint = "922F CA48 5FDB 20B1 ED1B A61F 284D 11D3 33C4 D21B"; } ];
|
||||
};
|
||||
edgarpost = {
|
||||
name = "Edgar Post-Buijs";
|
||||
email = "github@edgarpost.com";
|
||||
github = "EdgarPost";
|
||||
githubId = 488221;
|
||||
};
|
||||
edlimerkaj = {
|
||||
name = "Edli Merkaj";
|
||||
email = "edli.merkaj@identinet.io";
|
||||
@@ -8725,11 +8708,6 @@
|
||||
{ fingerprint = "2E51 F618 39D1 FA94 7A73 00C2 34C0 4305 D581 DBFE"; }
|
||||
];
|
||||
};
|
||||
ethanthoma = {
|
||||
name = "Ethan Thoma";
|
||||
github = "ethanthoma";
|
||||
githubId = 4424467;
|
||||
};
|
||||
ethindp = {
|
||||
name = "Ethin Probst";
|
||||
email = "harlydavidsen@gmail.com";
|
||||
@@ -10435,12 +10413,6 @@
|
||||
github = "gkleen";
|
||||
githubId = 20089782;
|
||||
};
|
||||
gl1tchxd = {
|
||||
name = "Felix Buchsteiner";
|
||||
github = "gl1tchxd-git";
|
||||
githubId = 92686452;
|
||||
email = "contact@gl1tchxd.at";
|
||||
};
|
||||
gleber = {
|
||||
email = "gleber.p@gmail.com";
|
||||
github = "gleber";
|
||||
@@ -11083,12 +11055,6 @@
|
||||
githubId = 79340822;
|
||||
keys = [ { fingerprint = "3582 5B85 66C8 4F36 45C7 EC42 809F 7938 9CB1 8650"; } ];
|
||||
};
|
||||
havunen = {
|
||||
name = "Sampo Kivistö";
|
||||
email = "sampo.kivisto@live.fi";
|
||||
github = "havunen";
|
||||
githubId = 2021355;
|
||||
};
|
||||
hawkw = {
|
||||
email = "eliza@elizas.website";
|
||||
github = "hawkw";
|
||||
@@ -11713,12 +11679,6 @@
|
||||
github = "I-Al-Istannen";
|
||||
githubId = 20284688;
|
||||
};
|
||||
i-love-lean = {
|
||||
name = "i-love-lean";
|
||||
github = "i-love-lean";
|
||||
githubId = 170473930;
|
||||
email = "nixpkgs@unnamed.website";
|
||||
};
|
||||
i01011001 = {
|
||||
email = "yugen.m7@gmail.com";
|
||||
github = "i01011001";
|
||||
@@ -17040,12 +17000,6 @@
|
||||
}
|
||||
];
|
||||
};
|
||||
lunitur = {
|
||||
email = "karlo.puselj@gmail.com";
|
||||
github = "Lunitur";
|
||||
githubId = 8092435;
|
||||
name = "Karlo Pušelj";
|
||||
};
|
||||
lunkentuss = {
|
||||
email = "peter.hansson17@gmail.com";
|
||||
matrix = "@lunkentuss:matrix.org";
|
||||
@@ -17799,11 +17753,6 @@
|
||||
githubId = 29855073;
|
||||
name = "Michael Colicchia";
|
||||
};
|
||||
Masrepus = {
|
||||
github = "Masrepus";
|
||||
githubId = 6538121;
|
||||
name = "Samuel Hopstock";
|
||||
};
|
||||
masrlinu = {
|
||||
github = "masrlinu";
|
||||
githubId = 5259918;
|
||||
@@ -18823,12 +18772,6 @@
|
||||
githubId = 1387206;
|
||||
name = "Mike Sperber";
|
||||
};
|
||||
mikilio = {
|
||||
email = "kilian.mio@mikilio.com";
|
||||
github = "Mikilio";
|
||||
githubId = 86004375;
|
||||
name = "Kilian Mio";
|
||||
};
|
||||
mikoim = {
|
||||
email = "ek@esh.ink";
|
||||
github = "mikoim";
|
||||
@@ -19173,12 +19116,6 @@
|
||||
githubId = 104795;
|
||||
name = "Marek Mahut";
|
||||
};
|
||||
mmclinton = {
|
||||
email = "nixpkg.concur071@simplelogin.com";
|
||||
github = "mmclinton";
|
||||
githubId = 96266047;
|
||||
name = "Miller Clinton";
|
||||
};
|
||||
mmesch = {
|
||||
github = "MMesch";
|
||||
githubId = 2597803;
|
||||
@@ -19501,12 +19438,6 @@
|
||||
githubId = 15896005;
|
||||
name = "Vladyslav Burzakovskyy";
|
||||
};
|
||||
mroboff = {
|
||||
email = "mark.roboff@bluecircuit.ai";
|
||||
github = "mroboff";
|
||||
githubId = 81203001;
|
||||
name = "Mark Roboff";
|
||||
};
|
||||
mrsmoer = {
|
||||
email = "mrsmoer@protonmail.com";
|
||||
github = "MrSmoer";
|
||||
@@ -20941,12 +20872,6 @@
|
||||
githubId = 41154684;
|
||||
name = "nokazn";
|
||||
};
|
||||
nolight132 = {
|
||||
email = "contact@nolight.dev";
|
||||
github = "nolight132";
|
||||
githubId = 71591964;
|
||||
name = "Pavel Olizko";
|
||||
};
|
||||
nolith = {
|
||||
github = "nolith";
|
||||
githubId = 78752;
|
||||
@@ -21702,12 +21627,6 @@
|
||||
name = "Oops418";
|
||||
githubId = 93655215;
|
||||
};
|
||||
opdavies = {
|
||||
email = "oliver+github@oliverdavies.uk";
|
||||
github = "opdavies";
|
||||
githubId = 339813;
|
||||
name = "Oliver Davies";
|
||||
};
|
||||
opeik = {
|
||||
email = "sandro@stikic.com";
|
||||
github = "opeik";
|
||||
@@ -23090,12 +23009,6 @@
|
||||
name = "Pradyuman Vig";
|
||||
keys = [ { fingerprint = "240B 57DE 4271 2480 7CE3 EAC8 4F74 D536 1C4C A31E"; } ];
|
||||
};
|
||||
prauscher = {
|
||||
email = "prauscher@prauscher.de";
|
||||
github = "prauscher";
|
||||
githubId = 175521;
|
||||
name = "Patrick Rauscher";
|
||||
};
|
||||
preisschild = {
|
||||
email = "florian@florianstroeger.com";
|
||||
github = "Preisschild";
|
||||
@@ -23444,6 +23357,12 @@
|
||||
github = "pyle";
|
||||
githubId = 7279609;
|
||||
};
|
||||
pyrotelekinetic = {
|
||||
name = "Clover Ison";
|
||||
email = "clover@isons.org";
|
||||
github = "pyrotelekinetic";
|
||||
githubId = 29682759;
|
||||
};
|
||||
pyrox0 = {
|
||||
name = "Pyrox";
|
||||
email = "pyrox@pyrox.dev";
|
||||
@@ -27452,18 +27371,18 @@
|
||||
name = "Steven Allen";
|
||||
keys = [ { fingerprint = "327B 20CE 21EA 68CF A774 8675 7C92 3221 5899 410C"; } ];
|
||||
};
|
||||
steeleduncan = {
|
||||
email = "steeleduncan@hotmail.com";
|
||||
github = "steeleduncan";
|
||||
githubId = 866573;
|
||||
name = "Duncan Steele";
|
||||
};
|
||||
steell = {
|
||||
email = "steve@steellworks.com";
|
||||
github = "Steell";
|
||||
githubId = 1699155;
|
||||
name = "Steve Elliott";
|
||||
};
|
||||
stefanboca = {
|
||||
email = "stefan.r.boca@gmail.com";
|
||||
github = "stefanboca";
|
||||
githubId = 45266795;
|
||||
name = "Stefan Boca";
|
||||
};
|
||||
stefanfehrenbach = {
|
||||
email = "stefan.fehrenbach@gmail.com";
|
||||
github = "fehrenbach";
|
||||
@@ -27582,12 +27501,6 @@
|
||||
githubId = 4340859;
|
||||
name = "Stian Lågstad";
|
||||
};
|
||||
stig = {
|
||||
email = "stig@circleci.com";
|
||||
github = "stig";
|
||||
githubId = 45407;
|
||||
name = "Stig Brautaset";
|
||||
};
|
||||
StijnDW = {
|
||||
email = "nixdev@rinsa.eu";
|
||||
github = "Stekke";
|
||||
@@ -29375,11 +29288,6 @@
|
||||
githubId = 47905926;
|
||||
name = "toyboot4e";
|
||||
};
|
||||
tpansino = {
|
||||
name = "Tom Pansino";
|
||||
github = "tpansino";
|
||||
githubId = 2768420;
|
||||
};
|
||||
tphanir = {
|
||||
github = "tphanir";
|
||||
name = "phani";
|
||||
@@ -29392,12 +29300,6 @@
|
||||
github = "tpwrules";
|
||||
githubId = 208010;
|
||||
};
|
||||
tr3foil = {
|
||||
name = "Clover Ison";
|
||||
email = "clover@isons.org";
|
||||
github = "tr3foil";
|
||||
githubId = 29682759;
|
||||
};
|
||||
transcaffeine = {
|
||||
name = "transcaffeine";
|
||||
email = "transcaffeine@finally.coffee";
|
||||
@@ -29797,11 +29699,6 @@
|
||||
githubId = 12422133;
|
||||
name = "Chromo-residuum-opec";
|
||||
};
|
||||
ui-1 = {
|
||||
name = "ui-1";
|
||||
github = "ui-1";
|
||||
githubId = 134524800;
|
||||
};
|
||||
uku3lig = {
|
||||
name = "uku";
|
||||
email = "hi@uku.moe";
|
||||
@@ -32219,11 +32116,6 @@
|
||||
githubId = 39456023;
|
||||
name = "Mike Yim";
|
||||
};
|
||||
zeusec = {
|
||||
name = "Cole";
|
||||
github = "zeusec";
|
||||
githubId = 65095161;
|
||||
};
|
||||
zevisert = {
|
||||
email = "dev@zevisert.ca";
|
||||
github = "zevisert";
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
#!/usr/bin/env nix-shell
|
||||
#!nix-shell -i bash
|
||||
#!nix-shell -p jq git
|
||||
# shellcheck shell=bash
|
||||
#
|
||||
# Usage: eval-pkg-sets.sh [extra flags for nix-* commands ...]
|
||||
#
|
||||
# Must be executed in a git checkout of Nixpkgs.
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
NIXPKGS="$(git rev-parse --show-toplevel)"
|
||||
PKGSETS="$(nix-env --readonly-mode --json --drv-path -f "$NIXPKGS" -qaP -A haskell.compiler "$@" \
|
||||
| jq -r 'to_entries | unique_by(.value.drvPath) .[] .key | sub("^haskell.compiler";"haskell.packages")')"
|
||||
|
||||
trap 'exit 1' SIGINT SIGTERM
|
||||
|
||||
set +e
|
||||
|
||||
badsets=""
|
||||
for set in $PKGSETS; do
|
||||
# Confirm an equivalent package set to haskell.compiler.$entry exists and is usable
|
||||
if ! nix-instantiate --readonly-mode -A "$set.ghc" "$@" > /dev/null 2>&1; then
|
||||
echo "Skipping $set... ($set.ghc does not evaluate)"
|
||||
else
|
||||
echo "Evaluating $set..."
|
||||
|
||||
if ! nix-env --readonly-mode -f "$NIXPKGS" -qaP --drv-path -A "$set" "$@" > /dev/null; then
|
||||
badsets+="$set "
|
||||
fi
|
||||
fi
|
||||
done
|
||||
|
||||
if [ -n "$badsets" ]; then
|
||||
echo "Found potential eval issues in the following sets:" >&2
|
||||
# shellcheck disable=SC2086
|
||||
printf '%s\n' $badsets
|
||||
exit 1
|
||||
fi
|
||||
@@ -33,7 +33,7 @@ fi
|
||||
|
||||
# Stackage solver to use, LTS or Nightly
|
||||
# (should be capitalized like the display name)
|
||||
SOLVER=Nightly
|
||||
SOLVER=LTS
|
||||
# Stackage solver version, if any. Use latest if empty
|
||||
VERSION=
|
||||
TMP_TEMPLATE=update-stackage.XXXXXXX
|
||||
@@ -105,7 +105,6 @@ sed -r \
|
||||
-e '/ hledger-ui /d' \
|
||||
-e '/ hledger-web /d' \
|
||||
-e '/ spacecookie /d' \
|
||||
-e '/ hnix-store-core /d' \
|
||||
< "${tmpfile_new}" >> $stackage_config
|
||||
# Explanations:
|
||||
# cabal2nix, distribution-nixpkgs, jailbreak-cabal, language-nix: These are our packages and we know what we are doing.
|
||||
|
||||
@@ -25,11 +25,6 @@ for k in "${!sources[@]}"; do
|
||||
mkdir "$TMPDIR/$k"
|
||||
tar -C "$TMPDIR/$k" -xf "${sources[$k]}"
|
||||
|
||||
if [ "$k" == "kdenlive" ]; then
|
||||
echo "[kdenlive] Applying horrible hack"
|
||||
rm -rf "$TMPDIR/$k/"*"/data/lumas"
|
||||
fi
|
||||
|
||||
(cd "$TMPDIR/$k"; reuse lint --json) | jq --arg name "$k" '{$name: .summary.used_licenses | sort}' -c > "$TMPDIR/$k.json"
|
||||
done
|
||||
|
||||
|
||||
@@ -91,13 +91,13 @@ class KDERepoMetadata:
|
||||
return {p.name: p for p in self.projects}
|
||||
|
||||
@functools.cached_property
|
||||
def projects_by_repo(self):
|
||||
return {p.repo_path: p for p in self.projects}
|
||||
def projects_by_path(self):
|
||||
return {p.project_path: p for p in self.projects}
|
||||
|
||||
def try_lookup_package(self, path):
|
||||
if path in IGNORE:
|
||||
return None
|
||||
project = self.projects_by_repo.get(path)
|
||||
project = self.projects_by_path.get(path)
|
||||
if project is None and path not in WARNED:
|
||||
WARNED.add(path)
|
||||
print(f"Warning: unknown project {path}")
|
||||
@@ -109,7 +109,7 @@ class KDERepoMetadata:
|
||||
Project.from_yaml(metadata_file)
|
||||
for metadata_file in repo_metadata.glob("projects-invent/**/metadata.yaml")
|
||||
] + [
|
||||
Project(id, None, project_path, project_path)
|
||||
Project(id, None, project_path, None)
|
||||
for project_path, id in THIRD_PARTY.items()
|
||||
]
|
||||
|
||||
@@ -125,11 +125,11 @@ class KDERepoMetadata:
|
||||
dep_graph = collections.defaultdict(set)
|
||||
|
||||
if unstable:
|
||||
spec_name = "kde-dependencies-latest-kf6"
|
||||
spec_name = "dependency-data-kf6-qt6"
|
||||
else:
|
||||
spec_name = "kde-dependencies-stable-kf6"
|
||||
spec_name = "dependency-data-stable-kf6-qt6"
|
||||
|
||||
spec_path = repo_metadata / "kde-dependencies" / spec_name
|
||||
spec_path = repo_metadata / "dependencies" / spec_name
|
||||
for line in spec_path.open():
|
||||
line = line.strip()
|
||||
if line.startswith("#"):
|
||||
|
||||
@@ -59,6 +59,6 @@ To make this path available, set the following option:
|
||||
|
||||
```nix
|
||||
{
|
||||
nix.settings.extra-sandbox-paths = [ "/dev/net" ];
|
||||
nix.settings.sandbox-paths = [ "/dev/net" ];
|
||||
}
|
||||
```
|
||||
|
||||
@@ -291,17 +291,10 @@ have a predefined type and string generator already declared under
|
||||
and returning a set with JSON-specific attributes `type` and
|
||||
`generate` as specified [below](#pkgs-formats-result).
|
||||
|
||||
`pkgs.formats.yaml` { *`tags`* ? false }
|
||||
`pkgs.formats.yaml` { }
|
||||
|
||||
: A function taking an attribute set with values
|
||||
|
||||
`tags`
|
||||
|
||||
: A boolean for controlling whether YAML tags can be generated.
|
||||
If set, attribute sets with a single key that starts with a "!"
|
||||
will be interpreted as a YAML tag.
|
||||
|
||||
It returns a set with YAML-specific attributes `type` and
|
||||
: A function taking an empty attribute set (for future extensibility)
|
||||
and returning a set with YAML-specific attributes `type` and
|
||||
`generate` as specified [below](#pkgs-formats-result).
|
||||
|
||||
`pkgs.formats.ini` { *`listsAsDuplicateKeys`* ? false, *`listToValue`* ? null, \.\.\. }
|
||||
|
||||
@@ -464,7 +464,7 @@
|
||||
|
||||
- `services.pds` has been renamed to `services.bluesky-pds`.
|
||||
|
||||
- `services.pfix-srsd` now automatically integrates with the local Postfix instance, when enabled. This behavior can disabled using the `services.pfix-srsd.configurePostfix` option.
|
||||
- `services.pfix-srsd` now automatically integrates with the local Postfix instance, when enabled. This behavior can disabled using the [services.pfix-srsd.configurePostfix](#opt-services.pfix-srsd.configurePostfix) option.
|
||||
|
||||
- `services.postsrsd` now automatically integrates with the local Postfix instance, when enabled. This behavior can disabled using the [services.postsrsd.configurePostfix](#opt-services.postsrsd.configurePostfix) option.
|
||||
|
||||
|
||||
@@ -38,8 +38,6 @@
|
||||
|
||||
- [Moonlight Qt](https://moonlight-stream.org/), a client for playing your PC games on almost any device. Available as [programs.moonlight-qt](#opt-programs.moonlight-qt.enable).
|
||||
|
||||
- [udp514-journal](https://github.com/eworm-de/udp514-journal), a service to forward remote syslog messages to systemd-journal. Available as [services.udp514-journal](#opt-services.udp514-journal.enable).
|
||||
|
||||
- [RomM](https://romm.app/), a self-hosted ROM manager and player. Available as [services.romm](#opt-services.romm.enable).
|
||||
|
||||
- [scx_loader](https://github.com/sched-ext/scx-loader), a system daemon and DBus-based loader for sched_ext schedulers. `scxctl` is the command-line client for interacting with the loader, allowing users to switch schedulers, modes, and arguments dynamically. Available as [services.scx-loader](#opt-services.scx-loader.enable)
|
||||
@@ -54,8 +52,6 @@
|
||||
|
||||
- [mail-tlsa-check-exporter](https://github.com/ietf-tools/mail-tlsa-check-exporter), validates SMTP / IMAP server certificates against a TLSA record as a Prometheus exporter. Available as [services.prometheus.exporters.mail-tlsa-check](#opt-services.prometheus.exporters.mail-tlsa-check.enable).
|
||||
|
||||
- [snowflake-prometheus-exporter](https://github.com/grafana/snowflake-prometheus-exporter), a Prometheus exporter for Snowflake metrics. Available as [services.prometheus.exporters.snowflake](#opt-services.prometheus.exporters.snowflake.enable).
