diff --git a/.webhook_bridge/pipeline-build-homepage-staging.yaml b/.webhook_bridge/pipeline-build-homepage-staging.yaml index 5acb097..206f49c 100644 --- a/.webhook_bridge/pipeline-build-homepage-staging.yaml +++ b/.webhook_bridge/pipeline-build-homepage-staging.yaml @@ -121,7 +121,7 @@ spec: - name: url value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git - name: revision - value: af22c87d0db59dece97d03e6b6a796d84010158f + value: 7d4b33528fef5f2e662d32d093566ce56eb4acd0 - name: pathInRepo value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml params: @@ -142,6 +142,9 @@ spec: - "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true" - --opt - build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time) + - --secret + - id=cache_token,src=/workspace/nix-cache-creds/CACHE_GET_TOKEN + # - id=cache_token,env=MY_ENV_TOKEN - name: BUILDKITD_TOML value: | debug = true @@ -155,6 +158,8 @@ spec: workspace: git-source - name: dockerconfig workspace: docker-credentials + - name: nix-cache-creds + workspace: nix-cache-creds runAfter: - fetch-repository finally: @@ -219,6 +224,7 @@ spec: workspaces: - name: git-source - name: docker-credentials + - name: nix-cache-creds workspaces: - name: git-source volumeClaimTemplate: @@ -233,6 +239,9 @@ spec: - name: docker-credentials secret: secretName: harbor-plain + - name: nix-cache-creds + secret: + secretName: nix-pull-through-cache params: - name: image-name value: "harbor.fizz.buzz/private/homepage-staging" diff --git a/docker/server/Dockerfile b/docker/server/Dockerfile index 675a197..ea12a46 100644 --- a/docker/server/Dockerfile +++ b/docker/server/Dockerfile @@ -10,39 +10,42 @@ filter-syscalls = false substituters = http://ncps.nix-pull-through-cache.svc.cluster.local:80 https://cache.nixos.org EOF -RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" cp "$(nix build nixpkgs#cacert --print-out-paths)/etc/ssl/certs/ca-bundle.crt" /tmp/ca-bundle.crt +RUN --mount=type=secret,id=cache_token echo "list" && find /run +RUN --mount=type=secret,id=cache_token echo "secret:" && cat /run/secrets/cache_token && echo "endsecret" -COPY . /tmp/build -WORKDIR /tmp/build +# RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" cp "$(nix build nixpkgs#cacert --print-out-paths)/etc/ssl/certs/ca-bundle.crt" /tmp/ca-bundle.crt -RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" nix build '.#docker_env' +# COPY . /tmp/build +# WORKDIR /tmp/build -# Export the built closure to a folder -RUN mkdir /tmp/nix-store-closure -RUN cp -R $(nix-store -qR result/) /tmp/nix-store-closure -RUN ln -s $(readlink -f /tmp/build/result/bin/sh) /tmp/sh +# RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" nix build '.#docker_env' + +# # Export the built closure to a folder +# RUN mkdir /tmp/nix-store-closure +# RUN cp -R $(nix-store -qR result/) /tmp/nix-store-closure +# RUN ln -s $(readlink -f /tmp/build/result/bin/sh) /tmp/sh -# -# Runner -# +# # +# # Runner +# # -FROM scratch +# FROM scratch -WORKDIR /app +# WORKDIR /app -ENV PATH="$PATH:/app/bin" +# ENV PATH="$PATH:/app/bin" -ENV SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt -ENV NIX_SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt -COPY --from=builder /tmp/ca-bundle.crt /etc/ssl/certs/ca-bundle.crt +# ENV SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt +# ENV NIX_SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt +# COPY --from=builder /tmp/ca-bundle.crt /etc/ssl/certs/ca-bundle.crt -COPY --from=builder /tmp/nix-store-closure /nix/store -COPY --from=builder /tmp/build/result /app -COPY --from=builder /tmp/sh /bin/sh -EXPOSE 8080 -#RUN addgroup web && adduser -D -G web web -#&& install -d -D -o web -g web -m 700 /srv/http/public -# RUN ln -sf /dev/stdout /var/log/nginx/access.log && ln -sf /dev/stderr /var/log/nginx/error.log -CMD ["/app/bin/launch_nginx"] +# COPY --from=builder /tmp/nix-store-closure /nix/store +# COPY --from=builder /tmp/build/result /app +# COPY --from=builder /tmp/sh /bin/sh +# EXPOSE 8080 +# #RUN addgroup web && adduser -D -G web web +# #&& install -d -D -o web -g web -m 700 /srv/http/public +# # RUN ln -sf /dev/stdout /var/log/nginx/access.log && ln -sf /dev/stderr /var/log/nginx/error.log +# CMD ["/app/bin/launch_nginx"]