Compare commits

..

3 Commits

Author SHA1 Message Date
Tom Alexander
affd4e61d6 auth
Some checks failed
build-staging Build build-staging has failed
2026-07-13 18:33:54 -04:00
Tom Alexander
40b81b715c Add support for building the site via nix. 2026-07-12 18:10:15 -04:00
Tom Alexander
feb4b2c082 Update webhook bridge refs.
Some checks failed
semver Build semver has succeeded
build-staging Build build-staging has failed
build Build build has failed
2026-05-03 16:37:38 -04:00
11 changed files with 386 additions and 204 deletions

View File

@@ -1,2 +1,5 @@
**/.git **/.git
**/.gitignore **/.gitignore
/.webhook_bridge
/result
**/Dockerfile

1
.gitignore vendored
View File

@@ -1 +1,2 @@
output/ output/
/result

View File

@@ -44,31 +44,6 @@ spec:
#!/usr/bin/env sh #!/usr/bin/env sh
set -euo pipefail set -euo pipefail
echo -n "$(date +%s)" | tee $(results.unix-time.path) echo -n "$(date +%s)" | tee $(results.unix-time.path)
- name: get-git-commit-time
taskSpec:
metadata: {}
stepTemplate:
image: alpine:3.20
computeResources:
requests:
cpu: 10m
memory: 600Mi
workingDir: "$(workspaces.repo.path)"
results:
- name: unix-time
description: The time of the git commit in unix timestamp format.
steps:
- image: alpine/git:v2.34.2
name: detect-tag-step
script: |
#!/usr/bin/env sh
set -euo pipefail
echo -n "$(git log -1 --pretty=%ct)" | tee $(results.unix-time.path)
workspaces:
- name: repo
workspace: git-source
runAfter:
- fetch-repository
- name: report-pending - name: report-pending
taskRef: taskRef:
resolver: git resolver: git
@@ -76,11 +51,9 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
runAfter:
- fetch-repository
params: params:
- name: CONTEXT - name: CONTEXT
value: "$(params.JOB_NAME)" value: "$(params.JOB_NAME)"
@@ -103,7 +76,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/git-clone/0.9/git-clone.yaml value: task/git-clone/0.9/git-clone.yaml
workspaces: workspaces:
@@ -116,6 +89,34 @@ spec:
value: $(params.PULL_BASE_SHA) value: $(params.PULL_BASE_SHA)
- name: deleteExisting - name: deleteExisting
value: "true" value: "true"
- name: get-git-commit-time
taskSpec:
metadata: {}
stepTemplate:
image: alpine:3.20
computeResources:
requests:
cpu: 10m
memory: 600Mi
workingDir: "$(workspaces.repo.path)"
results:
- name: unix-time
description: The time of the git commit in unix timestamp format.
steps:
- image: alpine/git:v2.34.2
name: detect-tag-step
script: |
#!/usr/bin/env sh
set -euo pipefail
find /
echo -n "$(git log -1 --pretty=%ct)" | tee $(results.unix-time.path)
workspaces:
- name: repo
workspace: git-source
- name: nix-cache-creds
workspace: nix-cache-creds
runAfter:
- fetch-repository
- name: build-image - name: build-image
taskRef: taskRef:
resolver: git resolver: git
@@ -123,7 +124,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git
- name: revision - name: revision
value: 7ee31a185243ee6da13dcd26a592c585b64c80e5 value: af22c87d0db59dece97d03e6b6a796d84010158f
- name: pathInRepo - name: pathInRepo
value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml
params: params:
@@ -144,6 +145,9 @@ spec:
- "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true" - "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true"
- --opt - --opt
- build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time) - build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time)
# - --secret
# - id=cache_token,src=./my_local_token.txt
# - id=cache_token,env=MY_ENV_TOKEN
- name: BUILDKITD_TOML - name: BUILDKITD_TOML
value: | value: |
debug = true debug = true
@@ -157,6 +161,8 @@ spec:
workspace: git-source workspace: git-source
- name: dockerconfig - name: dockerconfig
workspace: docker-credentials workspace: docker-credentials
- name: nix-cache-creds
workspace: nix-cache-creds
runAfter: runAfter:
- fetch-repository - fetch-repository
finally: finally:
@@ -171,7 +177,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
params: params:
@@ -200,7 +206,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
params: params:
@@ -221,6 +227,7 @@ spec:
workspaces: workspaces:
- name: git-source - name: git-source
- name: docker-credentials - name: docker-credentials
- name: nix-cache-creds
workspaces: workspaces:
- name: git-source - name: git-source
volumeClaimTemplate: volumeClaimTemplate:
@@ -235,6 +242,9 @@ spec:
- name: docker-credentials - name: docker-credentials
secret: secret:
secretName: harbor-plain secretName: harbor-plain
- name: nix-cache-creds
secret:
secretName: nix-pull-through-cache
params: params:
- name: image-name - name: image-name
value: "harbor.fizz.buzz/private/homepage-staging" value: "harbor.fizz.buzz/private/homepage-staging"