|
||||
|
||||
- [feishin](https://github.com/jeffvli/feishin), a modern self-hosted music player. Available as [services.feishin](#opt-services.feishin.enable).
|
||||
|
||||
- [CastSponsorSkip](https://github.com/gabe565/CastSponsorSkip/), skips YouTube sponsorships (and sometimes ads) on all local Google Cast devices.
|
||||
@@ -88,14 +84,10 @@
|
||||
|
||||
- [Krill](https://nlnetlabs.nl/projects/krill/about), RPKI CA and Publication Server written in Rust. Available as [services.krill](#opt-services.krill.enable).
|
||||
|
||||
- [vellum](https://github.com/greyxp1/vellum) is a live screen annotation overlay for Wayland. Available as [programs.vellum](#opt-programs.vellum.enable).
|
||||
|
||||
- [stash-clipboard](https://github.com/NotAShelf/stash), a Wayland clipboard "manager" with fast persistent history and multi-media support. Available as [services.stash-clipboard](#opt-services.stash-clipboard.enable).
|
||||
|
||||
- [OO7](https://github.com/linux-credentials/oo7) is a desktop-agnostic Secret Service provider. Available as [services.oo7](#opt-services.oo7.enable)
|
||||
|
||||
- [rosec](https://github.com/jmylchreest/rosec), a secrets daemon implementing the freedesktop.org Secret Service API with modular backend providers. It can automatically unlock the user's vault on login via PAM. Available as [services.rosec](#opt-services.rosec.enable).
|
||||
|
||||
- [NordVPN](https://github.com/NordSecurity/nordvpn-linux), a NordVPN client for linux. Available as [services.nordvpn](options.html#opt-services.nordvpn.enable).
|
||||
|
||||
- [RNSD](https://reticulum.network/), the Reticulum Network Stack Daemon. It provides a secure and efficient way to communicate over the Reticulum Network. Available as [services.rnsd](#opt-services.rnsd.enable).
|
||||
@@ -108,12 +100,6 @@
|
||||
|
||||
- [kvrocks_exporter](https://github.com/RocksLabs/kvrocks_exporter), a Prometheus exporter for Kvrocks metrics. Available as [services.prometheus.exporters.kvrocks](#opt-services.prometheus.exporters.kvrocks.enable).
|
||||
|
||||
- [Umbriel](https://docs.noctalia.dev/umbriel/), a Wayland compositor built on wlroots and SceneFX. Available as [programs.umbriel](#opt-programs.umbriel.enable).
|
||||
|
||||
- [Rundeck](https://www.rundeck.com), Self-Service Operations [services.rundeck](#opt-services.rundeck.enable).
|
||||
|
||||
- [yet-another-cloudwatch-exporter](https://github.com/prometheus-community/yet-another-cloudwatch-exporter), a Prometheus exporter for AWS CloudWatch metrics. Available as [services.prometheus.exporters.yace](#opt-services.prometheus.exporters.yace.enable).
|
||||
|
||||
## Backward Incompatibilities {#sec-release-26.11-incompatibilities}
|
||||
|
||||
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
|
||||
@@ -192,33 +178,18 @@
|
||||
|
||||
- `services.firezone.server.provision` has been removed due to it being unmaintanable. Remove all uses of provisioning and use the WebUI to configure firezone.
|
||||
|
||||
- `security.unprivilegedUsernsClone` has been removed. The option controls a sysctl only provided by the removed -hardened kernels. The removal should only affect users running custom hardened kernels.
|
||||
Disabling user-namespace is possible by setting `boot.kernel.sysctl."user.max_user_namespaces"` to zero, but not generally advised, as browsers, like firefox and chrome, and many other user tools use namespaces for sandboxing.
|
||||
|
||||
- The `services.syncthing` module now updates the Syncthing REST API using partial updates (`PATCH`) instead of full replacements (`PUT`) for general settings. Updating these settings was broken and prone to errors after updates, see [#428808](https://github.com/NixOS/nixpkgs/issues/428808) and [#528889](https://github.com/NixOS/nixpkgs/issues/528889). As a result, settings modified manually through the Syncthing Web UI that are not explicitly defined in your Nix configuration will now persist across rebuilds.
|
||||
|
||||
- `services.plantuml-server.packages.jetty` now supports `jetty_12`, it no longer supports `jetty_11`.
|
||||
|
||||
- `services.komodo-periphery` has been updated to support version 2.0.0. Some options have been renamed to match the new configuration structure; compatibility aliases are provided for the renamed options. The `passkeys` and `outbound.onboardingKey` options have been removed; use `passkeyFiles`, `auth.privateKey`/`auth.corePublicKeys`, or `outbound.onboardingKeyFile` instead. New outbound mode configuration is available under `outbound.*`.
|
||||
|
||||
- `services.pfix-srsd` and the supporting `pfixtools` package have been removed, as the project is dormant and does not support pcre2. `services.postsrsd` is the recommended replacement for Sender Rewriting Scheme support with Postfix.
|
||||
|
||||
- `services.quake3-server.port` has been removed in favor of the structured [](#opt-services.quake3-server.settings.net_port) option. Use `services.quake3-server.settings.net_port` to set any custom UDP port directly.
|
||||
|
||||
- Package `overseerr` has been removed as the `overseerr` and `jellyseerr` projects were merged under `seerr`.
|
||||
|
||||
- The papra NixOS module is now hardening the systemd unit by default. If this breaks any of the configured directories, please reconfigure them through `services.papra.environment` to enable sandbox passthrough.
|
||||
|
||||
- `slskd` has been updated to v0.25.0, which renames the `global` option to `transfers`. Please review the [changelog](https://github.com/slskd/slskd/releases#release-0.25.0).
|
||||
|
||||
- [firefox-syncserver.database.type](#opt-services.firefox-syncserver.database.type) no longer defaults to `"mysql"`. You must now explicitly choose between `"mysql"` and `"postgresql"`. New deployments should prefer PostgreSQL.
|
||||
|
||||
- `chatgpt` has been retargeted to OpenAI's new ChatGPT desktop app, while the previous app has been renamed to `chatgpt-classic`.
|
||||
|
||||
- NetBox was updated to `>= 4.6.8`. Have a look at the breaking changes
|
||||
of the [4.6 release](https://github.com/netbox-community/netbox/releases/tag/v4.6.0),
|
||||
make the required changes to your database, if needed, then upgrade by setting `services.netbox.package = pkgs.netbox_4_6;` in your configuration.
|
||||
|
||||
## Other Notable Changes {#sec-release-26.11-notable-changes}
|
||||
|
||||
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
|
||||
@@ -262,8 +233,6 @@
|
||||
|
||||
- `services.nginx` gained a [`lua`](#opt-services.nginx.lua.enable) option to enable Lua scripting via OpenResty's lua-nginx-module on a stock nginx, configuring `lua_package_path`/`lua_package_cpath` from the packages listed in [`services.nginx.lua.extraPackages`](#opt-services.nginx.lua.extraPackages). Use this to add Lua to a regular nginx; for the full OpenResty platform (libraries that rely on its bundled lualib, such as `lua-resty-openidc`), set `services.nginx.package` to `pkgs.openresty` instead — the option configures the Lua search path for it too.
|
||||
|
||||
- `services.nginx.virtualHosts.<name>.locations.<name>` gained a new `useGrpcErrorPages` option. If enabled, it sets up error pages that are valid gRPC messages. This is useful if you proxy gRPC and want to emit errors from nginx, for example when adding authentication on top.
|
||||
|
||||
- `security.polkit.settings` added for RFC42 style configuration of the polkitd daemon.
|
||||
|
||||
- `boot.supportedFilesystems.ntfs` installs `ntfsprogs-plus` instead of `ntfs3g` on kernel version 7.1 and later, unless `boot.supportedFilesystems.ntfs-3g` is explicitly enabled.
|
||||
@@ -278,9 +247,7 @@
|
||||
|
||||
- `services.gitlab.registry` now uses PostgreSQL as database storage for new installations and supports old installations that use the filesystem as metadata storage. It creates the required PostgreSQL database and user. Users can manually migrate their filesystem based metadata storage. See [GitLab Container Registry Migration to database metadata store](#module-services-gitlab-registry-database-migration).
|
||||
|
||||
- `services.fail2ban` now supports systemd socket activation via `fail2ban.socket`
|
||||
|
||||
- Enabling [`services.userborn`](#opt-services.userborn.enable) on a system that was previously managed by the default `update-users-groups.pl` script now imports the legacy state from `/var/lib/nixos/` on the first switch. Locked stub entries are added to `/etc/passwd` and `/etc/group` for every name recorded in `uid-map`/`gid-map` that no longer has a live entry, so a previously-used UID/GID cannot be reassigned to a different user. Subordinate id ranges recorded in `auto-subuid-map` are seeded into the subid files as well. If the import fails, userborn does not start and the user database is left untouched. Inspect `journalctl -u userborn-import-legacy.service`, fix or remove the legacy state, and switch again. The import can be skipped entirely with [`services.userborn.importLegacyState`](#opt-services.userborn.importLegacyState)` = false`.
|
||||
- Enabling [`services.userborn`](#opt-services.userborn.enable) on a system that was previously managed by the default `update-users-groups.pl` script now imports the legacy state from `/var/lib/nixos/` on the first switch. Locked stub entries are added to `/etc/passwd` and `/etc/group` for every name recorded in `uid-map`/`gid-map` that no longer has a live entry, so a previously-used UID/GID cannot be reassigned to a different user. If the import fails, userborn does not start and the user database is left untouched. Inspect `journalctl -u userborn-import-legacy.service`, fix or remove the legacy state, and switch again. The import can be skipped entirely with [`services.userborn.importLegacyState`](#opt-services.userborn.importLegacyState)` = false`.
|
||||
|
||||
- The `newuidmap` and `newgidmap` security wrappers are now installed with `cap_setuid`/`cap_setgid` file capabilities instead of the setuid-root bit, matching shadow's `--with-fcaps` install mode and other major distributions. Rootless containers (podman, docker-rootless, unprivileged user namespaces) are unaffected. The only behavioural change is that mapping host uid 0 via `/etc/subuid` (which NixOS never configures by default) additionally requires `cap_setfcap`; users who explicitly grant uid 0 in a subuid range can restore the previous behaviour with `security.wrappers.newuidmap.capabilities = lib.mkForce "cap_setuid,cap_setfcap+ep";`.
|
||||
|
||||
|
||||
@@ -1809,16 +1809,15 @@ class NspawnMachine(BaseMachine):
|
||||
|
||||
# 1. Wait for the directory to actually be created by the container
|
||||
self.log(f"Waiting for journal at {journal_path}...")
|
||||
warn_after = 10
|
||||
max_attempts = 10
|
||||
attempts = 0
|
||||
while not journal_path.exists():
|
||||
if proc.poll() is not None:
|
||||
self.log(f"Error: Journal directory {journal_path} never appeared.")
|
||||
return
|
||||
while not journal_path.exists() and attempts < max_attempts:
|
||||
time.sleep(1)
|
||||
attempts += 1
|
||||
if attempts == warn_after:
|
||||
self.log(f"Still waiting for journal at {journal_path}...")
|
||||
|
||||
if not journal_path.exists():
|
||||
self.log(f"Error: Journal directory {journal_path} never appeared.")
|
||||
return
|
||||
|
||||
# 2. Start the journalctl process
|
||||
# Using a loop here handles cases where journalctl might exit unexpectedly
|
||||
|
||||
@@ -1,9 +1,4 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
options,
|
||||
...
|
||||
}:
|
||||
{ lib, options, ... }:
|
||||
let
|
||||
inherit (lib) types mkOption literalMD;
|
||||
|
||||
@@ -31,7 +26,7 @@ in
|
||||
'';
|
||||
apply = lib.filterAttrs (k: v: v != null);
|
||||
type = types.submodule (
|
||||
{ options, ... }:
|
||||
{ options, config, ... }:
|
||||
{
|
||||
options = {
|
||||
maintainers = mkOption {
|
||||
@@ -76,10 +71,7 @@ in
|
||||
};
|
||||
platforms = mkOption {
|
||||
type = types.listOf types.raw;
|
||||
default = lib.platforms.linux ++ lib.optionals (config.containers == { }) lib.platforms.darwin;
|
||||
defaultText = literalMD ''
|
||||
`lib.platforms.linux ++ lib.platforms.darwin` when no containers are configured; otherwise `lib.platforms.linux`.
|
||||
'';
|
||||
default = lib.platforms.linux ++ lib.platforms.darwin;
|
||||
description = ''
|
||||
Sets the [`meta.platforms`](https://nixos.org/manual/nixpkgs/stable/#var-meta-platforms) attribute on the [{option}`test`](#test-opt-test) derivation.
|
||||
'';
|
||||
|
||||
@@ -35,7 +35,8 @@ let
|
||||
options = {
|
||||
devnet = mkOption {
|
||||
type = types.bool;
|
||||
default = containers != { } && nodes != { };
|
||||
default =
|
||||
builtins.length (lib.attrNames containers) > 0 && builtins.length (lib.attrNames nodes) > 0;
|
||||
defaultText = lib.literalMD "`true` if both VMs and containers are present.";
|
||||
description = ''
|
||||
This heuristic setting that assumes that the majority of tests requires VMs and containers
|
||||
@@ -51,14 +52,14 @@ let
|
||||
};
|
||||
uid-range = mkOption {
|
||||
type = types.bool;
|
||||
default = containers != { };
|
||||
default = builtins.length (lib.attrNames containers) > 0;
|
||||
defaultText = lib.literalMD "`true` if containers are present.";
|
||||
description = "Containers use systemd-nspawn, which requires pid 0 inside of the sandbox. `uid-range` enables that.";
|
||||
};
|
||||
kvm = mkOption {
|
||||
type = types.bool;
|
||||
default = isLinux && nodes != { };
|
||||
defaultText = lib.literalMD "`true` if built to run on Linux and any virtual machines are specified.";
|
||||
default = isLinux;
|
||||
defaultText = lib.literalMD "`true` if built to run on Linux.";
|
||||
description = "Whether Linux KVM virtualization is required when running this test. Can be disabled to allow emulated execution.";
|
||||
};
|
||||
apple-virt = mkOption {
|
||||
|
||||
@@ -7,15 +7,20 @@ testModuleArgs@{
|
||||
...
|
||||
}:
|
||||
let
|
||||
inherit (lib) mkOption types const;
|
||||
inherit (types) coercedTo lines functionTo;
|
||||
inherit (lib) mkOption types;
|
||||
inherit (types) either lines functionTo;
|
||||
in
|
||||
{
|
||||
options = {
|
||||
testScript = mkOption {
|
||||
type = coercedTo lines const (functionTo lines);
|
||||
# Only pass args the testScript function expects.
|
||||
apply = v: args: v (builtins.intersectAttrs (lib.functionArgs v) args);
|
||||
type = either lines (functionTo lines);
|
||||
apply =
|
||||
v:
|
||||
if lib.isFunction v then
|
||||
# Only pass args the testScript function expects.
|
||||
args: v (builtins.intersectAttrs (lib.functionArgs v) args)
|
||||
else
|
||||
v;
|
||||
description = ''
|
||||
A series of python declarations and statements that you write to perform
|
||||
the test.
|
||||
@@ -45,19 +50,23 @@ in
|
||||
withoutTestScriptReferences.includeTestScriptReferences = false;
|
||||
withoutTestScriptReferences.testScript = lib.mkForce "testscript omitted";
|
||||
|
||||
testScriptString = config.testScript {
|
||||
nodes = lib.mapAttrs (
|
||||
k: v:
|
||||
if v.virtualisation.useNixStoreImage then
|
||||
# prevent infinite recursion when testScript would
|
||||
# reference v's toplevel
|
||||
config.withoutTestScriptReferences.nodesCompat.${k}
|
||||
else
|
||||
# reuse memoized config
|
||||
v
|
||||
) config.nodesCompat;
|
||||
containers = config.containers;
|
||||
};
|
||||
testScriptString =
|
||||
if lib.isFunction config.testScript then
|
||||
config.testScript {
|
||||
nodes = lib.mapAttrs (
|
||||
k: v:
|
||||
if v.virtualisation.useNixStoreImage then
|
||||
# prevent infinite recursion when testScript would
|
||||
# reference v's toplevel
|
||||
config.withoutTestScriptReferences.nodesCompat.${k}
|
||||
else
|
||||
# reuse memoized config
|
||||
v
|
||||
) config.nodesCompat;
|
||||
containers = config.containers;
|
||||
}
|
||||
else
|
||||
config.testScript;
|
||||
|
||||
nodeDefaults =
|
||||
{ config, name, ... }:
|
||||
|
||||
@@ -842,7 +842,7 @@ in
|
||||
users.users = {
|
||||
root = {
|
||||
uid = ids.uids.root;
|
||||
description = mkDefault "System administrator";
|
||||
description = "System administrator";
|
||||
home = "/root";
|
||||
shell = mkDefault cfg.defaultUserShell;
|
||||
group = "root";
|
||||
@@ -850,7 +850,7 @@ in
|
||||
nobody = {
|
||||
uid = ids.uids.nobody;
|
||||
isSystemUser = true;
|
||||
description = mkDefault "Unprivileged account (don't use!)";
|
||||
description = "Unprivileged account (don't use!)";
|
||||
group = "nogroup";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -9,16 +9,6 @@ let
|
||||
cfg = imcfg.fcitx5;
|
||||
fcitx5Package = pkgs.qt6Packages.fcitx5-with-addons.override { inherit (cfg) addons; };
|
||||
settingsFormat = pkgs.formats.ini { };
|
||||
mkKeyValue = lib.generators.mkKeyValueDefault {
|
||||
mkValueString =
|
||||
v:
|
||||
if true == v then
|
||||
"True"
|
||||
else if false == v then
|
||||
"False"
|
||||
else
|
||||
lib.generators.mkValueStringDefault { } v;
|
||||
} "=";
|
||||
in
|
||||
{
|
||||
options = {
|
||||
@@ -141,13 +131,10 @@ in
|
||||
};
|
||||
in
|
||||
lib.attrsets.mergeAttrsList [
|
||||
(optionalFile "config" (lib.generators.toINI { inherit mkKeyValue; }) cfg.settings.globalOptions)
|
||||
(optionalFile "profile" (lib.generators.toINI { inherit mkKeyValue; }) cfg.settings.inputMethod)
|
||||
(optionalFile "config" (lib.generators.toINI { }) cfg.settings.globalOptions)
|
||||
(optionalFile "profile" (lib.generators.toINI { }) cfg.settings.inputMethod)
|
||||
(lib.concatMapAttrs (
|
||||
name: value:
|
||||
optionalFile "conf/${name}.conf" (lib.generators.toINIWithGlobalSection {
|
||||
inherit mkKeyValue;
|
||||
}) value
|
||||
name: value: optionalFile "conf/${name}.conf" (lib.generators.toINIWithGlobalSection { }) value
|
||||
) cfg.settings.addons)
|
||||
];
|
||||
|
||||
|
||||
@@ -58,7 +58,7 @@ let
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
"/EFI/BOOT/BOOTX64.EFI".source =
|
||||
"''${config.systemd.package}/lib/systemd/boot/efi/systemd-bootx64.efi";
|
||||
"''${pkgs.systemd}/lib/systemd/boot/efi/systemd-bootx64.efi";
|
||||
|
||||
"/loader/entries/nixos.conf".source = systemdBootEntry;
|
||||
}
|
||||
@@ -227,7 +227,7 @@ in
|
||||
"10-esp" = {
|
||||
contents = {
|
||||
"/EFI/BOOT/BOOTX64.EFI".source =
|
||||
"''${config.systemd.package}/lib/systemd/boot/efi/systemd-bootx64.efi";
|
||||
"''${pkgs.systemd}/lib/systemd/boot/efi/systemd-bootx64.efi";
|
||||
};
|
||||
repartConfig = {
|
||||
Type = "esp";
|
||||
|
||||
@@ -352,7 +352,6 @@
|
||||
./programs/udevil.nix
|
||||
./programs/upki.nix
|
||||
./programs/usbtop.nix
|
||||
./programs/vellum.nix
|
||||
./programs/vim.nix
|
||||
./programs/virt-manager.nix
|
||||
./programs/vivid.nix
|
||||
@@ -372,7 +371,6 @@
|
||||
./programs/wayland/pinnacle.nix
|
||||
./programs/wayland/river.nix
|
||||
./programs/wayland/sway.nix
|
||||
./programs/wayland/umbriel.nix
|
||||
./programs/wayland/uwsm.nix
|
||||
./programs/wayland/waybar.nix
|
||||
./programs/wayland/wayfire.nix
|
||||
@@ -784,7 +782,6 @@
|
||||
./services/logging/syslog-ng.nix
|
||||
./services/logging/syslogd.nix
|
||||
./services/logging/SystemdJournal2Gelf.nix
|
||||
./services/logging/udp514-journal.nix
|
||||
./services/logging/ulogd.nix
|
||||
./services/logging/vector.nix
|
||||
./services/mail/automx2.nix
|
||||
@@ -807,6 +804,7 @@
|
||||
./services/mail/offlineimap.nix
|
||||
./services/mail/opendkim.nix
|
||||
./services/mail/opensmtpd.nix
|
||||
./services/mail/pfix-srsd.nix
|
||||
./services/mail/postfix-tlspol.nix
|
||||
./services/mail/postfix.nix
|
||||
./services/mail/postgrey.nix
|
||||
@@ -1084,7 +1082,6 @@
|
||||
./services/monitoring/nezha.nix
|
||||
./services/monitoring/ocsinventory-agent.nix
|
||||
./services/monitoring/opentelemetry-collector.nix
|
||||
./services/monitoring/orbit.nix
|
||||
./services/monitoring/osquery.nix
|
||||
./services/monitoring/parsedmarc.nix
|
||||
./services/monitoring/perses.nix
|
||||
@@ -1322,7 +1319,6 @@
|
||||
./services/networking/mmsd.nix
|
||||
./services/networking/modemmanager.nix
|
||||
./services/networking/monero.nix
|
||||
./services/networking/moonshine.nix
|
||||
./services/networking/mosquitto.nix
|
||||
./services/networking/mozillavpn.nix
|
||||
./services/networking/mptcpd.nix
|
||||
@@ -1578,7 +1574,6 @@
|
||||
./services/security/physlock.nix
|
||||
./services/security/pocket-id.nix
|
||||
./services/security/reaction.nix
|
||||
./services/security/rosec.nix
|
||||
./services/security/shibboleth-sp.nix
|
||||
./services/security/sks.nix
|
||||
./services/security/spire/agent.nix
|
||||
@@ -1825,7 +1820,6 @@
|
||||
./services/web-apps/romm.nix
|
||||
./services/web-apps/rss-bridge.nix
|
||||
./services/web-apps/rsshub.nix
|
||||
./services/web-apps/rundeck.nix
|
||||
./services/web-apps/rustical.nix
|
||||
./services/web-apps/rutorrent.nix
|
||||
./services/web-apps/screego.nix
|
||||
|
||||
@@ -60,7 +60,7 @@ in
|
||||
description = ''
|
||||
Configuration written to {file}`/etc/atuin/config.toml`.
