Files
nixpkgs/pkgs/by-name/fl/fluxcd/update.sh
leigh capili 289b7b1f42 fluxcd: rewrite update script to use nix-update
The previous script extracted the Go vendor hash by setting a fake
hash, running nix-build, and grep-parsing "got:" from stderr. This
can fail when the Nix error output format differs across environments,
as seen on r-ryantm's infrastructure since the 2.8.x transition.

Replace with nix-update for version, src hash, and vendor hash.
Retain manual handling of manifestsHash (a second fetchzip artifact
that nix-update cannot manage).

Similar to: adguardhome, helix, perses, viddy update scripts.
2026-05-01 21:53:09 -06:00

22 lines
1.0 KiB
Bash
Executable File

#!/usr/bin/env nix-shell
#!nix-shell -i bash -p gnused nix-update
set -eu -o pipefail
set -x
# Compute the relative dir of the update script
SCRIPT_DIR="$(cd -- "$(dirname "$0")" >/dev/null 2>&1; pwd -P)"
# Update version, src hash, and vendor hash
nix-update fluxcd
# Read the potentially updated version from `nix-update fluxcd` using SCRIPT_DIR
VERSION=$(sed -n 's/.*version = "\(.*\)".*/\1/p' "${SCRIPT_DIR}/package.nix" | head -1)
# Update the additional fluxcd manifests hash
# This is idempotent and will run regardless of whether nix-update changes the package.nix version
# note: tag format is assumed to be v${VERSION} which matches the fetchZip in package.nix
MANIFESTS_SHA256=$(nix-prefetch-url --quiet --unpack "https://github.com/fluxcd/flux2/releases/download/v${VERSION}/manifests.tar.gz")
MANIFESTS_HASH=$(nix --extra-experimental-features nix-command hash convert --hash-algo sha256 --to sri "$MANIFESTS_SHA256")
sed -i "s|manifestsHash = \".*\"|manifestsHash = \"${MANIFESTS_HASH}\"|" "${SCRIPT_DIR}/package.nix"