kyouma-net/flake.nix

141 lines
4.9 KiB
Nix
Raw Normal View History

2024-01-12 14:04:38 +01:00
{
description = "kyouma.net website";
inputs.nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
inputs.flake-utils.url = "github:numtide/flake-utils";
outputs = { self, nixpkgs, flake-utils }:
flake-utils.lib.eachDefaultSystem (system: let
pkgs = nixpkgs.legacyPackages.${system};
in rec {
2024-01-12 16:53:30 +01:00
packages.vid = pkgs.stdenv.mkDerivation {
name = "kyouma-www-vid";
src = ./.;
buildInputs = [ pkgs.yt-dlp ];
buildPhase = ''
yt-dlp -f 136+251 C4oApBlw7Gc --merge-output-format mp4 -o "media/sunnyday-avc.mp4"
yt-dlp -f 398+251 C4oApBlw7Gc --merge-output-format mp4 -o "media/sunnyday-av1.mp4"
'';
installPhase = ''cp -r media $out'';
outputHashMode = "recursive";
outputHashAlgo = "sha256";
outputHash = "abrls86wyBJaZN3QM/p8fRoGQ7jVseao3F4oiMPh+84=";
};
2024-01-12 14:04:38 +01:00
packages.kyouma-www = pkgs.stdenv.mkDerivation {
pname = "kyouma-www";
version = self.shortRev or (toString self.lastModifiedDate);
src = ./.;
2024-01-15 16:57:10 +01:00
buildPhase = '''';
2024-01-12 14:04:38 +01:00
installPhase = ''cp -r src $out'';
};
packages.default = packages.kyouma-www;
2024-01-15 16:57:10 +01:00
nixosModules.default =
2024-01-16 12:58:23 +01:00
{ config, options, pkgs, lib, ... }: with lib;
2024-01-15 16:57:10 +01:00
let
cfg = config.services.vyosBld;
2024-01-15 21:00:21 +01:00
bldFlags = (attrsets.mapAttrsToList (flag: opt: "--" + flag + " " + opt) cfg.buildFlags);
2024-01-15 16:57:10 +01:00
in {
2024-01-15 21:00:21 +01:00
options.services.vyosBld = {
2024-01-15 16:57:10 +01:00
enable = mkEnableOption "VyOS automatic build";
output = mkOption {
type = types.str;
default = null;
2024-01-15 21:00:21 +01:00
description = "Where the iso should be copied";
2024-01-15 16:57:10 +01:00
};
keep = mkOption {
type = types.number;
default = 5;
description = "Amount of versions to keep";
};
buildFreq = mkOption {
type = types.str;
default = "*-*-* 4:20:00";
description = "How often a new Image should be build. See {manpage}`systemd.timer(5)`";
};
flavor = mkOption {
type = types.str;
default = "iso";
description = "See VyOS build docs";
};
buildFlags = mkOption {
2024-01-15 21:00:21 +01:00
type = types.attrs;
2024-01-15 16:57:10 +01:00
default = "";
description = "Build Flags see https://docs.vyos.io/en/latest/contributing/build-vyos.html
example:
{ build-by = 'mail@server.tld' }";
};
};
2024-01-16 12:58:23 +01:00
config = with lib; mkIf cfg.enable {
users = {
users.vyos-bld = {
isSystemUser = true;
group = "vyos-bld";
};
groups.vyos-bld = {};
};
virtualisation.docker = {
daemon.settings = {
ipv6 = true;
fixed-cidr-v6 = "fd00::/80";
};
autoPrune = {
enable = true;
flags = [ "--all" "--filter until=24h" ];
};
rootless = {
enable = true;
setSocketVariable = true;
};
};
networking.firewall.extraCommands = ''ip6tables -t nat -A POSTROUTING -s fd00::/80 ! -o docker0 -j MASQUERADE'';
cfg.bldScript = pkgs.writeShellScrip "build-vyos" ''
2024-01-15 21:00:21 +01:00
cleanup() {
rmdir "$root"
}
root="$(mktemp -d)"
trap cleanup EXIT
iso_name="vyos-${cfg.buildFlags.version}-${cfg.buildFlags.architecture}.iso"
bld_dir="$root/vyos-build"
2024-01-16 12:58:23 +01:00
docker_cmd="${pkgs.docker}/bin/docker run --rm -it --privileged -v $bld_dir:/vyos -w /vyos vyos/vyos-build:current"
2024-01-15 21:00:21 +01:00
git clone -b current --single-branch https://github.com/vyos/vyos-build $root
2024-01-16 12:58:23 +01:00
$docker_cmd sudo ./build-vyos-image ${flavor} ${builtins.concatStringsSep " " bldFlags}
$docker_cmd sudo chown -R ${config.users.users.vyos-bld.uid}:${config.users.groups.vyos-bld.gid} /vyos
2024-01-15 21:00:21 +01:00
cp $bld_dir/build/$iso_name ${cfg.output}
2024-01-16 12:58:23 +01:00
mapfile -t old_isos < <(ls ${cfg.output} | head -n -${builtins.toString cfg.keep})
2024-01-15 21:00:21 +01:00
for i in $\{old_isos[@]}; do
rm -r ${cfg.output}/$\{old_iso[$i]}
done
'';
2024-01-16 12:58:23 +01:00
systemd = {
services.docker.after = [ "firewall.service" ];
services.vyosBld = {
serviceConfig = {
User = "vyos-bld";
Group = "vyos-bld";
ExecStart = cfg.bldScript;
2024-01-15 21:00:21 +01:00
2024-01-16 12:58:23 +01:00
PrivateTmp = true;
ProtectHome = true;
};
2024-01-15 16:57:10 +01:00
};
2024-01-16 12:58:23 +01:00
timers.vyosBld = {
wantedBy = [ "timers.target" ];
timerConfig = {
OnCalendar = cfg.buildFreq;
};
2024-01-15 16:57:10 +01:00
};
};
};
2024-01-16 12:58:23 +01:00
}
2024-01-15 16:57:10 +01:00
;
2024-01-12 14:04:38 +01:00
});
}