|
||||
|
||||
See <https://docs.atuin.sh/latest/configuration/config/> for the full list
|
||||
See <https://docs.atuin.sh/configuration/config/> for the full list
|
||||
of options.
|
||||
'';
|
||||
};
|
||||
@@ -99,7 +99,7 @@ in
|
||||
{file}`/etc/atuin/themes/theme-name.toml`
|
||||
where the name of each attribute is the theme-name
|
||||
|
||||
See <https://docs.atuin.sh/latest/guide/theming/> for the full list
|
||||
See <https://docs.atuin.sh/guide/theming/> for the full list
|
||||
of options.
|
||||
'';
|
||||
default = { };
|
||||
|
||||
@@ -86,6 +86,9 @@ in
|
||||
programs = {
|
||||
cpu-energy-meter.enable = lib.mkDefault true;
|
||||
};
|
||||
|
||||
# See <https://github.com/sosy-lab/benchexec/blob/3.18/doc/INSTALL.md#kernel-requirements>.
|
||||
security.unprivilegedUsernsClone = true;
|
||||
};
|
||||
|
||||
meta.maintainers = with lib.maintainers; [ lorenzleutgeb ];
|
||||
|
||||
@@ -1,81 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.programs.vellum;
|
||||
|
||||
inherit (lib)
|
||||
getExe
|
||||
literalExpression
|
||||
mkEnableOption
|
||||
mkIf
|
||||
mkOption
|
||||
mkPackageOption
|
||||
;
|
||||
inherit (lib.types) separatedString;
|
||||
|
||||
toml = pkgs.formats.toml { };
|
||||
in
|
||||
{
|
||||
options.programs.vellum = {
|
||||
enable = mkEnableOption "vellum, a live screen annotation overlay for Wayland";
|
||||
|
||||
package = mkPackageOption pkgs "vellum" { };
|
||||
|
||||
settings = mkOption {
|
||||
inherit (toml) type;
|
||||
default = { };
|
||||
description = ''
|
||||
Configuration options for vellum.
|
||||
See available options at <https://github.com/greyxp1/vellum/blob/master/docs/configuration.md>.
|
||||
'';
|
||||
example = literalExpression ''
|
||||
{
|
||||
default_tool = "arrow";
|
||||
remember_last_tool = false;
|
||||
feedback_duration_ms = 250;
|
||||
}
|
||||
'';
|
||||
};
|
||||
|
||||
extraOptions = mkOption {
|
||||
type = separatedString " ";
|
||||
default = "";
|
||||
description = ''
|
||||
Extra command-line options to pass to
|
||||
the {command}`vellum` daemon.
|
||||
'';
|
||||
example = "--force-backend vulkan";
|
||||
};
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
environment = {
|
||||
systemPackages = [ cfg.package ];
|
||||
|
||||
etc."xdg/vellum/config.toml" = mkIf (cfg.settings != { }) {
|
||||
source = toml.generate "vellum-config.toml" cfg.settings;
|
||||
};
|
||||
};
|
||||
|
||||
systemd.user.services.vellum = {
|
||||
description = "Vellum screen annotation overlay";
|
||||
after = [ "graphical-session.target" ];
|
||||
partOf = [ "graphical-session.target" ];
|
||||
wantedBy = [ "graphical-session.target" ];
|
||||
restartTriggers = [ config.environment.etc."xdg/vellum/config.toml".source ];
|
||||
serviceConfig = {
|
||||
ExecStart = "${getExe cfg.package} ${cfg.extraOptions}";
|
||||
Restart = "on-failure";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
meta = {
|
||||
maintainers = with lib.maintainers; [ poz ];
|
||||
};
|
||||
}
|
||||
@@ -1,48 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
let
|
||||
cfg = config.programs.umbriel;
|
||||
in
|
||||
{
|
||||
options.programs.umbriel = {
|
||||
enable = lib.mkEnableOption "Umbriel, a Wayland compositor built on wlroots and SceneFX";
|
||||
package = lib.mkPackageOption pkgs "umbriel" { };
|
||||
portalPackage = lib.mkPackageOption pkgs "xdg-desktop-portal-umbriel" { };
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable (
|
||||
lib.mkMerge [
|
||||
{
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
services.displayManager.sessionPackages = [ cfg.package ];
|
||||
systemd.packages = [ cfg.package ];
|
||||
|
||||
systemd.user.services.umbriel = {
|
||||
restartIfChanged = false;
|
||||
enableDefaultPath = false;
|
||||
};
|
||||
|
||||
xdg.portal = {
|
||||
enable = lib.mkDefault true;
|
||||
extraPortals = [ cfg.portalPackage ];
|
||||
configPackages = [ cfg.portalPackage ];
|
||||
};
|
||||
}
|
||||
|
||||
(import ./wayland-session.nix {
|
||||
inherit lib pkgs;
|
||||
enableXWayland = false;
|
||||
enableWlrPortal = false;
|
||||
})
|
||||
]
|
||||
);
|
||||
|
||||
meta.maintainers = with lib.maintainers; [
|
||||
samiser
|
||||
pyrox0
|
||||
];
|
||||
}
|
||||
@@ -320,9 +320,6 @@ in
|
||||
The Javascript version of Parsoid configured through this module does not work with modern MediaWiki versions,
|
||||
and has been deprecated by upstream, so it has been removed. MediaWiki comes with a new PHP-based parser built-in, so there is no need for this module.
|
||||
'')
|
||||
(mkRemovedOptionModule [ "services" "pfix-srsd" ] ''
|
||||
The pfixtools project is dormant and does not support pcre2. `services.postsrsd` is the recommended replacement for Sender Rewriting Scheme support with Postfix.
|
||||
'')
|
||||
(mkRemovedOptionModule [ "services" "pingvin-share" ] ''
|
||||
The `pingvin-share.backend` package was broken and the project was archived upstream, so it was removed from nixpkgs.
|
||||
'')
|
||||
|
||||
@@ -772,7 +772,7 @@ let
|
||||
description = ''
|
||||
Key type to use for private keys.
|
||||
For an up to date list of supported values check the --key-type option
|
||||
at <https://go-acme.github.io/lego/references/ref-flags/index.html#options>.
|
||||
at <https://go-acme.github.io/lego/usage/cli/options/>.
|
||||
'';
|
||||
};
|
||||
|
||||
@@ -833,7 +833,7 @@ let
|
||||
'';
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
"DNSUPDATE_TSIG_SECRET_FILE" = "/run/secrets/tsig-secret-example.org";
|
||||
"RFC2136_TSIG_SECRET_FILE" = "/run/secrets/tsig-secret-example.org";
|
||||
}
|
||||
'';
|
||||
};
|
||||
@@ -852,9 +852,8 @@ let
|
||||
inherit (defaultAndText "ocspMustStaple" false) default defaultText;
|
||||
description = ''
|
||||
Turns on the OCSP Must-Staple TLS extension.
|
||||
Make sure you know what you're doing!
|
||||
OCSP Must-Staple can be considered a legacy feature, that is no longer superted by Let's Encrypt. See:
|
||||
- <https://letsencrypt.org/2024/12/05/ending-ocsp>
|
||||
Make sure you know what you're doing! See:
|
||||
|
||||
- <https://blog.apnic.net/2019/01/15/is-the-web-ready-for-ocsp-must-staple/>
|
||||
- <https://blog.hboeck.de/archives/886-The-Problem-with-OCSP-Stapling-and-Must-Staple-and-why-Certificate-Revocation-is-still-broken.html>
|
||||
'';
|
||||
|
||||
@@ -9,16 +9,6 @@
|
||||
[ "security" "virtualization" "flushL1DataCache" ]
|
||||
[ "security" "virtualisation" "flushL1DataCache" ]
|
||||
)
|
||||
(lib.mkRemovedOptionModule
|
||||
[
|
||||
"security"
|
||||
"unprivilegedUsernsClone"
|
||||
]
|
||||
''
|
||||
to disable or enable unprivileged user namespaces please use
|
||||
the sysctl "user.max_user_namespaces".
|
||||
''
|
||||
)
|
||||
];
|
||||
|
||||
options = {
|
||||
@@ -41,6 +31,16 @@
|
||||
'';
|
||||
};
|
||||
|
||||
security.unprivilegedUsernsClone = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
When disabled, unprivileged users will not be able to create new namespaces.
|
||||
By default unprivileged user namespaces are disabled.
|
||||
This option only works in a hardened profile.
|
||||
'';
|
||||
};
|
||||
|
||||
security.protectKernelImage = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
@@ -121,6 +121,10 @@
|
||||
];
|
||||
})
|
||||
|
||||
(lib.mkIf config.security.unprivilegedUsernsClone {
|
||||
boot.kernel.sysctl."kernel.unprivileged_userns_clone" = lib.mkDefault true;
|
||||
})
|
||||
|
||||
(lib.mkIf config.security.protectKernelImage {
|
||||
# Disable hibernation (allows replacing the running kernel)
|
||||
boot.kernelParams = [ "nohibernate" ];
|
||||
|
||||
@@ -686,18 +686,6 @@ let
|
||||
'';
|
||||
};
|
||||
|
||||
rosec = {
|
||||
enable = lib.mkOption {
|
||||
default = false;
|
||||
type = lib.types.bool;
|
||||
description = ''
|
||||
If enabled, pam_rosec will attempt to automatically unlock the
|
||||
user's rosec vault upon login. If the user login password does not
|
||||
match their vault password, rosec will prompt separately after login.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
enableUMask = lib.mkOption {
|
||||
default = config.security.pam.enableUMask;
|
||||
defaultText = lib.literalExpression "config.security.pam.enableUMask";
|
||||
@@ -1221,7 +1209,6 @@ let
|
||||
|| cfg.kwallet.enable
|
||||
|| cfg.enableGnomeKeyring
|
||||
|| cfg.oo7.enable
|
||||
|| cfg.rosec.enable
|
||||
|| config.services.intune.enable
|
||||
|| cfg.googleAuthenticator.enable
|
||||
|| cfg.gnupg.enable
|
||||
@@ -1291,12 +1278,6 @@ let
|
||||
control = "optional";
|
||||
modulePath = "${pkgs.oo7-pam}/lib/security/pam_oo7.so";
|
||||
}
|
||||
{
|
||||
name = "rosec";
|
||||
enable = cfg.rosec.enable;
|
||||
control = "optional";
|
||||
modulePath = "${pkgs.rosec}/lib/security/pam_rosec.so";
|
||||
}
|
||||
{
|
||||
name = "intune";
|
||||
enable = config.services.intune.enable;
|
||||
@@ -1518,12 +1499,6 @@ let
|
||||
control = "optional";
|
||||
modulePath = "${pkgs.oo7-pam}/lib/security/pam_oo7.so";
|
||||
}
|
||||
{
|
||||
name = "rosec";
|
||||
enable = cfg.rosec.enable;
|
||||
control = "optional";
|
||||
modulePath = "${pkgs.rosec}/lib/security/pam_rosec.so";
|
||||
}
|
||||
];
|
||||
|
||||
session = utils.pam.autoOrderRules [
|
||||
@@ -1751,12 +1726,6 @@ let
|
||||
auto_start = true;
|
||||
};
|
||||
}
|
||||
{
|
||||
name = "rosec";
|
||||
enable = cfg.rosec.enable;
|
||||
control = "optional";
|
||||
modulePath = "${pkgs.rosec}/lib/security/pam_rosec.so";
|
||||
}
|
||||
{
|
||||
name = "gnupg";
|
||||
enable = cfg.gnupg.enable;
|
||||
|
||||
@@ -59,9 +59,6 @@ So the raw tpm character device, the kernel RM, and `tabrmd` are all "TCTIs".
|
||||
The ESAPI library speaks the client side of the TCTI protocol, and can be connected to any server TCTI.
|
||||
All of the other libraries or programs that work with TPM all use ESAPI under the hood, and so a common characteristic among all these libraries is that you will find you need to configure them in some way as to which TCTI they should be talking to.
|
||||
|
||||
A TPM-enabled system should choose to enable either the Linux kernel resource manager or the `tabrmd` resource manager. The tpm2-software group does not have absolute guidance on this, but the userspace resource manager supports an anti-contention feature known as session un-gapping but has not seen recent development.
|
||||
The kernel resource manager has seen more active development and is the resource manager of choice in immutable distributions such as Fedora Silverblue.
|
||||
|
||||
#### Higher Level Interfaces {#module-security-tpm2-introduction-hli}
|
||||
|
||||
As alluded to previously, there are a number of ways of speaking the client side TCTI that all amount to wrappers around ESAPI. They include:
|
||||
@@ -76,16 +73,6 @@ As alluded to previously, there are a number of ways of speaking the client side
|
||||
|
||||
A typical configuration is:
|
||||
```
|
||||
security.tpm2 = {
|
||||
enable = true;
|
||||
pkcs11.enable = true;
|
||||
|
||||
tctiEnvironment.enable = true;
|
||||
}
|
||||
```
|
||||
|
||||
Or to use the `tpm2-abrmd` resource manager:
|
||||
```
|
||||
security.tpm2 = {
|
||||
enable = true;
|
||||
abrmd.enable = true;
|
||||
@@ -98,6 +85,7 @@ security.tpm2 = {
|
||||
`enable = true;` is required for any tpm functionality other than the raw character device and kernel resource manager to be available.
|
||||
|
||||
`abrmd.enable = true;` causes the tpm2-abrmd program (the user-space resource manager) to run as a systemd service.
|
||||
Generally you want this because the user-space resource manager gets more frequent updates than the kernel-space RM, and there aren't any kernel RM features that are unavailable in the user-space RM.
|
||||
|
||||
`pkcs11.enable = true;` makes the PKCS11 tool and libraries available in the system path.
|
||||
Generally you want this because it's unlikely to cause problems and it's required by one of the more common TPM use cases, which is protecting an ssh key using the TPM.