View File

@@ -88,7 +88,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
runAfter: runAfter:
@@ -115,7 +115,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/git-clone/0.9/git-clone.yaml value: task/git-clone/0.9/git-clone.yaml
workspaces: workspaces:
@@ -135,7 +135,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git
- name: revision - name: revision
value: 7ee31a185243ee6da13dcd26a592c585b64c80e5 value: af22c87d0db59dece97d03e6b6a796d84010158f
- name: pathInRepo - name: pathInRepo
value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml
params: params:
@@ -183,7 +183,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
params: params:
@@ -212,7 +212,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
params: params:

View File

@@ -74,7 +74,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
params: params:
@@ -99,7 +99,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/git-clone/0.9/git-clone.yaml value: task/git-clone/0.9/git-clone.yaml
workspaces: workspaces:
@@ -124,7 +124,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
params: params:
@@ -153,7 +153,7 @@ spec:
- name: url - name: url
value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git
- name: revision - name: revision
value: df36b3853a5657fd883015cdbf07ad6466918acf value: f914437a46978b95f325f68d791dcf1a35738f60
- name: pathInRepo - name: pathInRepo
value: task/gitea-set-status/0.1/gitea-set-status.yaml value: task/gitea-set-status/0.1/gitea-set-status.yaml
params: params:

