auth
Some checks failed
build-staging Build build-staging has failed

This commit is contained in:
Tom Alexander
2026-07-13 18:33:54 -04:00
parent 40b81b715c
commit 854715be0f
2 changed files with 38 additions and 26 deletions

View File

@@ -121,7 +121,7 @@ spec:
- name: url
value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git
- name: revision
value: af22c87d0db59dece97d03e6b6a796d84010158f
value: 7d4b33528fef5f2e662d32d093566ce56eb4acd0
- name: pathInRepo
value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml
params:
@@ -142,6 +142,9 @@ spec:
- "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true"
- --opt
- build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time)
- --secret
- id=cache_token,src=/workspace/nix-cache-creds/CACHE_GET_TOKEN
# - id=cache_token,env=MY_ENV_TOKEN
- name: BUILDKITD_TOML
value: |
debug = true
@@ -155,6 +158,8 @@ spec:
workspace: git-source
- name: dockerconfig
workspace: docker-credentials
- name: nix-cache-creds
workspace: nix-cache-creds
runAfter:
- fetch-repository
finally:
@@ -219,6 +224,7 @@ spec:
workspaces:
- name: git-source
- name: docker-credentials
- name: nix-cache-creds
workspaces:
- name: git-source
volumeClaimTemplate:
@@ -233,6 +239,9 @@ spec:
- name: docker-credentials
secret:
secretName: harbor-plain
- name: nix-cache-creds
secret:
secretName: nix-pull-through-cache
params:
- name: image-name
value: "harbor.fizz.buzz/private/homepage-staging"

View File

@@ -10,39 +10,42 @@ filter-syscalls = false
substituters = http://ncps.nix-pull-through-cache.svc.cluster.local:80 https://cache.nixos.org
EOF
RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" cp "$(nix build nixpkgs#cacert --print-out-paths)/etc/ssl/certs/ca-bundle.crt" /tmp/ca-bundle.crt
RUN --mount=type=secret,id=cache_token find /run
RUN --mount=type=secret,id=cache_token echo "secret:" && cat /run/secrets/cache_token echo "endsecret"
COPY . /tmp/build
WORKDIR /tmp/build
# RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" cp "$(nix build nixpkgs#cacert --print-out-paths)/etc/ssl/certs/ca-bundle.crt" /tmp/ca-bundle.crt
RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" nix build '.#docker_env'
# COPY . /tmp/build
# WORKDIR /tmp/build
# Export the built closure to a folder
RUN mkdir /tmp/nix-store-closure
RUN cp -R $(nix-store -qR result/) /tmp/nix-store-closure
RUN ln -s $(readlink -f /tmp/build/result/bin/sh) /tmp/sh
# RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" nix build '.#docker_env'
# # Export the built closure to a folder
# RUN mkdir /tmp/nix-store-closure
# RUN cp -R $(nix-store -qR result/) /tmp/nix-store-closure
# RUN ln -s $(readlink -f /tmp/build/result/bin/sh) /tmp/sh
#
# Runner
#
# #
# # Runner
# #
FROM scratch
# FROM scratch
WORKDIR /app
# WORKDIR /app
ENV PATH="$PATH:/app/bin"
# ENV PATH="$PATH:/app/bin"
ENV SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt
ENV NIX_SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt
COPY --from=builder /tmp/ca-bundle.crt /etc/ssl/certs/ca-bundle.crt
# ENV SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt
# ENV NIX_SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt
# COPY --from=builder /tmp/ca-bundle.crt /etc/ssl/certs/ca-bundle.crt
COPY --from=builder /tmp/nix-store-closure /nix/store
COPY --from=builder /tmp/build/result /app
COPY --from=builder /tmp/sh /bin/sh
EXPOSE 8080
#RUN addgroup web && adduser -D -G web web
#&& install -d -D -o web -g web -m 700 /srv/http/public
# RUN ln -sf /dev/stdout /var/log/nginx/access.log && ln -sf /dev/stderr /var/log/nginx/error.log
CMD ["/app/bin/launch_nginx"]
# COPY --from=builder /tmp/nix-store-closure /nix/store
# COPY --from=builder /tmp/build/result /app
# COPY --from=builder /tmp/sh /bin/sh
# EXPOSE 8080
# #RUN addgroup web && adduser -D -G web web
# #&& install -d -D -o web -g web -m 700 /srv/http/public
# # RUN ln -sf /dev/stdout /var/log/nginx/access.log && ln -sf /dev/stderr /var/log/nginx/error.log
# CMD ["/app/bin/launch_nginx"]