|
||||
|
||||
@@ -154,7 +154,7 @@ let
|
||||
script =
|
||||
"exec "
|
||||
+ lib.optionalString cfg.inhibitsSleep ''
|
||||
${config.systemd.package}/bin/systemd-inhibit \
|
||||
${pkgs.systemd}/bin/systemd-inhibit \
|
||||
--who="borgbackup" \
|
||||
--what="sleep" \
|
||||
--why="Scheduled backup" \
|
||||
|
||||
@@ -392,7 +392,7 @@ in
|
||||
let
|
||||
extraOptions = lib.concatMapStrings (arg: " -o ${arg}") backup.extraOptions;
|
||||
inhibitCmd = lib.concatStringsSep " " [
|
||||
"${config.systemd.package}/bin/systemd-inhibit"
|
||||
"${pkgs.systemd}/bin/systemd-inhibit"
|
||||
"--mode='block'"
|
||||
"--who='restic'"
|
||||
"--what='sleep'"
|
||||
|
||||
@@ -27,7 +27,7 @@ in
|
||||
|
||||
options = {
|
||||
services.chromadb = {
|
||||
enable = mkEnableOption "ChromaDB, an open-source AI application database";
|
||||
enable = mkEnableOption "ChromaDB, an open-source AI application database.";
|
||||
|
||||
package = mkPackageOption pkgs [ "python3Packages" "chromadb" ] { };
|
||||
|
||||
|
||||
@@ -213,7 +213,7 @@ in
|
||||
initialScript = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
description = "A file containing SQL statements to be executed on the first startup. Can be used for granting certain permissions on the database. Run as superuser.";
|
||||
description = "A file containing SQL statements to be executed on the first startup. Can be used for granting certain permissions on the database.";
|
||||
};
|
||||
|
||||
ensureDatabases = lib.mkOption {
|
||||
|
||||
@@ -291,7 +291,7 @@ in
|
||||
};
|
||||
initial_session = mkIf (cfgAutoLogin.enable && (cfgAutoLogin.user != null)) {
|
||||
inherit (cfgAutoLogin) user;
|
||||
command = ''${getExe pkgs.bash} -lc "${config.systemd.package}/bin/systemd-cat $(<${autoLoginCommand})"'';
|
||||
command = ''${getExe pkgs.bash} -lc "${pkgs.systemd}/bin/systemd-cat $(<${autoLoginCommand})"'';
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -15,16 +15,9 @@ let
|
||||
;
|
||||
cfg = config.services.quake3-server;
|
||||
|
||||
toQuake3Value = value: if lib.isBool value then (if value then "1" else "0") else toString value;
|
||||
|
||||
toQuake3Config =
|
||||
settings:
|
||||
lib.concatStrings (
|
||||
lib.mapAttrsToList (name: value: ''seta ${name} "${toQuake3Value value}"'' + "\n") settings
|
||||
);
|
||||
|
||||
configFile = pkgs.writeText "q3ds-extra.cfg" ''
|
||||
${toQuake3Config cfg.settings}
|
||||
set net_port ${toString cfg.port}
|
||||
|
||||
${cfg.extraConfig}
|
||||
'';
|
||||
|
||||
@@ -57,19 +50,19 @@ let
|
||||
'';
|
||||
in
|
||||
{
|
||||
|
||||
imports = [
|
||||
(lib.mkRenamedOptionModule
|
||||
[ "services" "quake3-server" "port" ]
|
||||
[ "services" "quake3-server" "settings" "net_port" ]
|
||||
)
|
||||
];
|
||||
|
||||
options = {
|
||||
services.quake3-server = {
|
||||
enable = mkEnableOption "Quake 3 dedicated server";
|
||||
package = lib.mkPackageOption pkgs "ioquake3" { };
|
||||
|
||||
port = mkOption {
|
||||
type = types.port;
|
||||
default = 27960;
|
||||
description = ''
|
||||
UDP Port the server should listen on.
|
||||
'';
|
||||
};
|
||||
|
||||
openFirewall = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
@@ -78,59 +71,16 @@ in
|
||||
'';
|
||||
};
|
||||
|
||||
settings = mkOption {
|
||||
type = types.submodule {
|
||||
freeformType = types.attrsOf (
|
||||
types.nullOr (
|
||||
types.oneOf [
|
||||
types.str
|
||||
types.bool
|
||||
types.int
|
||||
types.float
|
||||
types.port
|
||||
]
|
||||
)
|
||||
);
|
||||
options = {
|
||||
net_port = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
default = 27960;
|
||||
description = "UDP port for the dedicated server to bind to.";
|
||||
};
|
||||
};
|
||||
};
|
||||
default = { };
|
||||
example = {
|
||||
sv_hostname = "My Quake 3 server";
|
||||
g_gametype = 0;
|
||||
sv_pure = true;
|
||||
};
|
||||
description = ''
|
||||
Quake 3 cvars set via `seta` on server start (i.e. persisted,
|
||||
archive-flagged cvars – the vast majority of server settings).
|
||||
Note that options changed via RCON will not be persisted. To list
|
||||
all possible options, use "cvarlist 1" via RCON.
|
||||
'';
|
||||
};
|
||||
|
||||
extraConfig = mkOption {
|
||||
type = types.lines;
|
||||
default = "";
|
||||
example = ''
|
||||
// map rotation and other things that don't map onto plain cvars
|
||||
set d1 "map q3dm1 ; set nextmap vstr d2"
|
||||
set d2 "map q3dm7 ; set nextmap vstr d1"
|
||||
vstr d1
|
||||
|
||||
// rarely needed: cvars with a non-seta flag
|
||||
sets sv_privatePassword "hidden"
|
||||
seta rconPassword "superSecret" // sets RCON password for remote console
|
||||
seta sv_hostname "My Quake 3 server" // name that appears in server list
|
||||
'';
|
||||
description = ''
|
||||
Extra configuration lines appended after `settings`, for anything
|
||||
that isn't a plain persisted cvar: map-rotation scripts, `exec`,
|
||||
`vstr`, aliases, or cvars that need `set`/`sets`/`sett`/`setu`
|
||||
instead of `seta`. Note that options changed via RCON will not be
|
||||
persisted. To list all possible options, use "cvarlist 1" via RCON.
|
||||
Extra configuration options. Note that options changed via RCON will not be persisted. To list all possible
|
||||
options, use "cvarlist 1" via RCON.
|
||||
'';
|
||||
};
|
||||
|
||||
@@ -153,7 +103,7 @@ in
|
||||
baseq3InStore = builtins.typeOf cfg.baseq3 == "set";
|
||||
in
|
||||
mkIf cfg.enable {
|
||||
networking.firewall.allowedUDPPorts = mkIf cfg.openFirewall [ cfg.settings.net_port ];
|
||||
networking.firewall.allowedUDPPorts = mkIf cfg.openFirewall [ cfg.port ];
|
||||
|
||||
systemd.services.q3ds = {
|
||||
description = "Quake 3 dedicated server";
|
||||
@@ -165,7 +115,7 @@ in
|
||||
serviceConfig = with lib; {
|
||||
Restart = "always";
|
||||
DynamicUser = true;
|
||||
WorkingDirectory = if baseq3InStore then home else cfg.baseq3;
|
||||
WorkingDirectory = home;
|
||||
|
||||
# It is possible to alter configuration files via RCON. To ensure reproducibility we have to prevent this
|
||||
ReadOnlyPaths = if baseq3InStore then home else cfg.baseq3;
|
||||
|
||||
@@ -332,7 +332,7 @@
|
||||
# devices needed here become available. This is terribly broken and
|
||||
# essentially no better than a random sleep(). See PR #452645 for
|
||||
# an attempt to fix this issue.
|
||||
ExecStartPre = "-${lib.getExe' config.systemd.package "udevadm"} settle --timeout=180";
|
||||
ExecStartPre = "-${lib.getExe' pkgs.systemd "udevadm"} settle --timeout=180";
|
||||
ExecStart =
|
||||
let
|
||||
script = pkgs.callPackage ./cdi-generate.nix {
|
||||
|
||||
@@ -405,17 +405,17 @@ in
|
||||
commands = [
|
||||
{
|
||||
# Ability to restart homebridge service
|
||||
command = "${config.systemd.package}/bin/systemctl restart homebridge";
|
||||
command = "${pkgs.systemd}/bin/systemctl restart homebridge";
|
||||
options = [ "NOPASSWD" ];
|
||||
}
|
||||
{
|
||||
# Ability to shutdown server
|
||||
command = "${config.systemd.package}/bin/shutdown -h now";
|
||||
command = "${pkgs.systemd}/bin/shutdown -h now";
|
||||
options = [ "NOPASSWD" ];
|
||||
}
|
||||
{
|
||||
# Ability to restart server
|
||||
command = "${config.systemd.package}/bin/shutdown -r now";
|
||||
command = "${pkgs.systemd}/bin/shutdown -r now";
|
||||
options = [ "NOPASSWD" ];
|
||||
}
|
||||
];
|
||||
|
||||
@@ -1,95 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.services.udp514-journal;
|
||||
description = "Forward syslog from network (udp/514) to journal";
|
||||
in
|
||||
{
|
||||
options = {
|
||||
services.udp514-journal = {
|
||||
enable = lib.mkEnableOption "the udp514-journal systemd socket/service";
|
||||
|
||||
openFirewall = lib.mkEnableOption "" // {
|
||||
description = "Whether to open the port in the firewall.";
|
||||
};
|
||||
|
||||
port = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
default = 514;
|
||||
description = "Port to listen on";
|
||||
};
|
||||
|
||||
package = lib.mkPackageOption pkgs "udp514-journal" { };
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
systemd.sockets.udp514-journal = {
|
||||
enable = true;
|
||||
name = "udp514-journal.socket";
|
||||
inherit description;
|
||||
listenDatagrams = [ (builtins.toString cfg.port) ];
|
||||
wantedBy = [ "sockets.target" ];
|
||||
};
|
||||
|
||||
systemd.services.udp514-journal = {
|
||||
enable = true;
|
||||
name = "udp514-journal.service";
|
||||
inherit description;
|
||||
requires = [
|
||||
"systemd-journald.socket"
|
||||
"udp514-journal.socket"
|
||||
];
|
||||
serviceConfig = {
|
||||
Type = "notify";
|
||||
Restart = "always";
|
||||
ExecStart = "${cfg.package}/bin/udp514-journal";
|
||||
DynamicUser = "on";
|
||||
CapabilityBoundingSet = "";
|
||||
AmbientCapabilities = "";
|
||||
ProtectSystem = "strict";
|
||||
ProtectHome = "on";
|
||||
PrivateDevices = "on";
|
||||
PrivateTmp = true;
|
||||
PrivateUsers = "self";
|
||||
PrivateNetwork = "on";
|
||||
RestrictAddressFamilies = [ "AF_UNIX" ];
|
||||
RestrictNamespaces = true;
|
||||
RestrictSUIDSGID = true;
|
||||
RestrictRealtime = true;
|
||||
LockPersonality = true;
|
||||
SystemCallArchitectures = "native";
|
||||
SystemCallFilter = [
|
||||
"@system-service"
|
||||
"~@privileged"
|
||||
"~@resources"
|
||||
];
|
||||
ProtectClock = true;
|
||||
ProtectHostname = true;
|
||||
ProtectKernelLogs = true;
|
||||
ProtectKernelModules = true;
|
||||
ProtectKernelTunables = "on";
|
||||
ProtectControlGroups = "strict";
|
||||
ProtectProc = "noaccess";
|
||||
ProcSubset = "pid";
|
||||
MemoryDenyWriteExecute = true;
|
||||
NoNewPrivileges = true;
|
||||
MemoryMax = "5M";
|
||||
UMask = "0077";
|
||||
};
|
||||
confinement = {
|
||||
enable = true;
|
||||
binSh = null;
|
||||
};
|
||||
};
|
||||
|
||||
networking.firewall.allowedUDPPorts = lib.mkIf cfg.openFirewall [ cfg.port ];
|
||||
};
|
||||
|
||||
meta.maintainers = with lib.maintainers; [ usovalx ];
|
||||
}
|
||||
81
nixos/modules/services/mail/pfix-srsd.nix
Normal file
81
nixos/modules/services/mail/pfix-srsd.nix
Normal file
@@ -0,0 +1,81 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.services.pfix-srsd;
|
||||
in
|
||||
{
|
||||
|
||||
###### interface
|
||||
|
||||
options = {
|
||||
|
||||
services.pfix-srsd = {
|
||||
enable = lib.mkOption {
|
||||
default = false;
|
||||
type = lib.types.bool;
|
||||
description = "Whether to run the postfix sender rewriting scheme daemon.";
|
||||
};
|
||||
|
||||
domain = lib.mkOption {
|
||||
description = "The domain for which to enable srs";
|
||||
type = lib.types.str;
|
||||
example = "example.com";
|
||||
};
|
||||
|
||||
secretsFile = lib.mkOption {
|
||||
description = ''
|
||||
The secret data used to encode the SRS address.
|
||||
to generate, use a command like:
|
||||
`for n in $(seq 5); do dd if=/dev/urandom count=1 bs=1024 status=none | sha256sum | sed 's/ -$//' | sed 's/^/ /'; done`
|
||||
'';
|
||||
type = lib.types.path;
|
||||
default = "/var/lib/pfix-srsd/secrets";
|
||||
};
|
||||
|
||||
configurePostfix = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = ''
|
||||
Whether to configure the required settings to use pfix-srsd in the local Postfix instance.
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
###### implementation
|
||||
|
||||
config = lib.mkMerge [
|
||||
(lib.mkIf (cfg.enable && cfg.configurePostfix && config.services.postfix.enable) {
|
||||
services.postfix.settings.main = {
|
||||
sender_canonical_maps = [ "tcp:127.0.0.1:10001" ];
|
||||
sender_canonical_classes = [ "envelope_sender" ];
|
||||
recipient_canonical_maps = [ "tcp:127.0.0.1:10002" ];
|
||||
recipient_canonical_classes = [ "envelope_recipient" ];
|
||||
};
|
||||
})
|
||||
|
||||
(lib.mkIf cfg.enable {
|
||||
environment = {
|
||||
systemPackages = [ pkgs.pfixtools ];
|
||||
};
|
||||
|
||||
systemd.services.pfix-srsd = {
|
||||
description = "Postfix sender rewriting scheme daemon";
|
||||
before = [ "postfix.service" ];
|
||||
#note that we use requires rather than wants because postfix
|
||||
#is unable to process (almost) all mail without srsd
|
||||
requiredBy = [ "postfix.service" ];
|
||||
serviceConfig = {
|
||||
Type = "forking";
|
||||
PIDFile = "/run/pfix-srsd.pid";
|
||||
ExecStart = "${pkgs.pfixtools}/bin/pfix-srsd -p /run/pfix-srsd.pid -I ${config.services.pfix-srsd.domain} ${config.services.pfix-srsd.secretsFile}";
|
||||
};
|
||||
};
|
||||
})
|
||||
];
|
||||
}
|
||||
@@ -1296,5 +1296,6 @@ in
|
||||
[ "services" "postfix" "settings" "main" "smtp_tls_security_level" ]
|
||||
(config: lib.mkIf config.services.postfix.useDane "dane")
|
||||
)
|
||||
(lib.mkRenamedOptionModule [ "services" "postfix" "useSrs" ] [ "services" "pfix-srsd" "enable" ])
|
||||
];
|
||||
}
|
||||
|
||||
@@ -74,7 +74,7 @@ in
|
||||
default = null;
|
||||
description = ''
|
||||
Environment file, used to set any secret ATUIN_* environment variables, such as ATUIN_DB_URI containing a password.
|
||||
See <https://docs.atuin.sh/latest/self-hosting/server-setup/#configuration> for available environment variables.
|
||||
See https://docs.atuin.sh/cli/self-hosting/server-setup/#configuration for available environment variables.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
@@ -96,7 +96,7 @@ in
|
||||
ln -s ${lib.getExe cfg.blenderPackage} BlenderData/nix-blender-linux64/blender
|
||||
''
|
||||
+ lib.optionalString (cfg.basicSecurityPasswordFile != null) ''
|
||||
BLENDFARM_PASSWORD=$(${config.systemd.package}/bin/systemd-creds cat BLENDFARM_PASS_FILE)
|
||||
BLENDFARM_PASSWORD=$(${pkgs.systemd}/bin/systemd-creds cat BLENDFARM_PASS_FILE)
|
||||
sed -i "s/null/\"$BLENDFARM_PASSWORD\"/g" ServerSettings
|
||||
'';
|
||||
serviceConfig = {
|
||||
|
||||
@@ -78,7 +78,7 @@ in
|
||||
export CLOUDFLARE_EMAIL="${cfg.email}"
|
||||
''}
|
||||
${lib.optionalString (cfg.apiTokenFile != null) ''
|
||||
export CLOUDFLARE_APITOKEN=$(${config.systemd.package}/bin/systemd-creds cat CLOUDFLARE_APITOKEN_FILE)
|
||||
export CLOUDFLARE_APITOKEN=$(${pkgs.systemd}/bin/systemd-creds cat CLOUDFLARE_APITOKEN_FILE)
|
||||
''}
|
||||
${pkgs.cfdyndns}/bin/cfdyndns
|
||||
'';
|
||||
|
||||
@@ -96,7 +96,7 @@ in
|
||||
startAt = "*:0/5";
|
||||
path = [
|
||||
pkgs.gnused
|
||||
config.systemd.package
|
||||
pkgs.systemd
|
||||
pkgs.curl
|
||||
pkgs.gawk
|
||||
duckdns
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
}:
|
||||
let
|
||||
cfg = config.services.portunus;
|
||||
|
||||
in
|
||||
{
|
||||
options.services.portunus = {
|
||||
@@ -78,15 +79,9 @@ in
|
||||
type = lib.types.listOf (
|
||||
lib.types.submodule {
|
||||
options = {
|
||||
redirectURIs = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
description = "URLs where the OIDC client should redirect";
|
||||
};
|
||||
callbackURL = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default = null;
|
||||
description = "URL where the OIDC client should redirect (deprecated, use redirectURIs)";
|
||||
type = lib.types.str;
|
||||
description = "URL where the OIDC client should redirect";
|
||||
};
|
||||
id = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
@@ -98,7 +93,7 @@ in
|
||||
default = [ ];
|
||||
example = [
|
||||
{
|
||||
redirectURIs = [ "https://example.com/client/oidc/callback" ];
|
||||
callbackURL = "https://example.com/client/oidc/callback";
|
||||
id = "service";
|
||||
}
|
||||
];
|
||||
@@ -232,7 +227,7 @@ in
|
||||
|
||||
staticClients = lib.forEach cfg.dex.oidcClients (client: {
|
||||
inherit (client) id;
|
||||
redirectURIs = client.redirectURIs ++ lib.optional (client.callbackURL != null) client.callbackURL;
|
||||
redirectURIs = [ client.callbackURL ];
|
||||
name = "OIDC for ${client.id}";
|
||||
secretEnv = "DEX_CLIENT_${client.id}";
|
||||
});
|
||||
|
||||
@@ -71,7 +71,7 @@ in
|
||||
serviceConfig = {
|
||||
ExecStartPre = [
|
||||
"${cfg.package}/bin/beszel-hub migrate up"
|
||||
"${cfg.package}/bin/beszel-hub migrate history-sync"
|
||||
"${cfg.package}/bin/beszel-hub history-sync"
|
||||
];
|
||||
ExecStart = ''
|
||||
${cfg.package}/bin/beszel-hub serve --http='${cfg.host}:${toString cfg.port}'
|
||||
|
||||
@@ -2090,6 +2090,7 @@ in
|
||||
serviceConfig = {
|
||||
ExecStartPre = [
|
||||
"${lib.getExe' pkgs.coreutils "ln"} -fs ${cfg.package}/share/grafana/conf ${cfg.dataDir}"
|
||||
"${lib.getExe' pkgs.coreutils "ln"} -fs ${cfg.package}/share/grafana/tools ${cfg.dataDir}"
|
||||
];
|
||||
ExecStart = "${lib.getExe cfg.package} server -homepath ${cfg.dataDir} -config ${configFile}";
|
||||
|
||||
|
||||
@@ -1,182 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
let
|
||||
cfg = config.services.orbit;
|
||||
in
|
||||
{
|
||||
options.services.orbit = {
|
||||
enable = lib.mkEnableOption "Fleet Orbit agent" // {
|
||||
description = "Enable the Fleet Orbit agent.";
|
||||
example = lib.literalExpression ''
|
||||
# Use an enrollment secret from a plaintext file managed outside the Nix store.
|
||||
{
|
||||
services.orbit = {
|
||||
enable = true;
|
||||
fleetUrl = "https://fleet.example.com";
|
||||
enrollSecretPath = "/etc/fleet/enroll-secret";
|
||||
|
||||
desktop.enable = true;
|
||||
};
|
||||
}
|
||||
|
||||
# Use an enrollment secret from sops-nix.
|
||||
{ config, ... }:
|
||||
{
|
||||
sops.secrets.fleet-orbit-enroll-secret = { };
|
||||
|
||||
services.orbit = {
|
||||
enable = true;
|
||||
fleetUrl = "https://fleet.example.com";
|
||||
enrollSecretPath = config.sops.secrets.fleet-orbit-enroll-secret.path;
|
||||
|
||||
desktop.enable = true;
|
||||
};
|
||||
}
|
||||
'';
|
||||
};
|
||||
|
||||
orbitPackage = lib.mkPackageOption pkgs "fleet-orbit" { };
|
||||
|
||||
osqueryPackage = lib.mkPackageOption pkgs "osquery" { };
|
||||
|
||||
desktop = {
|
||||
enable = lib.mkEnableOption "Fleet Desktop tray application";
|
||||
|
||||
package = lib.mkPackageOption pkgs "fleet-desktop" { };
|
||||
|
||||
alternativeBrowserHost = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default = null;
|
||||
example = "fleet-browser.example.com";
|
||||
description = ''
|
||||
Alternative host to use for Fleet Desktop browser URLs. This can be
|
||||
required when Fleet uses TLS client authentication.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
fleetUrl = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
example = "https://fleet.example.com";
|
||||
description = "The base URL of the Fleet server.";
|
||||
};
|
||||
|
||||
enrollSecretPath = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
example = "/run/secrets/fleet-enroll-secret";
|
||||
description = ''
|
||||
Path to a file containing the enroll secret for authenticating to the Fleet server.
|
||||
This should point to a secret outside the Nix store, for example a sops-nix or agenix
|
||||
secret path.
|
||||
'';
|
||||
};
|
||||
|
||||
fleetCertificate = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt";
|
||||
defaultText = lib.literalExpression "\"\${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt\"";
|
||||
description = "Path to the Fleet server certificate chain.";
|
||||
};
|
||||
|
||||
debug = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Enable debug logging.";
|
||||
};
|
||||
|
||||
devMode = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Run Orbit in development mode.";
|
||||
};
|
||||
|
||||
enableScripts = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Enable Fleet script execution.";
|
||||
};
|
||||
|
||||
endUserEmail = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.str;
|
||||
default = null;
|
||||
example = "user@example.com";
|
||||
description = "End-user email to pass to Orbit.";
|
||||
};
|
||||
|
||||
fleetManagedHostIdentityCertificate = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Configure Orbit to use Fleet-managed host identity certificates.
|
||||
This requires a Fleet Enterprise Edition subscription.
|
||||
'';
|
||||
};
|
||||
|
||||
hostIdentifier = lib.mkOption {
|
||||
type = lib.types.nullOr (
|
||||
lib.types.enum [
|
||||
"uuid"
|
||||
"instance"
|
||||
]
|
||||
);
|
||||
default = null;
|
||||
example = "uuid";
|
||||
description = "Host identifier mode to use when Orbit and osquery enroll to Fleet.";
|
||||
};
|
||||
|
||||
insecure = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Disable TLS certificate verification.";
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
systemd.services.orbit = {
|
||||
description = "Fleet Orbit agent";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
after = [ "network-online.target" ];
|
||||
wants = [ "network-online.target" ];
|
||||
|
||||
environment = lib.filterAttrs (_: value: value != null) {
|
||||
ORBIT_FLEET_URL = cfg.fleetUrl;
|
||||
ORBIT_ENROLL_SECRET_PATH = "%d/enroll-secret";
|
||||
ORBIT_FLEET_CERTIFICATE = cfg.fleetCertificate;
|
||||
ORBIT_DEBUG = lib.boolToString cfg.debug;
|
||||
ORBIT_DEV_MODE = lib.boolToString cfg.devMode;
|
||||
ORBIT_ENABLE_SCRIPTS = lib.boolToString cfg.enableScripts;
|
||||
ORBIT_END_USER_EMAIL = cfg.endUserEmail;
|
||||
ORBIT_FLEET_MANAGED_HOST_IDENTITY_CERTIFICATE = lib.boolToString cfg.fleetManagedHostIdentityCertificate;
|
||||
ORBIT_HOST_IDENTIFIER = cfg.hostIdentifier;
|
||||
ORBIT_INSECURE = lib.boolToString cfg.insecure;
|
||||
ORBIT_FLEET_DESKTOP_ALTERNATIVE_BROWSER_HOST = cfg.desktop.alternativeBrowserHost;
|
||||
|
||||
ORBIT_DISABLE_KEYSTORE = "true";
|
||||
ORBIT_DISABLE_UPDATES = "true";
|
||||
ORBIT_FLEET_DESKTOP = lib.boolToString cfg.desktop.enable;
|
||||
ORBIT_LOG_FILE = "/var/log/orbit/orbit.log";
|
||||
ORBIT_OSQUERY_DB = "/var/lib/orbit/osquery.db";
|
||||
ORBIT_ROOT_DIR = "/var/lib/orbit";
|
||||
NIX_ORBIT_OSQUERYD_PATH = lib.getExe' cfg.osqueryPackage "osqueryd";
|
||||
NIX_ORBIT_OSQUERY_LOG_PATH = "/var/log/orbit/osquery";
|
||||
NIX_ORBIT_DESKTOP_PATH = if cfg.desktop.enable then lib.getExe cfg.desktop.package else null;
|
||||
};
|
||||
|
||||
serviceConfig = {
|
||||
ExecStart = lib.getExe cfg.orbitPackage;
|
||||
LoadCredential = [ "enroll-secret:${cfg.enrollSecretPath}" ];
|
||||
StateDirectory = "orbit";
|
||||
LogsDirectory = "orbit";
|
||||
TimeoutStartSec = 0;
|
||||
Restart = "always";
|
||||
RestartSec = 60;
|
||||
KillMode = "control-group";
|
||||
KillSignal = "SIGTERM";
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -121,7 +121,6 @@ let
|
||||
"smartctl"
|
||||
"smokeping"
|
||||
"snmp"
|
||||
"snowflake"
|
||||
"speedtest"
|
||||
"sql"
|
||||
"statsd"
|
||||
@@ -136,7 +135,6 @@ let
|
||||
"varnish"
|
||||
"wireguard"
|
||||
"xray"
|
||||
"yace"
|
||||
"zfs-siebenmann"
|
||||
"zfs"
|
||||
]
|
||||
|
||||
@@ -1,91 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.services.prometheus.exporters.snowflake;
|
||||
inherit (lib)
|
||||
mkIf
|
||||
mkOption
|
||||
types
|
||||
optional
|
||||
escapeShellArg
|
||||
concatStringsSep
|
||||
getExe
|
||||
;
|
||||
|
||||
# The private key is passed to systemd via LoadCredential, which exposes it in
|
||||
# the per-service credentials directory (`%d`) readable by the service even
|
||||
# under DynamicUser.
|
||||
args = [
|
||||
"--web.listen-address ${cfg.listenAddress}:${toString cfg.port}"
|
||||
"--account ${escapeShellArg cfg.account}"
|
||||
"--username ${escapeShellArg cfg.username}"
|
||||
"--warehouse ${escapeShellArg cfg.warehouse}"
|
||||
"--role ${escapeShellArg cfg.role}"
|
||||
]
|
||||
++ optional (cfg.privateKeyFile != null) "--private-key-path=%d/snowflake-private-key"
|
||||
++ cfg.extraFlags;
|
||||
in
|
||||
{
|
||||
port = 9975;
|
||||
extraOpts = {
|
||||
account = mkOption {
|
||||
type = types.str;
|
||||
example = "xy12345.us-east-1";
|
||||
description = "Snowflake account to collect metrics for (`--account`).";
|
||||
};
|
||||
username = mkOption {
|
||||
type = types.str;
|
||||
description = "Username used when querying metrics (`--username`).";
|
||||
};
|
||||
warehouse = mkOption {
|
||||
type = types.str;
|
||||
description = "Warehouse used when querying metrics (`--warehouse`).";
|
||||
};
|
||||
role = mkOption {
|
||||
type = types.str;
|
||||
default = "ACCOUNTADMIN";
|
||||
description = "Role used when querying metrics (`--role`).";
|
||||
};
|
||||
privateKeyFile = mkOption {
|
||||
type = types.nullOr types.path;
|
||||
default = null;
|
||||
example = "/run/secrets/snowflake-exporter.p8";
|
||||
description = ''
|
||||
Path to the user's RSA private key for key-pair authentication. The file
|
||||
is passed to the service via {manpage}`systemd.exec(5)` credentials, so
|
||||
it is read only by the exporter and never copied into the world-readable
|
||||
Nix store. If the key is encrypted, supply its password via
|
||||
{option}`environmentFile` (`SNOWFLAKE_EXPORTER_PRIVATE_KEY_PASSWORD`).
|
||||
|
||||
Mutually exclusive with password authentication; when set, do not also
|
||||
provide `SNOWFLAKE_EXPORTER_PASSWORD`.
|
||||
'';
|
||||
};
|
||||
environmentFile = mkOption {
|
||||
type = types.nullOr types.path;
|
||||
default = null;
|
||||
example = "/run/secrets/snowflake-exporter.env";
|
||||
description = ''
|
||||
Path to an environment file, as defined in {manpage}`systemd.exec(5)`,
|
||||
used to pass secrets without exposing them in the world-readable Nix
|
||||
store or the process's command line. For password authentication set
|
||||
`SNOWFLAKE_EXPORTER_PASSWORD`; for an encrypted key (see
|
||||
{option}`privateKeyFile`) set `SNOWFLAKE_EXPORTER_PRIVATE_KEY_PASSWORD`.
|
||||
'';
|
||||
};
|
||||
};
|
||||
serviceOpts = {
|
||||
serviceConfig = {
|
||||
EnvironmentFile = mkIf (cfg.environmentFile != null) [ cfg.environmentFile ];
|
||||
LoadCredential = mkIf (cfg.privateKeyFile != null) [
|
||||
"snowflake-private-key:${cfg.privateKeyFile}"
|
||||
];
|
||||
ExecStart = "${getExe pkgs.prometheus-snowflake-exporter} ${concatStringsSep " " args}";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1,59 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.services.prometheus.exporters.yace;
|
||||
inherit (lib)
|
||||
mkIf
|
||||
mkOption
|
||||
types
|
||||
escapeShellArg
|
||||
concatStringsSep
|
||||
getExe
|
||||
;
|
||||
in
|
||||
{
|
||||
port = 5000;
|
||||
extraOpts = {
|
||||
configFile = mkOption {
|
||||
type = types.path;
|
||||
description = ''
|
||||
Path to the YACE configuration file, defining which CloudWatch
|
||||
metrics to scrape. See
|
||||
<https://github.com/prometheus-community/yet-another-cloudwatch-exporter#configuration>
|
||||
for the format. AWS credentials are supplied separately via the
|
||||
environment (see {option}`environmentFile`, an IMDS instance role,
|
||||
or the usual `AWS_*` variables).
|
||||
'';
|
||||
};
|
||||
environmentFile = mkOption {
|
||||
type = types.nullOr types.path;
|
||||
default = null;
|
||||
example = "/run/secrets/yace.env";
|
||||
description = ''
|
||||
Path to an environment file, as defined in {manpage}`systemd.exec(5)`,
|
||||
used to pass AWS credentials (e.g. `AWS_ACCESS_KEY_ID`,
|
||||
`AWS_SECRET_ACCESS_KEY`, `AWS_REGION`) to the exporter without exposing
|
||||
them in the world-readable Nix store. Not needed on EC2 with an IMDS
|
||||
instance role.
|
||||
'';
|
||||
};
|
||||
};
|
||||
serviceOpts = {
|
||||
serviceConfig = {
|
||||
EnvironmentFile = mkIf (cfg.environmentFile != null) [ cfg.environmentFile ];
|
||||
ExecStart = concatStringsSep " " (
|
||||
[
|
||||
(getExe pkgs.yet-another-cloudwatch-exporter)
|
||||
"--config.file ${escapeShellArg cfg.configFile}"
|
||||
"--listen-address ${cfg.listenAddress}:${toString cfg.port}"
|
||||
]
|
||||
++ cfg.extraFlags
|
||||
);
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -361,7 +361,7 @@ let
|
||||
MONITOR = <generated from config.power.ups.upsmon.monitor>
|
||||
NOTIFYCMD = "''${cfg.package}/bin/upssched";
|
||||
POWERDOWNFLAG = "/run/killpower";
|
||||
SHUTDOWNCMD = "''${config.systemd.package}/bin/shutdown now";
|
||||
SHUTDOWNCMD = "''${pkgs.systemd}/bin/shutdown now";
|
||||
}
|
||||
'';
|
||||
description = "Additional settings to add to `upsmon.conf`.";
|
||||
@@ -398,7 +398,7 @@ let
|
||||
);
|
||||
NOTIFYCMD = lib.mkDefault "${cfg.package}/bin/upssched";
|
||||
POWERDOWNFLAG = lib.mkDefault "/run/killpower";
|
||||
SHUTDOWNCMD = lib.mkDefault "${config.systemd.package}/bin/shutdown now";
|
||||
SHUTDOWNCMD = lib.mkDefault "${pkgs.systemd}/bin/shutdown now";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -20,7 +20,8 @@ let
|
||||
|
||||
settings =
|
||||
if (cfg.settings != null) then
|
||||
lib.recursiveUpdate cfg.settings (
|
||||
cfg.settings
|
||||
// (
|
||||
if cfg.settings.schema_version < 23 then
|
||||
{
|
||||
bind_host = cfg.host;
|
||||
@@ -191,9 +192,8 @@ in
|
||||
# Note: --check-config has the side effect of modifying the file at rest!
|
||||
${lib.getExe cfg.package} -c "$STATE_DIRECTORY/AdGuardHome.yaml" --check-config
|
||||
|
||||
# sed operation needed to fix protection_disabled_until value changed by yaml-merge
|
||||
${lib.getExe pkgs.yaml-merge} "$STATE_DIRECTORY/AdGuardHome.yaml" "${configFile}" \
|
||||
| sed -E "s/(protection_disabled_until: [0-9]{4}-[0-9]{2}-[0-9]{2}) /\1T/" > "$STATE_DIRECTORY/AdGuardHome.yaml.tmp"
|
||||
# Writing directly to AdGuardHome.yaml results in empty file
|
||||
${lib.getExe pkgs.yaml-merge} "$STATE_DIRECTORY/AdGuardHome.yaml" "${configFile}" > "$STATE_DIRECTORY/AdGuardHome.yaml.tmp"
|
||||
mv "$STATE_DIRECTORY/AdGuardHome.yaml.tmp" "$STATE_DIRECTORY/AdGuardHome.yaml"
|
||||
else
|
||||
${installFresh}
|
||||
|
||||
@@ -120,7 +120,7 @@ in
|
||||
else
|
||||
"-o \"UserKnownHostsFile=/dev/null\" -o \"StrictHostKeyChecking=no\"";
|
||||
ready = pkgs.writers.writeBash "systemd-signal-ready" ''
|
||||
${config.systemd.package}/bin/systemd-notify --ready
|
||||
${pkgs.systemd}/bin/systemd-notify --ready
|
||||
'';
|
||||
in
|
||||
''
|
||||
|
||||
@@ -97,7 +97,7 @@ in
|
||||
source = pkgs.writeShellScript "restart-clatd" ''
|
||||
[ "$DEVICE_IFACE" = "${cfg.settings.clat-dev or "clat"}" ] && exit 0
|
||||
[ "$2" != "up" ] && [ "$2" != "down" ] && exit 0
|
||||
${config.systemd.package}/bin/systemctl restart clatd.service
|
||||
${pkgs.systemd}/bin/systemctl restart clatd.service
|
||||
'';
|
||||
}
|
||||
];
|
||||
|
||||
@@ -73,8 +73,6 @@ in
|
||||
"${cfg.rootDir}"
|
||||
"/etc/resolv.conf"
|
||||
];
|
||||
# warp-svc uses this absolute FHS path instead of looking up nft in PATH.
|
||||
BindReadOnlyPaths = [ "${lib.getExe pkgs.nftables}:/usr/sbin/nft" ];
|
||||
CapabilityBoundingSet = caps;
|
||||
AmbientCapabilities = caps;
|
||||
Restart = "always";
|
||||
|
||||
@@ -35,12 +35,6 @@ in
|
||||
|
||||
package = lib.mkPackageOption pkgs "crab-hole" { };
|
||||
|
||||
openFirewall = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Open ports in the firewall for crab-hole's DNS server.";
|
||||
};
|
||||
|
||||
supplementaryGroups = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
@@ -176,11 +170,6 @@ in
|
||||
RestartSec = 1;
|
||||
};
|
||||
};
|
||||
|
||||
networking.firewall = lib.mkIf cfg.openFirewall {
|
||||
allowedUDPPorts = [ 53 ];
|
||||
allowedTCPPorts = [ 53 ];
|
||||
};
|
||||
};
|
||||
|
||||
meta.maintainers = [
|
||||
|
||||
@@ -302,7 +302,7 @@ in
|
||||
]
|
||||
++ lib.optional cfg.setHostname (
|
||||
pkgs.writeShellScriptBin "hostname" ''
|
||||
${lib.getExe' config.systemd.package "hostnamectl"} set-hostname --transient $1
|
||||
${lib.getExe' pkgs.systemd "hostnamectl"} set-hostname --transient $1
|
||||
''
|
||||
);
|
||||
|
||||
|
||||
@@ -1,188 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.services.moonshine;
|
||||
tomlFormat = pkgs.formats.toml { };
|
||||
configFile = tomlFormat.generate "moonshine-config.toml" cfg.settings;
|
||||
|
||||
runScript = pkgs.writeShellScriptBin "moonshine-server" ''
|
||||
export XDG_RUNTIME_DIR="''${XDG_RUNTIME_DIR:-/run/user/$(${lib.getExe' pkgs.coreutils "id"} -u)}"
|
||||
export DBUS_SESSION_BUS_ADDRESS="''${DBUS_SESSION_BUS_ADDRESS:-unix:path=$XDG_RUNTIME_DIR/bus}"
|
||||
exec ${lib.getExe cfg.package} ${configFile} "$@"
|
||||
'';
|
||||
in
|
||||
{
|
||||
options.services.moonshine = {
|
||||
enable = lib.mkEnableOption "Moonshine, a headless game streaming server for Moonlight clients";
|
||||
|
||||
package = lib.mkPackageOption pkgs "moonshine" { };
|
||||
|
||||
user = lib.mkOption {
|
||||
type = lib.types.nonEmptyStr;
|
||||
example = "alice";
|
||||
description = ''
|
||||
User under which to run Moonshine. The user must be declared separately
|
||||
in {option}`users.users`. Lingering is enabled automatically so the
|
||||
server can run without an active login session.
|
||||
'';
|
||||
};
|
||||
|
||||
settings = lib.mkOption {
|
||||
type = tomlFormat.type;
|
||||
default = { };
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
name = "my-desktop";
|
||||
address = "0.0.0.0";
|
||||
application = [
|
||||
{
|
||||
title = "Steam";
|
||||
command = [ "steam" "steam://open/bigpicture" ];
|
||||
}
|
||||
];
|
||||
application_scanner = [
|
||||
{
|
||||
type = "steam";
|
||||
library = "$HOME/.local/share/Steam";
|
||||
command = [ "steam" "-bigpicture" "steam://rungameid/{game_id}" ];
|
||||
}
|
||||
];
|
||||
}
|
||||
'';
|
||||
description = ''
|
||||
Moonshine configuration, generated as a TOML file in the Nix store.
|
||||
See <https://github.com/hgaiser/moonshine/blob/main/moonshine-core/src/config.rs>
|
||||
for the available settings and <https://github.com/hgaiser/moonshine#configuration> for some examples.
|
||||
|
||||
Do not leave this option empty: Moonshine's upstream defaults configure
|
||||
Steam at {file}`/usr/bin/steam`, which does not exist on NixOS. Define
|
||||
at least `application` with an executable in the Nix store, as shown in
|
||||
the example. Setting `application` explicitly is sufficient;
|
||||
`application_scanners` may be omitted.
|
||||
|
||||
Moonshine stores {file}`cert.pem` and {file}`key.pem` in
|
||||
{file}`~/.config/moonshine/`, and paired-client state in
|
||||
{file}`~/.local/share/moonshine/state.toml` for the configured user.
|
||||
|
||||
Since the service runs without a desktop session, its notification
|
||||
action cannot reliably open the pairing page. Pair clients by visiting
|
||||
{file}`http://<host>:47989/pin` in a browser instead.
|
||||
'';
|
||||
};
|
||||
|
||||
extraPackages = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.package;
|
||||
default = [ ];
|
||||
example = lib.literalExpression "[ pkgs.steam ]";
|
||||
description = ''
|
||||
Packages added to the service's {env}`PATH` for applications launched
|
||||
by Moonshine.
|
||||
'';
|
||||
};
|
||||
|
||||
environment = lib.mkOption {
|
||||
type = lib.types.attrsOf lib.types.str;
|
||||
default = { };
|
||||
example = {
|
||||
MESA_VK_DEVICE_SELECT = "10de:25a2!";
|
||||
};
|
||||
description = ''
|
||||
Environment variables set for Moonshine.
|
||||
|
||||
::: {.note}
|
||||
Those are not inherited by launched applications.
|
||||
:::
|
||||
'';
|
||||
};
|
||||
|
||||
firewallInterfaces = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [ ];
|
||||
example = [
|
||||
"tailscale0"
|
||||
"wg0"
|
||||
];
|
||||
description = ''
|
||||
Network interfaces on which to open the Moonlight/GameStream ports.
|
||||
The ports are not opened when this list is empty.
|
||||
Moonshine is not designed for use on public networks. Do not expose Moonshine ports directly to the internet. See https://github.com/hgaiser/moonshine#security
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
assertions = [
|
||||
{
|
||||
assertion = lib.hasAttr cfg.user config.users.users;
|
||||
message = "services.moonshine.user refers to undeclared user '${cfg.user}'.";
|
||||
}
|
||||
];
|
||||
|
||||
boot.kernelModules = [
|
||||
"uinput"
|
||||
"uhid"
|
||||
];
|
||||
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
# Make the implicit WSI Vulkan layer available to launched applications.
|
||||
hardware.graphics = {
|
||||
enable = true;
|
||||
extraPackages = [ cfg.package ];
|
||||
};
|
||||
|
||||
networking.firewall.interfaces = lib.genAttrs cfg.firewallInterfaces (_: {
|
||||
allowedTCPPorts = [
|
||||
(cfg.settings.webserver.port_https or 47984)
|
||||
(cfg.settings.webserver.port or 47989)
|
||||
(cfg.settings.stream.port or 48010)
|
||||
];
|
||||
allowedUDPPorts = [
|
||||
5353 # moonshine has an embedded mDNS responder that does not conflict with avahi
|
||||
(cfg.settings.stream.video.port or 47998)
|
||||
(cfg.settings.stream.control.port or 47999)
|
||||
(cfg.settings.stream.audio.port or 48000)
|
||||
];
|
||||
});
|
||||
|
||||
services.udev.packages = [ cfg.package ];
|
||||
|
||||
systemd.services.moonshine = {
|
||||
description = "Streaming server using the NVIDIA GameStream / Moonlight protocol.";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
after = [ "network.target" ];
|
||||
path = [ pkgs.xwayland ] ++ cfg.extraPackages;
|
||||
environment = {
|
||||
MOONSHINE_LOG = "moonshine=info";
|
||||
}
|
||||
// cfg.environment;
|
||||
serviceConfig = {
|
||||
User = cfg.user;
|
||||
SupplementaryGroups = [ "moonshine" ];
|
||||
ExecStart = lib.getExe runScript;
|
||||
Restart = "on-failure";
|
||||
RestartSec = 5;
|
||||
DeviceAllow = [
|
||||
"/dev/uinput rw"
|
||||
"/dev/uhid rw"
|
||||
"char-drm rw"
|
||||
"char-nvidia rw"
|
||||
"char-nvidia-uvm rw"
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
users = {
|
||||
groups.moonshine = { };
|
||||
users.${cfg.user} = {
|
||||
linger = true;
|
||||
extraGroups = [ "input" ];
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1049,7 +1049,7 @@ in
|
||||
};
|
||||
syncthing-init = lib.mkIf (cleanedConfig != { }) {
|
||||
description = "Syncthing configuration updater";
|
||||
requires = [ "syncthing.service" ];
|
||||
requisite = [ "syncthing.service" ];
|
||||
after = [ "syncthing.service" ];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
|
||||
|
||||
@@ -825,7 +825,6 @@ in
|
||||
RestrictSUIDSGID = true;
|
||||
ExecReload = [
|
||||
" " # This is needed to clear the ExecReload definitions from upstream
|
||||
"${lib.getExe' pkgs.util-linux "kill"} -HUP $MAINPID"
|
||||
];
|
||||
ExecStart = [
|
||||
" " # This is needed to clear the ExecStart definitions from upstream
|
||||
|
||||
@@ -400,8 +400,12 @@ in
|
||||
# Security
|
||||
NoNewPrivileges = true;
|
||||
# Directory
|
||||
RuntimeDirectory = "fail2ban";
|
||||
RuntimeDirectoryMode = "0750";
|
||||
StateDirectory = "fail2ban";
|
||||
StateDirectoryMode = "0750";
|
||||
LogsDirectory = "fail2ban";
|
||||
LogsDirectoryMode = "0750";
|
||||
# Sandboxing
|
||||
ProtectSystem = "strict";
|
||||
ProtectHome = true;
|
||||
@@ -413,10 +417,6 @@ in
|
||||
ProtectControlGroups = true;
|
||||
};
|
||||
};
|
||||
systemd.sockets.fail2ban.wantedBy = [
|
||||
"sockets.target"
|
||||
"fail2ban.service"
|
||||
];
|
||||
|
||||
# Defaults for the daemon settings
|
||||
services.fail2ban.daemonSettings.Definition = {
|
||||
|
||||
@@ -31,8 +31,7 @@ let
|
||||
format = pkgs.formats.keyValue { };
|
||||
settingsFile = format.generate "pocket-id-env-vars" cfg.settings;
|
||||
|
||||
exportCredentials =
|
||||
n: _: ''export ${n}="$(${config.systemd.package}/bin/systemd-creds cat ${n}_FILE)"'';
|
||||
exportCredentials = n: _: ''export ${n}="$(${pkgs.systemd}/bin/systemd-creds cat ${n}_FILE)"'';
|
||||
exportAllCredentials = vars: lib.concatStringsSep "\n" (lib.mapAttrsToList exportCredentials vars);
|
||||
getLoadCredentialList = lib.mapAttrsToList (n: v: "${n}_FILE:${v}") cfg.credentials;
|
||||
in
|
||||
|
||||
@@ -1,50 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
let
|
||||
cfg = config.services.rosec;
|
||||
in
|
||||
{
|
||||
options.services.rosec = {
|
||||
enable = lib.mkEnableOption "rosec, a secrets daemon implementing the freedesktop.org Secret Service API";
|
||||
|
||||
package = lib.mkPackageOption pkgs "rosec" { };
|
||||
|
||||
pam = {
|
||||
enable = lib.mkEnableOption "PAM integration to automatically unlock the rosec vault on login";
|
||||
|
||||
services = lib.mkOption {
|
||||
type = with lib.types; listOf str;
|
||||
default = [ "login" ];
|
||||
example = [
|
||||
"login"
|
||||
"greetd"
|
||||
];
|
||||
description = ''
|
||||
List of PAM services for which to enable rosec automatic unlock.
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
services.dbus.packages = [ cfg.package ];
|
||||
|
||||
systemd.packages = [ cfg.package ];
|
||||
|
||||
xdg.portal.extraPortals = [ cfg.package ];
|
||||
|
||||
security.pam.services = lib.mkIf cfg.pam.enable (
|
||||
lib.genAttrs cfg.pam.services (_: {
|
||||
rosec.enable = true;
|
||||
})
|
||||
);
|
||||
};
|
||||
|
||||
meta.maintainers = with lib.maintainers; [ mikilio ];
|
||||
}
|
||||
@@ -149,11 +149,6 @@ in
|
||||
default = "tinyauth";
|
||||
description = "Group account under which Tinyauth runs.";
|
||||
};
|
||||
|
||||
enableUnixSocket = mkEnableOption (
|
||||
"a UNIX domain socket at `/run/tinyauth/tinyauth.sock`"
|
||||
+ " instead of listening on an IP address and port."
|
||||
);
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
@@ -179,7 +174,6 @@ in
|
||||
GIN_MODE = "release";
|
||||
TINYAUTH_DATABASE_PATH = "${cfg.dataDir}/tinyauth.db";
|
||||
TINYAUTH_RESOURCES_PATH = "${cfg.dataDir}/resources";
|
||||
TINYAUTH_SERVER_SOCKETPATH = mkIf cfg.enableUnixSocket "%t/tinyauth/tinyauth.sock";
|
||||
};
|
||||
|
||||
serviceConfig = {
|
||||
@@ -187,8 +181,6 @@ in
|
||||
User = cfg.user;
|
||||
Group = cfg.group;
|
||||
WorkingDirectory = cfg.dataDir;
|
||||
RuntimeDirectory = mkIf cfg.enableUnixSocket "tinyauth";
|
||||
RuntimeDirectoryMode = mkIf cfg.enableUnixSocket "750";
|
||||
ExecStart = getExe cfg.package;
|
||||
Restart = "always";
|
||||
|
||||
@@ -232,7 +224,7 @@ in
|
||||
"~@privileged"
|
||||
"~@resources"
|
||||
];
|
||||
UMask = if cfg.enableUnixSocket then "0007" else "0077";
|
||||
UMask = "0077";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -31,15 +31,6 @@ let
|
||||
;
|
||||
isNormal = opts.isNormalUser;
|
||||
shell = utils.toShellPath opts.shell;
|
||||
autoSubIdRange = opts.autoSubUidGidRange;
|
||||
subUidRanges = map (r: {
|
||||
start = r.startUid;
|
||||
inherit (r) count;
|
||||
}) opts.subUidRanges;
|
||||
subGidRanges = map (r: {
|
||||
start = r.startGid;
|
||||
inherit (r) count;
|
||||
}) opts.subGidRanges;
|
||||
}) (lib.filterAttrs (_: u: u.enable) config.users.users);
|
||||
};
|
||||
|
||||
@@ -56,19 +47,12 @@ let
|
||||
previousConfigPath = "/var/lib/userborn/previous-userborn.json";
|
||||
|
||||
immutableEtc = config.system.etc.overlay.enable && !config.system.etc.overlay.mutable;
|
||||
# The files live outside /etc and need to be linked or bind-mounted there.
|
||||
filesOutsideEtc = !cfg.static && cfg.passwordFilesLocation != "/etc";
|
||||
# The filenames created by userborn.
|
||||
passwordFiles = [
|
||||
"group"
|
||||
"passwd"
|
||||
"shadow"
|
||||
];
|
||||
# newuidmap opens these with O_NOFOLLOW, no symlinks in /etc.
|
||||
subIdFiles = [
|
||||
"subuid"
|
||||
"subgid"
|
||||
];
|
||||
|
||||
in
|
||||
{
|
||||
@@ -109,9 +93,6 @@ in
|
||||
write the files directly to `/etc`.
|
||||
|
||||
However this can also serve other use cases, e.g. when `/etc` is on a `tmpfs`.
|
||||
|
||||
The subid files are an exception: `newuidmap` rejects symlinks, so
|
||||
they are bind-mounted into `/etc` instead of being symlinked.
|
||||
'';
|
||||
};
|
||||
|
||||
@@ -247,16 +228,13 @@ in
|
||||
|
||||
# Make the source files writable before executing userborn.
|
||||
(lib.mkIf (!userCfg.mutableUsers) (
|
||||
lib.map (file: "-${pkgs.util-linux}/bin/umount ${cfg.passwordFilesLocation}/${file}") (
|
||||
passwordFiles ++ subIdFiles
|
||||
)
|
||||
lib.map (file: "-${pkgs.util-linux}/bin/umount ${cfg.passwordFilesLocation}/${file}") passwordFiles
|
||||
))
|
||||
];
|
||||
|
||||
ExecStartPost =
|
||||
if userCfg.mutableUsers then
|
||||
# Store the config so the next run can tell declarative changes
|
||||
# from manual edits (see USERBORN_PREVIOUS_CONFIG).
|
||||
# Store the config somewhere for the next invocation
|
||||
[
|
||||
"${pkgs.coreutils}/bin/ln -sf ${userbornConfigJson} ${previousConfigPath}"
|
||||
]
|
||||
@@ -265,33 +243,9 @@ in
|
||||
(lib.map (
|
||||
file:
|
||||
"${pkgs.util-linux}/bin/mount --bind -o ro ${cfg.passwordFilesLocation}/${file} ${cfg.passwordFilesLocation}/${file}"
|
||||
) (passwordFiles ++ subIdFiles));
|
||||
) passwordFiles);
|
||||
};
|
||||
};
|
||||
|
||||
# Bind-mount the subid files into /etc when they live elsewhere,
|
||||
# newuidmap rejects symlinks.
|
||||
mounts = lib.mkIf filesOutsideEtc (
|
||||
map (file: {
|
||||
what = "${cfg.passwordFilesLocation}/${file}";
|
||||
where = "/etc/${file}";
|
||||
type = "none";
|
||||
options = "bind";
|
||||
after = [ "userborn.service" ];
|
||||
requires = [ "userborn.service" ];
|
||||
wantedBy = [ "sysinit.target" ];
|
||||
requiredBy = [ "sysinit-reactivation.target" ];
|
||||
before = [
|
||||
"sysinit.target"
|
||||
"sysinit-reactivation.target"
|
||||
"shutdown.target"
|
||||
];
|
||||
conflicts = [ "shutdown.target" ];
|
||||
# Re-mount after userborn's atomic rename replaces the inode.
|
||||
restartTriggers = [ userbornConfigJson ];
|
||||
unitConfig.DefaultDependencies = false;
|
||||
}) subIdFiles
|
||||
);
|
||||
};
|
||||
|
||||
environment.etc = lib.mkMerge [
|
||||
@@ -304,11 +258,11 @@ in
|
||||
source = "${userbornStaticFiles}/${file}";
|
||||
mode = if file == "shadow" then "0000" else "0644";
|
||||
}
|
||||
) (passwordFiles ++ subIdFiles)
|
||||
) passwordFiles
|
||||
)
|
||||
))
|
||||
|
||||
(lib.mkIf filesOutsideEtc (
|
||||
(lib.mkIf (!cfg.static && cfg.passwordFilesLocation != "/etc") (
|
||||
# Statically create the symlinks to passwordFilesLocation when they're not
|
||||
# inside /etc because we will not be able to do it at runtime in case of a
|
||||
# (non-static) immutable /etc!
|
||||
@@ -322,19 +276,6 @@ in
|
||||
) passwordFiles
|
||||
)
|
||||
))
|
||||
|
||||
(lib.mkIf filesOutsideEtc (
|
||||
# Placeholder mount points for the subid bind mounts.
|
||||
lib.listToAttrs (
|
||||
lib.map (
|
||||
file:
|
||||
lib.nameValuePair file {
|
||||
text = "";
|
||||
mode = "0644";
|
||||
}
|
||||
) subIdFiles
|
||||
)
|
||||
))
|
||||
];
|
||||
};
|
||||
|
||||
|
||||
@@ -160,10 +160,6 @@ in
|
||||
);
|
||||
|
||||
environment.systemPackages = [ cfg.package ];
|
||||
|
||||
# Install at least one monospace font, as otherwise the fallback is DejaVu Sans, a non-monospace font
|
||||
fonts.packages = [ pkgs.hack-font ];
|
||||
|
||||
systemd.packages = [ cfg.package ];
|
||||
|
||||
systemd.services."kmsconvt@" = {
|
||||
|
||||
@@ -787,7 +787,6 @@ in
|
||||
|
||||
# Caches
|
||||
PrivateTmp = true;
|
||||
TemporaryFileSystem = "/dev/shm:mode=1777,nosuid,nodev";
|
||||
CacheDirectory = [
|
||||
"frigate"
|
||||
# https://github.com/blakeblackshear/frigate/discussions/18129
|
||||
|
||||
@@ -342,17 +342,10 @@ in
|
||||
'';
|
||||
};
|
||||
};
|
||||
virtualHosts.${domainFor "albums"} = {
|
||||
forceSSL = mkDefault true;
|
||||
locations."/" = {
|
||||
root = webPackage "albums";
|
||||
tryFiles = "$uri $uri.html /index.html";
|
||||
extraConfig = ''
|
||||
add_header Access-Control-Allow-Origin 'https://${cfgWeb.domains.api}';
|
||||
'';
|
||||
};
|
||||
};
|
||||
virtualHosts.${domainFor "photos"} = {
|
||||
serverAliases = [
|
||||
(domainFor "albums") # the albums app is shared with the photos frontend
|
||||
];
|
||||
forceSSL = mkDefault true;
|
||||
locations."/" = {
|
||||
root = webPackage "photos";
|
||||
|
||||
@@ -137,15 +137,7 @@ in
|
||||
host = mkOption {
|
||||
type = types.str;
|
||||
default = "localhost";
|
||||
example = ""; # all interfaces
|
||||
# hint: the use of "" for IMMICH_HOST is not documented
|
||||
# see https://docs.immich.app/install/environment-variables/#ports
|
||||
# or https://github.com/immich-app/immich/blob/767caf9bfec2ec74ebdef6f58643ee9505da8550/docs/docs/install/environment-variables.md?plain=1#L70
|
||||
# impl: https://github.com/immich-app/immich/blob/60f4dedb2991c8356d2977f1dc9cfa2cf666788c/server/src/app.common.ts#L90
|
||||
description = ''
|
||||
The host that immich will listen on.
|
||||
Set to an empty string (`""`) to listen on all interfaces.
|
||||
'';
|
||||
description = "The host that immich will listen on.";
|
||||
};
|
||||
port = mkOption {
|
||||
type = types.port;
|
||||
|
||||
@@ -9,8 +9,7 @@ let
|
||||
meiliCfg = config.services.meilisearch;
|
||||
format = pkgs.formats.yaml { };
|
||||
configFile = format.generate "librechat.yaml" cfg.settings;
|
||||
exportCredentials =
|
||||
n: _: ''export ${n}="$(${config.systemd.package}/bin/systemd-creds cat ${n}_FILE)"'';
|
||||
exportCredentials = n: _: ''export ${n}="$(${pkgs.systemd}/bin/systemd-creds cat ${n}_FILE)"'';
|
||||
exportAllCredentials = vars: lib.concatStringsSep "\n" (lib.mapAttrsToList exportCredentials vars);
|
||||
getLoadCredentialList = lib.mapAttrsToList (n: v: "${n}_FILE:${v}") cfg.credentials;
|
||||
in
|
||||
|
||||
@@ -109,12 +109,12 @@ let
|
||||
'';
|
||||
|
||||
dbAddr =
|
||||
if cfg.database.type == "postgres" then
|
||||
(if cfg.database.socket == null then cfg.database.host else cfg.database.socket)
|
||||
else if cfg.database.socket == null then
|
||||
if cfg.database.socket == null then
|
||||
"${cfg.database.host}:${toString cfg.database.port}"
|
||||
else if cfg.database.type == "mysql" then
|
||||
"${cfg.database.host}:${cfg.database.socket}"
|
||||
else if cfg.database.type == "postgres" then
|
||||
"${cfg.database.socket}"
|
||||
else
|
||||
throw "Unsupported database type: ${cfg.database.type} for socket: ${cfg.database.socket}";
|
||||
|
||||
|
||||
@@ -434,12 +434,11 @@ in
|
||||
package = lib.mkOption {
|
||||
type = types.package;
|
||||
default =
|
||||
if lib.versionAtLeast config.system.stateVersion "26.11" then pkgs.netbox_4_6 else pkgs.netbox_4_5;
|
||||
if lib.versionAtLeast config.system.stateVersion "26.05" then pkgs.netbox_4_5 else pkgs.netbox_4_4;
|
||||
defaultText = lib.literalExpression ''
|
||||
if lib.versionAtLeast config.system.stateVersion "26.11" then
|
||||
pkgs.netbox_4_6
|
||||
else
|
||||
pkgs.netbox_4_5;
|
||||
if lib.versionAtLeast config.system.stateVersion "26.05"
|
||||
then pkgs.netbox_4_5
|
||||
else pkgs.netbox_4_4;
|
||||
'';
|
||||
description = ''
|
||||
NetBox package to use.
|
||||
|
||||
@@ -8,22 +8,14 @@ let
|
||||
cfg = config.services.papra;
|
||||
defaultUser = "papra";
|
||||
defaultGroup = "papra";
|
||||
defaultEnv = {
|
||||
SERVER_SERVE_PUBLIC_DIR = true;
|
||||
PORT = 1221;
|
||||
DATABASE_URL = "file:/var/lib/papra/db.sqlite";
|
||||
DOCUMENT_STORAGE_FILESYSTEM_ROOT = "/var/lib/papra/local-documents";
|
||||
};
|
||||
in
|
||||
{
|
||||
imports = [
|
||||
(lib.mkChangedOptionModule
|
||||
[ "services" "papra" "environmentFile" ]
|
||||
[ "services" "papra" "environmentFiles" ]
|
||||
(
|
||||
config:
|
||||
let
|
||||
value = lib.getAttrFromPath [ "services" "papra" "environmentFile" ] config;
|
||||
in
|
||||
if value == null then [ ] else [ value ]
|
||||
)
|
||||
)
|
||||
];
|
||||
|
||||
options = {
|
||||
services.papra = {
|
||||
enable = lib.mkEnableOption "Papra";
|
||||
@@ -45,103 +37,31 @@ in
|
||||
|
||||
package = lib.mkPackageOption pkgs "papra" { };
|
||||
|
||||
openFirewall = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Whether to open the firewall for Papra.
|
||||
'';
|
||||
};
|
||||
|
||||
environment = lib.mkOption {
|
||||
type = lib.types.submodule {
|
||||
freeformType =
|
||||
with lib.types;
|
||||
attrsOf (oneOf [
|
||||
str
|
||||
int
|
||||
float
|
||||
bool
|
||||
path
|
||||
package
|
||||
]);
|
||||
|
||||
options = {
|
||||
PORT = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
default = 1221;
|
||||
description = ''
|
||||
The port on which Papra listens.
|
||||
See <https://docs.papra.app/self-hosting/configuration/#port> for more information.
|
||||
'';
|
||||
};
|
||||
|
||||
DATABASE_URL = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "file:/var/lib/papra/db.sqlite";
|
||||
description = ''
|
||||
The URL of the database.
|
||||
See <https://docs.papra.app/self-hosting/configuration/#database_url> for more information.
|
||||
|
||||
::: {.note}
|
||||
When specifying a `file:` URL with an absolute path through this option,
|
||||
the database's parent directory is automatically added to the systemd
|
||||
service's `ReadWritePaths`. Other local database paths, including paths
|
||||
specified through `environmentFiles`, may need to be added to `ReadWritePaths` manually.
|
||||
:::
|
||||
'';
|
||||
};
|
||||
|
||||
INGESTION_FOLDER_ROOT_PATH = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "/var/lib/papra/ingestion";
|
||||
description = ''
|
||||
The root directory in which ingestion folders for each organization are stored.
|
||||
The parent directory must already exist if using a custom path.
|
||||
See <https://docs.papra.app/self-hosting/configuration/#ingestion_folder_root_path> for more information.
|
||||
'';
|
||||
};
|
||||
|
||||
DOCUMENT_STORAGE_FILESYSTEM_ROOT = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "/var/lib/papra/local-documents";
|
||||
description = ''
|
||||
The root directory to store documents in.
|
||||
The parent directory must already exist if using a custom path.
|
||||
See <https://docs.papra.app/self-hosting/configuration/#document_storage_filesystem_root> for more information.
|
||||
'';
|
||||
};
|
||||
|
||||
SERVER_SERVE_PUBLIC_DIR = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = true;
|
||||
description = ''
|
||||
Whether to serve the public directory.
|
||||
See <https://docs.papra.app/self-hosting/configuration/#server_serve_public_dir> for more information.
|
||||
'';
|
||||
};
|
||||
};
|
||||
type =
|
||||
with lib.types;
|
||||
attrsOf (oneOf [
|
||||
str
|
||||
int
|
||||
float
|
||||
bool
|
||||
path
|
||||
package
|
||||
]);
|
||||
default = defaultEnv;
|
||||
example = {
|
||||
PORT = 1221;
|
||||
};
|
||||
default = { };
|
||||
description = ''
|
||||
Environment variables to pass to Papra.
|
||||
See <https://docs.papra.app/self-hosting/configuration/#configuration-variables> for more information.
|
||||
'';
|
||||
description = "Environment variables to set for the service.";
|
||||
};
|
||||
|
||||
environmentFiles = lib.mkOption {
|
||||
type = with lib.types; listOf path;
|
||||
default = [ ];
|
||||
example = [ "/run/secrets/papra.env" ];
|
||||
description = ''
|
||||
Files to load environment variables from in addition to [](#opt-services.papra.environment).
|
||||
This is useful to avoid putting secrets into the nix store.
|
||||
See <https://docs.papra.app/self-hosting/configuration/#configuration-variables> for more information.
|
||||
'';
|
||||
environmentFile = lib.mkOption {
|
||||
type = with lib.types; nullOr path;
|
||||
default = null;
|
||||
description = "Environment file, usefult to provide secrets to the service";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
users = {
|
||||
users = lib.optionalAttrs (cfg.user == defaultUser) {
|
||||
@@ -156,18 +76,6 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
systemd.tmpfiles.settings."10-papra" = {
|
||||
"${cfg.environment.DOCUMENT_STORAGE_FILESYSTEM_ROOT}".d = {
|
||||
mode = "0700";
|
||||
inherit (cfg) user group;
|
||||
};
|
||||
|
||||
"${cfg.environment.INGESTION_FOLDER_ROOT_PATH}".d = {
|
||||
mode = "0770";
|
||||
inherit (cfg) user group;
|
||||
};
|
||||
};
|
||||
|
||||
systemd.services.papra = {
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
serviceConfig = {
|
||||
@@ -177,58 +85,15 @@ in
|
||||
User = cfg.user;
|
||||
Group = cfg.group;
|
||||
StateDirectory = "papra";
|
||||
StateDirectoryMode = "0700";
|
||||
EnvironmentFile = cfg.environmentFiles;
|
||||
ReadWritePaths = lib.unique (
|
||||
[
|
||||
cfg.environment.DOCUMENT_STORAGE_FILESYSTEM_ROOT
|
||||
cfg.environment.INGESTION_FOLDER_ROOT_PATH
|
||||
]
|
||||
++ lib.optional (lib.hasPrefix "file:/" cfg.environment.DATABASE_URL) (
|
||||
dirOf (lib.removePrefix "file:" cfg.environment.DATABASE_URL)
|
||||
)
|
||||
);
|
||||
|
||||
# Hardening
|
||||
CapabilityBoundingSet = "";
|
||||
NoNewPrivileges = true;
|
||||
LockPersonality = true;
|
||||
PrivateDevices = true;
|
||||
PrivateTmp = true;
|
||||
ProcSubset = "pid";
|
||||
ProtectClock = true;
|
||||
ProtectControlGroups = true;
|
||||
ProtectHome = true;
|
||||
ProtectHostname = true;
|
||||
ProtectKernelLogs = true;
|
||||
ProtectKernelModules = true;
|
||||
ProtectKernelTunables = true;
|
||||
ProtectProc = "invisible";
|
||||
ProtectSystem = "strict";
|
||||
RemoveIPC = true;
|
||||
RestrictAddressFamilies = [
|
||||
"AF_UNIX"
|
||||
"AF_INET"
|
||||
"AF_INET6"
|
||||
];
|
||||
RestrictNamespaces = true;
|
||||
RestrictRealtime = true;
|
||||
RestrictSUIDSGID = true;
|
||||
SystemCallArchitectures = "native";
|
||||
SystemCallFilter = [
|
||||
"@system-service"
|
||||
"~@privileged"
|
||||
"~@resources"
|
||||
];
|
||||
UMask = "0007";
|
||||
EnvironmentFile = cfg.environmentFile;
|
||||
};
|
||||
environment = lib.mapAttrs (
|
||||
_: s: if lib.isBool s then lib.boolToString s else toString s
|
||||
) cfg.environment;
|
||||
};
|
||||
|
||||
networking.firewall = lib.mkIf cfg.openFirewall {
|
||||
allowedTCPPorts = [ cfg.environment.PORT ];
|
||||
environment =
|
||||
let
|
||||
environmentwithDefaults = defaultEnv // cfg.environment;
|
||||
in
|
||||
(lib.mapAttrs (
|
||||
_: s: if lib.isBool s then lib.boolToString s else toString s
|
||||
) environmentwithDefaults);
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -1,651 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
cfg = config.services.rundeck;
|
||||
settingsFormat = pkgs.formats.javaProperties { };
|
||||
effectivePort = if cfg.ssl.enable then cfg.ssl.port else cfg.serverPort;
|
||||
scheme = if cfg.ssl.enable then "https" else "http";
|
||||
|
||||
configFile = settingsFormat.generate "rundeck-config.properties" cfg.settings;
|
||||
frameworkFile = settingsFormat.generate "framework.properties" cfg.frameworkSettings;
|
||||
|
||||
realmFile = pkgs.writeText "realm.properties" ''
|
||||
${cfg.adminUser}:@ADMIN_PASSWORD@,user,admin
|
||||
'';
|
||||
|
||||
replaceSecret =
|
||||
placeholder: file: target:
|
||||
"replace-secret ${
|
||||
lib.escapeShellArgs [
|
||||
placeholder
|
||||
file
|
||||
target
|
||||
]
|
||||
}";
|
||||
|
||||
rundeckStartScript = pkgs.writeShellScript "start-rundeck" ''
|
||||
# Generate SSH
|
||||
if [ ! -f ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType} ]; then
|
||||
umask 0077
|
||||
${lib.getExe' pkgs.openssh "ssh-keygen"} -t ${cfg.sshKeyType} ${
|
||||
lib.optionalString (cfg.sshKeyType == "rsa") "-b 4096"
|
||||
} -N "" -f ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType}
|
||||
chmod 644 ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType}.pub
|
||||
chown ${cfg.user}:${cfg.group} ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType} ${cfg.dataDir}/.ssh/id_${cfg.sshKeyType}.pub
|
||||
fi
|
||||
|
||||
${lib.getExe cfg.package} \
|
||||
--skipinstall \
|
||||
-b ${cfg.dataDir} \
|
||||
-c ${cfg.configDir} \
|
||||
-p ${cfg.dataDir}/projects
|
||||
'';
|
||||
in
|
||||
{
|
||||
options = {
|
||||
services.rundeck = {
|
||||
enable = lib.mkEnableOption "Rundeck service";
|
||||
|
||||
package = lib.mkPackageOption pkgs "rundeck" { };
|
||||
|
||||
adminUser = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "admin";
|
||||
description = "Username for the Rundeck admin user";
|
||||
example = "rundeck-admin";
|
||||
};
|
||||
|
||||
adminPasswordFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
description = "Path to a file containing the admin password";
|
||||
example = "/run/secrets/rundeck-admin-password";
|
||||
};
|
||||
|
||||
user = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "rundeck";
|
||||
description = "User account under which Rundeck runs";
|
||||
};
|
||||
|
||||
group = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "rundeck";
|
||||
description = "Group account under which Rundeck runs";
|
||||
};
|
||||
|
||||
serverHostname = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "localhost";
|
||||
description = "Hostname for the Rundeck server";
|
||||
};
|
||||
|
||||
serverURL = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "${scheme}://${cfg.serverHostname}:${toString effectivePort}";
|
||||
defaultText = lib.literalMD ''
|
||||
`<scheme>://<serverHostname>:<port>`, where scheme is `https` when
|
||||
`ssl.enable` else `http`, and port is `ssl.port` when `ssl.enable`
|
||||
else `serverPort`.
|
||||
'';
|
||||
description = "Complete Grails server URL";
|
||||
example = "https://myhost:4443/rundeck";
|
||||
};
|
||||
|
||||
serverPort = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
default = 4440;
|
||||
description = "Port on which Rundeck will listen";
|
||||
};
|
||||
|
||||
serverUUID = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "";
|
||||
description = "UUID for the Rundeck server (automatically generated if not specified)";
|
||||
};
|
||||
|
||||
dataDir = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "/var/lib/rundeck";
|
||||
description = "Directory for Rundeck runtime data (RDECK_BASE)";
|
||||
};
|
||||
|
||||
configDir = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
default = "/etc/rundeck";
|
||||
description = "Directory for Rundeck configuration files";
|
||||
};
|
||||
|
||||
javaOpts = lib.mkOption {
|
||||
type = lib.types.listOf lib.types.str;
|
||||
default = [
|
||||
"-Xmx1024m"
|
||||
"-Xms256m"
|
||||
"-XX:MaxMetaspaceSize=256m"
|
||||
"-server"
|
||||
];
|
||||
description = "Additional Java options for Rundeck";
|
||||
};
|
||||
|
||||
aclPolicies = lib.mkOption {
|
||||
type = lib.types.attrsOf lib.types.str;
|
||||
default = { };
|
||||
description = "ACL policies for Rundeck, where the attribute name is the filename and the value is the policy content";
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
"admin.aclpolicy" = '''
|
||||
description: Admin access for administrators
|
||||
context:
|
||||
project: '.*'
|
||||
for:
|
||||
resource:
|
||||
- allow: '*'
|
||||
job:
|
||||
- allow: '*'
|
||||
node:
|
||||
- allow: '*'
|
||||
by:
|
||||
group: admin
|
||||
---
|
||||
description: Admin access in application scope
|
||||
context:
|
||||
application: 'rundeck'
|
||||
for:
|
||||
resource:
|
||||
- allow: '*'
|
||||
project:
|
||||
- allow: '*'
|
||||
by:
|
||||
group: admin
|
||||
''';
|
||||
}
|
||||
'';
|
||||
};
|
||||
|
||||
sshKeyType = lib.mkOption {
|
||||
type = lib.types.enum [
|
||||
"rsa"
|
||||
"ed25519"
|
||||
];
|
||||
default = "rsa";
|
||||
description = "Type of SSH key to generate (rsa for compatibility, ed25519 for better security)";
|
||||
};
|
||||
|
||||
openFirewall = lib.mkOption {
|
||||
type = lib.types.bool;
|
||||
default = false;
|
||||
description = "Whether to open the Rundeck port in the firewall";
|
||||
};
|
||||
|
||||
startTimeout = lib.mkOption {
|
||||
type = lib.types.int;
|
||||
default = 180;
|
||||
description = "Timeout in seconds before systemd considers the service startup as failed";
|
||||
example = 120;
|
||||
};
|
||||
|
||||
database = {
|
||||
type = lib.mkOption {
|
||||
type = lib.types.enum [
|
||||
"h2"
|
||||
"postgresql"
|
||||
"mysql"
|
||||
];
|
||||
default = "h2";
|
||||
description = "Database type to use (h2, postgresql, or mysql)";
|
||||
};
|
||||
|
||||
host = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "localhost";
|
||||
description = "Database host";
|
||||
};
|
||||
|
||||
port = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.port;
|
||||
default =
|
||||
if cfg.database.type == "postgresql" then
|
||||
5432
|
||||
else if cfg.database.type == "mysql" then
|
||||
3306
|
||||
else
|
||||
null;
|
||||
defaultText = lib.literalExpression ''
|
||||
if config.services.rundeck.database.type == "postgresql" then
|
||||
5432
|
||||
else if config.services.rundeck.database.type == "mysql" then
|
||||
3306
|
||||
else
|
||||
null
|
||||
'';
|
||||
description = "Database port (defaults: PostgreSQL: 5432, MySQL: 3306)";
|
||||
};
|
||||
|
||||
name = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "rundeck";
|
||||
description = "Database name";
|
||||
};
|
||||
|
||||
username = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "rundeck";
|
||||
description = "Database username";
|
||||
};
|
||||
|
||||
passwordFile = lib.mkOption {
|
||||
type = lib.types.nullOr lib.types.path;
|
||||
default = null;
|
||||
description = "Path to a file containing the database password";
|
||||
example = "/run/secrets/rundeck-db-password";
|
||||
};
|
||||
};
|
||||
|
||||
settings = lib.mkOption {
|
||||
type = lib.types.submodule {
|
||||
freeformType = settingsFormat.type;
|
||||
};
|
||||
default = { };
|
||||
description = ''
|
||||
Configuration written to `rundeck-config.properties`.
|
||||
See <https://docs.rundeck.com/docs/administration/configuration/config-file-reference.html>
|
||||
for available options.
|
||||
|
||||
Secrets must not be set here, as this ends up world-readable in the Nix
|
||||
store. Use the dedicated `*File` options instead.
|
||||
'';
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
"rundeck.feature.repository.enabled" = "true";
|
||||
"rundeck.projectsStorageType" = "db";
|
||||
"rundeck.gui.title" = "My Rundeck Instance";
|
||||
"rdeck.security.useHMacRequestTokens" = "true";
|
||||
"rundeck.web.jetty.servlet.MaxFormKeys" = "2000";
|
||||
}
|
||||
'';
|
||||
};
|
||||
|
||||
frameworkSettings = lib.mkOption {
|
||||
type = lib.types.submodule {
|
||||
freeformType = settingsFormat.type;
|
||||
};
|
||||
default = { };
|
||||
description = ''
|
||||
Configuration written to `framework.properties`.
|
||||
See <https://docs.rundeck.com/docs/administration/configuration/config-file-reference.html>
|
||||
for available options.
|
||||
'';
|
||||
example = lib.literalExpression ''
|
||||
{
|
||||
"framework.ssh.timeout" = "120";
|
||||
"framework.ssh.user" = "deploy";
|
||||
}
|
||||
'';
|
||||
};
|
||||
|
||||
ssl = {
|
||||
enable = lib.mkEnableOption "SSL support";
|
||||
|
||||
port = lib.mkOption {
|
||||
type = lib.types.port;
|
||||
default = 4443;
|
||||
description = "Port on which Rundeck will listen for HTTPS when ssl.enable is true";
|
||||
};
|
||||
|
||||
keyStore = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
example = "/etc/rundeck/ssl/keystore";
|
||||
description = "Path to the keystore containing the SSL certificate";
|
||||
};
|
||||
|
||||
keyStorePasswordFile = lib.mkOption {
|
||||
type = lib.types.path;
|
||||
description = "Path to a file containing the SSL keystore password";
|
||||
example = "/run/secrets/rundeck-keystore-password";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
|
||||
assertions = [
|
||||
{
|
||||
assertion =
|
||||
cfg.database.type == "h2"
|
||||
|| (cfg.database.host != "" && cfg.database.username != "" && cfg.database.passwordFile != null);
|
||||
message = "When using external database (PostgreSQL/MySQL), host, username, and passwordFile must be provided";
|
||||
}
|
||||
{
|
||||
assertion = cfg.database.type == "h2" || cfg.database.port != null;
|
||||
message = "Database port must be set when using an external database";
|
||||
}
|
||||
];
|
||||
|
||||
services.rundeck.settings = {
|
||||
"server.address" = lib.mkDefault "0.0.0.0";
|
||||
"server.port" = lib.mkDefault (toString cfg.serverPort);
|
||||
"grails.serverURL" = lib.mkDefault cfg.serverURL;
|
||||
"logging.config" = lib.mkDefault "${cfg.configDir}/log4j2.properties";
|
||||
"dataSource.url" = lib.mkDefault (
|
||||
if cfg.database.type == "h2" then
|
||||
"jdbc:h2:file:${cfg.dataDir}/data/rundeckdb;DB_CLOSE_ON_EXIT=FALSE;NON_KEYWORDS=MONTH,HOUR,MINUTE,YEAR,SECONDS"
|
||||
else if cfg.database.type == "postgresql" then
|
||||
"jdbc:postgresql://${cfg.database.host}:${toString cfg.database.port}/${cfg.database.name}"
|
||||
else
|
||||
"jdbc:mysql://${cfg.database.host}:${toString cfg.database.port}/${cfg.database.name}?autoReconnect=true&useSSL=false"
|
||||
);
|
||||
"dataSource.driverClassName" = lib.mkDefault (
|
||||
if cfg.database.type == "h2" then
|
||||
"org.h2.Driver"
|
||||
else if cfg.database.type == "postgresql" then
|
||||
"org.postgresql.Driver"
|
||||
else
|
||||
"org.mariadb.jdbc.Driver"
|
||||
);
|
||||
"dataSource.username" = lib.mkDefault cfg.database.username;
|
||||
}
|
||||
// lib.optionalAttrs (cfg.database.passwordFile != null) {
|
||||
"dataSource.password" = lib.mkDefault "@DB_PASSWORD@";
|
||||
}
|
||||
// lib.optionalAttrs (cfg.database.type == "h2") {
|
||||
"dataSource.dialect" = lib.mkDefault "org.hibernate.dialect.H2Dialect";
|
||||
}
|
||||
// lib.optionalAttrs (cfg.database.type == "mysql") {
|
||||
"dataSource.dialect" = lib.mkDefault "org.hibernate.dialect.MariaDB103Dialect";
|
||||
}
|
||||
// lib.optionalAttrs cfg.ssl.enable {
|
||||
"server.https.port" = lib.mkDefault (toString cfg.ssl.port);
|
||||
"server.ssl.keyStore" = lib.mkDefault (toString cfg.ssl.keyStore);
|
||||
"server.ssl.keyStorePassword" = lib.mkDefault "@KEYSTORE_PASSWORD@";
|
||||
};
|
||||
|
||||
services.rundeck.frameworkSettings = {
|
||||
"framework.server.name" = lib.mkDefault cfg.serverHostname;
|
||||
"framework.server.hostname" = lib.mkDefault cfg.serverHostname;
|
||||
"framework.server.port" = lib.mkDefault (toString effectivePort);
|
||||
"framework.server.url" = lib.mkDefault cfg.serverURL;
|
||||
"framework.ssh.keypath" = lib.mkDefault "${cfg.dataDir}/.ssh/id_${cfg.sshKeyType}";
|
||||
"framework.ssh.user" = lib.mkDefault cfg.user;
|
||||
"framework.ssh.timeout" = lib.mkDefault "60";
|
||||
"rdeck.base" = cfg.dataDir;
|
||||
"framework.projects.dir" = "${cfg.dataDir}/projects";
|
||||
"framework.etc.dir" = toString cfg.configDir;
|
||||
"framework.var.dir" = "${cfg.dataDir}/var";
|
||||
"framework.tmp.dir" = "${cfg.dataDir}/var/tmp";
|
||||
"framework.logs.dir" = "${cfg.dataDir}/var/logs";
|
||||
"framework.libext.dir" = "${cfg.dataDir}/libext";
|
||||
"rundeck.server.uuid" = if cfg.serverUUID != "" then cfg.serverUUID else "@SERVER_UUID@";
|
||||
};
|
||||
|
||||
users.users.${cfg.user} = {
|
||||
isSystemUser = true;
|
||||
group = cfg.group;
|
||||
home = cfg.dataDir;
|
||||
createHome = true;
|
||||
};
|
||||
|
||||
users.groups.${cfg.group} = { };
|
||||
|
||||
systemd.tmpfiles.settings."10-rundeck" = {
|
||||
"${cfg.dataDir}" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.dataDir}/etc" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.dataDir}/data" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.dataDir}/projects" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.dataDir}/libext" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.dataDir}/var" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.dataDir}/var/logs" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.dataDir}/var/tmp" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.dataDir}/.ssh" = {
|
||||
d = {
|
||||
mode = "0700";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.configDir}" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"${cfg.configDir}/ssl" = {
|
||||
d = {
|
||||
mode = "0750";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
};
|
||||
};
|
||||
|
||||
"/var/log/rundeck" = {
|
||||
L = {
|
||||
argument = "${cfg.dataDir}/var/logs";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
environment.etc."rundeck/jaas-loginmodule.conf" = {
|
||||
mode = "0640";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
text = ''
|
||||
RDpropertyfilelogin {
|
||||
org.eclipse.jetty.jaas.spi.PropertyFileLoginModule required
|
||||
debug="true"
|
||||
file="/etc/rundeck/realm.properties";
|
||||
};
|
||||
'';
|
||||
};
|
||||
|
||||
environment.etc."rundeck/log4j2.properties" = {
|
||||
mode = "0640";
|
||||
user = cfg.user;
|
||||
group = cfg.group;
|
||||
text = ''
|
||||
status = info
|
||||
name = RundeckPro
|
||||
|
||||
appender.console.type = Console
|
||||
appender.console.name = STDOUT
|
||||
appender.console.layout.type = PatternLayout
|
||||
appender.console.layout.pattern = %d{DEFAULT} %-5p %c{1} - %m%n
|
||||
|
||||
appender.file.type = RollingFile
|
||||
appender.file.name = FILE
|
||||
appender.file.fileName = ${cfg.dataDir}/var/logs/rundeck.log
|
||||
appender.file.filePattern = ${cfg.dataDir}/var/logs/rundeck.%d{yyyy-MM-dd}.log
|
||||
appender.file.layout.type = PatternLayout
|
||||
appender.file.layout.pattern = %d{DEFAULT} [%t] %-5p %c{1} - %m%n
|
||||
appender.file.policies.type = Policies
|
||||
appender.file.policies.time.type = TimeBasedTriggeringPolicy
|
||||
appender.file.policies.time.interval = 1
|
||||
appender.file.policies.time.modulate = true
|
||||
|
||||
rootLogger.level = info
|
||||
rootLogger.appenderRef.stdout.ref = STDOUT
|
||||
rootLogger.appenderRef.file.ref = FILE
|
||||
|
||||
logger.hibernate.name = org.hibernate
|
||||
logger.hibernate.level = ERROR
|
||||
'';
|
||||
};
|
||||
|
||||
systemd.services.rundeck = {
|
||||
description = "Rundeck Service";
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
after = [
|
||||
"network.target"
|
||||
]
|
||||
++ lib.optional (cfg.database.type == "mysql") "mysql.service"
|
||||
++ lib.optional (cfg.database.type == "postgresql") "postgresql.service";
|
||||
wants =
|
||||
lib.optional (cfg.database.type == "mysql") "mysql.service"
|
||||
++ lib.optional (cfg.database.type == "postgresql") "postgresql.service";
|
||||
|
||||
environment = {
|
||||
RDECK_BASE = cfg.dataDir;
|
||||
RUNDECK_CONFIG_DIR = cfg.configDir;
|
||||
JAVA_OPTS = lib.concatStringsSep " " cfg.javaOpts;
|
||||
};
|
||||
|
||||
path = [ pkgs.replace-secret ];
|
||||
|
||||
serviceConfig = {
|
||||
User = cfg.user;
|
||||
Group = cfg.group;
|
||||
ExecStart = rundeckStartScript;
|
||||
WorkingDirectory = cfg.dataDir;
|
||||
RuntimeDirectory = "rundeck";
|
||||
RuntimeDirectoryMode = "0750";
|
||||
UMask = "0027";
|
||||
|
||||
LimitNOFILE = 65536;
|
||||
ReadWritePaths = [
|
||||
cfg.dataDir
|
||||
cfg.configDir
|
||||
];
|
||||
RestartSec = "10s";
|
||||
Restart = "always";
|
||||
TimeoutStartSec = "${toString cfg.startTimeout}s";
|
||||
|
||||
CapabilityBoundingSet = [ "CAP_SYS_ADMIN" ];
|
||||
AmbientCapabilities = [ "CAP_SYS_ADMIN" ];
|
||||
|
||||
LimitCORE = 0;
|
||||
LockPersonality = true;
|
||||
MemorySwapMax = 0;
|
||||
MemoryZSwapMax = 0;
|
||||
PrivateDevices = true;
|
||||
PrivateTmp = true;
|
||||
ProtectClock = true;
|
||||
ProtectControlGroups = true;
|
||||
ProtectHome = true;
|
||||
ProtectHostname = true;
|
||||
ProtectKernelLogs = true;
|
||||
ProtectKernelModules = true;
|
||||
ProtectKernelTunables = true;
|
||||
ProtectProc = "invisible";
|
||||
RemoveIPC = true;
|
||||
RestrictAddressFamilies = [
|
||||
"AF_UNIX"
|
||||
"AF_INET"
|
||||
"AF_INET6"
|
||||
"AF_NETLINK"
|
||||
];
|
||||
RestrictNamespaces = true;
|
||||
RestrictRealtime = true;
|
||||
RestrictSUIDSGID = true;
|
||||
SystemCallArchitectures = "native";
|
||||
};
|
||||
|
||||
preStart = ''
|
||||
${lib.optionalString (cfg.serverUUID == "") ''
|
||||
# Generate UUID
|
||||
UUID_FILE="${cfg.dataDir}/.uuid"
|
||||
if [ ! -f "$UUID_FILE" ]; then
|
||||
umask 0137
|
||||
${lib.getExe' pkgs.util-linux "uuidgen"} > "$UUID_FILE"
|
||||
fi
|
||||
''}
|
||||
|
||||
|
||||
install -m 0640 ${configFile} ${cfg.configDir}/rundeck-config.properties
|
||||
install -m 0640 ${frameworkFile} ${cfg.configDir}/framework.properties
|
||||
install -m 0600 ${realmFile} ${cfg.configDir}/realm.properties
|
||||
|
||||
${replaceSecret "@ADMIN_PASSWORD@" cfg.adminPasswordFile "${cfg.configDir}/realm.properties"}
|
||||
|
||||
${lib.optionalString (cfg.database.passwordFile != null) (
|
||||
replaceSecret "@DB_PASSWORD@" cfg.database.passwordFile "${cfg.configDir}/rundeck-config.properties"
|
||||
)}
|
||||
|
||||
${lib.optionalString cfg.ssl.enable (
|
||||
replaceSecret "@KEYSTORE_PASSWORD@" cfg.ssl.keyStorePasswordFile
|
||||
"${cfg.configDir}/rundeck-config.properties"
|
||||
)}
|
||||
|
||||
${lib.optionalString (cfg.serverUUID == "") (
|
||||
replaceSecret "@SERVER_UUID@" "${cfg.dataDir}/.uuid" "${cfg.configDir}/framework.properties"
|
||||
)}
|
||||
|
||||
if [ -f ${cfg.dataDir}/etc/framework.properties ]; then
|
||||
install -m 0640 ${cfg.configDir}/framework.properties ${cfg.dataDir}/etc/framework.properties
|
||||
fi
|
||||
|
||||
${lib.concatStringsSep "\n" (
|
||||
lib.mapAttrsToList (
|
||||
name: content:
|
||||
"install -m 0640 ${pkgs.writeText "rundeck-${name}" content} ${cfg.dataDir}/etc/${name}"
|
||||
) cfg.aclPolicies
|
||||
)}
|
||||
'';
|
||||
};
|
||||
|
||||
networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [
|
||||
(if cfg.ssl.enable then cfg.ssl.port else cfg.serverPort)
|
||||
];
|
||||
};
|
||||
}
|
||||
@@ -145,7 +145,7 @@ in
|
||||
|
||||
serviceConfig = {
|
||||
DynamicUser = true;
|
||||
ExecStart = "${lib.getExe cfg.package} serve";
|
||||
ExecStart = lib.getExe cfg.package;
|
||||
EnvironmentFile = cfg.environmentFiles;
|
||||
Restart = "on-failure";
|
||||
StateDirectory = "rustical";
|
||||
|
||||
@@ -398,11 +398,6 @@ let
|
||||
|
||||
hostListen = if vhost.forceSSL then filter (x: x.ssl) defaultListen else defaultListen;
|
||||
|
||||
# If there's any location setting `useGrpcErrorPages`, we need to add the location blocks.
|
||||
locationsWantGrpcErrorPages = builtins.any (location: location.useGrpcErrorPages) (
|
||||
attrValues vhost.locations
|
||||
);
|
||||
|
||||
listenString =
|
||||
{
|
||||
addr,
|
||||
@@ -520,10 +515,6 @@ let
|
||||
|
||||
${mkBasicAuth vhostName vhost}
|
||||
|
||||
${optionalString locationsWantGrpcErrorPages ''
|
||||
include ${./grpc-locations.conf};
|
||||
''}
|
||||
|
||||
${optionalString (vhost.root != null) "root ${vhost.root};"}
|
||||
|
||||
${optionalString (vhost.globalRedirect != null) ''
|
||||
@@ -568,9 +559,6 @@ let
|
||||
optionalAttrs (config.fastcgiParams != { }) (defaultFastcgiParams // config.fastcgiParams)
|
||||
)
|
||||
)}
|
||||
${optionalString config.useGrpcErrorPages ''
|
||||
include ${./grpc-error-pages.conf};
|
||||
''}
|
||||
${optionalString (config.index != null) "index ${config.index};"}
|
||||
${optionalString (config.tryFiles != null) "try_files ${config.tryFiles};"}
|
||||
${optionalString (config.root != null) "root ${config.root};"}
|
||||
|
||||
@@ -1,22 +0,0 @@
|
||||
error_page 400 = @grpc_internal;
|
||||
error_page 401 = @grpc_unauthenticated;
|
||||
error_page 403 = @grpc_permission_denied;
|
||||
error_page 404 = @grpc_unimplemented;
|
||||
error_page 429 = @grpc_unavailable;
|
||||
error_page 502 = @grpc_unavailable;
|
||||
error_page 503 = @grpc_unavailable;
|
||||
error_page 504 = @grpc_unavailable;
|
||||
# NGINX-to-gRPC status code mappings
|
||||
# Ref: https://github.com/grpc/grpc/blob/master/doc/statuscodes.md
|
||||
#
|
||||
error_page 405 = @grpc_internal; # Method not allowed
|
||||
error_page 408 = @grpc_deadline_exceeded; # Request timeout
|
||||
error_page 413 = @grpc_resource_exhausted; # Payload too large
|
||||
error_page 414 = @grpc_resource_exhausted; # Request URI too large
|
||||
error_page 415 = @grpc_internal; # Unsupported media type;
|
||||
error_page 426 = @grpc_internal; # HTTP request was sent to HTTPS port
|
||||
error_page 495 = @grpc_unauthenticated; # Client certificate authentication error
|
||||
error_page 496 = @grpc_unauthenticated; # Client certificate not presented
|
||||
error_page 497 = @grpc_internal; # HTTP request was sent to mutual TLS port
|
||||
error_page 500 = @grpc_internal; # Server error
|
||||
error_page 501 = @grpc_internal; # Not implemented
|
||||
@@ -1,46 +0,0 @@
|
||||
# gRPC error responses
|
||||
# Ref: https://github.com/grpc/grpc-go/blob/master/codes/codes.go
|
||||
# Ref: https://grpc.io/docs/guides/wire
|
||||
#
|
||||
location @grpc_deadline_exceeded {
|
||||
add_header grpc-status 4;
|
||||
add_header grpc-message 'deadline exceeded';
|
||||
default_type application/grpc;
|
||||
return 200;
|
||||
}
|
||||
location @grpc_permission_denied {
|
||||
add_header grpc-status 7;
|
||||
add_header grpc-message 'permission denied';
|
||||
default_type application/grpc;
|
||||
return 200;
|
||||
}
|
||||
location @grpc_resource_exhausted {
|
||||
add_header grpc-status 8;
|
||||
add_header grpc-message 'resource exhausted';
|
||||
default_type application/grpc;
|
||||
return 200;
|
||||
}
|
||||
location @grpc_unimplemented {
|
||||
add_header grpc-status 12;
|
||||
add_header grpc-message unimplemented;
|
||||
default_type application/grpc;
|
||||
return 200;
|
||||
}
|
||||
location @grpc_internal {
|
||||
add_header grpc-status 13;
|
||||
add_header grpc-message 'internal error';
|
||||
default_type application/grpc;
|
||||
return 200;
|
||||
}
|
||||
location @grpc_unavailable {
|
||||
add_header grpc-status 14;
|
||||
add_header grpc-message unavailable;
|
||||
default_type application/grpc;
|
||||
return 200;
|
||||
}
|
||||
location @grpc_unauthenticated {
|
||||
add_header grpc-status 16;
|
||||
add_header grpc-message unauthenticated;
|
||||
default_type application/grpc;
|
||||
return 200;
|
||||
}
|
||||
@@ -158,17 +158,5 @@ with lib;
|
||||
Enable recommended uwsgi settings.
|
||||
'';
|
||||
};
|
||||
|
||||
useGrpcErrorPages = mkOption {
|
||||
type = types.bool;
|
||||
default = false;
|
||||
description = ''
|
||||
Whether to configure error codes to be emitted as gRPC-compatible errors.
|
||||
|
||||
Should be set when proxying gRPC, and returning responses from nginx (like when adding authentication).
|
||||
|
||||
This defines a few `@grpc-*` locations inside the containing vhost.
|
||||
'';
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -200,7 +200,6 @@ in
|
||||
AmbientCapabilities = "cap_net_bind_service";
|
||||
NoNewPrivileges = true;
|
||||
LimitNOFILE = 131072;
|
||||
LimitMEMLOCK = "infinity";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user