View File

@@ -1,69 +1,48 @@
# syntax=docker/dockerfile:1 #
ARG ALPINE_VERSION="3.20" # Builder
#
FROM nixos/nix:2.31.3 AS builder
RUN tee -a /etc/nix/nix.conf <<EOF
extra-experimental-features = nix-command flakes
filter-syscalls = false
substituters = http://ncps.nix-pull-through-cache.svc.cluster.local:80 https://cache.nixos.org
EOF
RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" cp "$(nix build nixpkgs#cacert --print-out-paths)/etc/ssl/certs/ca-bundle.crt" /tmp/ca-bundle.crt
COPY . /tmp/build
WORKDIR /tmp/build
RUN --mount=type=secret,id=cache_token NIX_CONFIG="extra-access-tokens = ncps.nix-pull-through-cache.svc.cluster.local=$(cat /run/secrets/cache_token)" nix build '.#docker_env'
# Export the built closure to a folder
RUN mkdir /tmp/nix-store-closure
RUN cp -R $(nix-store -qR result/) /tmp/nix-store-closure
RUN ln -s $(readlink -f /tmp/build/result/bin/sh) /tmp/sh
FROM scratch AS private #
ADD git@code.fizz.buzz:talexander/homepage_private.git /homepage_private # Runner
#
FROM scratch
WORKDIR /app
FROM scratch AS explorer ENV PATH="$PATH:/app/bin"
ADD https://code.fizz.buzz/talexander/organic_ast_explorer.git /organic_ast_explorer
ENV SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt
ENV NIX_SSL_CERT_FILE=/etc/ssl/certs/ca-bundle.crt
COPY --from=builder /tmp/ca-bundle.crt /etc/ssl/certs/ca-bundle.crt
COPY --from=builder /tmp/nix-store-closure /nix/store
FROM scratch AS organic COPY --from=builder /tmp/build/result /app
ADD git@code.fizz.buzz:talexander/organic.git /organic COPY --from=builder /tmp/sh /bin/sh
EXPOSE 8080
#RUN addgroup web && adduser -D -G web web
#&& install -d -D -o web -g web -m 700 /srv/http/public
FROM rustlang/rust:nightly-alpine$ALPINE_VERSION AS organic-build # RUN ln -sf /dev/stdout /var/log/nginx/access.log && ln -sf /dev/stderr /var/log/nginx/error.log
RUN apk add --no-cache musl-dev make bash CMD ["/app/bin/launch_nginx"]
RUN rustup target add wasm32-unknown-unknown
RUN --mount=type=tmpfs,target=/tmp --mount=type=cache,target=/usr/local/cargo/registry,sharing=locked cargo install wasm-bindgen-cli
COPY --link --from=organic /organic /organic
WORKDIR /organic
RUN --mount=type=tmpfs,target=/tmp --mount=type=cache,target=/usr/local/cargo/registry,sharing=locked make wasm
FROM node:lts-alpine$ALPINE_VERSION AS explorer-build
COPY --link --from=explorer /organic_ast_explorer /organic_ast_explorer
COPY --link --from=organic-build /organic /organic
WORKDIR /organic_ast_explorer
RUN --mount=type=tmpfs,target=/tmp --mount=type=cache,target=/npmcache,sharing=locked npm set cache /npmcache && npm install
RUN npm run release
FROM rustlang/rust:nightly-alpine$ALPINE_VERSION AS natter-build
RUN apk add --no-cache musl-dev
ADD git@code.fizz.buzz:talexander/natter.git /natter
WORKDIR /natter
RUN --mount=type=tmpfs,target=/tmp --mount=type=cache,target=/usr/local/cargo/registry,sharing=locked CARGO_TARGET_DIR=/target cargo build --profile release-lto
FROM alpine:$ALPINE_VERSION AS natter
COPY --link --from=natter-build /target/release-lto/natter /usr/bin/
COPY --link . /source
COPY --link --from=private /homepage_private/static /source/static/
COPY --link --from=explorer-build /organic_ast_explorer/dist /source/static/organic/ast_explorer/
RUN --network=none --mount=type=tmpfs,target=/tmp natter build --config /source/natter.toml
FROM alpine:$ALPINE_VERSION AS server
RUN apk add --no-cache bash nginx
RUN addgroup web && adduser -D -G web web && install -d -D -o web -g web -m 700 /srv/http/public
RUN ln -sf /dev/stdout /var/log/nginx/access.log && ln -sf /dev/stderr /var/log/nginx/error.log
COPY --chown=web:web docker/server/nginx.conf /srv/http
COPY --chown=web:web docker/server/headers.include /srv/http
COPY --from=natter --chown=web:web /source/output/ /srv/http/public/
ENTRYPOINT ["/usr/sbin/nginx", "-c", "/srv/http/nginx.conf", "-e", "stderr", "-g", "daemon off;"]

View File

@@ -1,4 +1,4 @@
user web; # user web;
worker_processes 4; worker_processes 4;
# Speed up regular expressions. # Speed up regular expressions.
@@ -12,7 +12,7 @@ events {
} }
http { http {
include /etc/nginx/mime.types; include @mime_types@;
default_type application/octet-stream; default_type application/octet-stream;
types { types {
@@ -24,11 +24,11 @@ http {
sendfile on; sendfile on;
tcp_nopush on; tcp_nopush on;
include headers.include; include @headers_include@;
server { server {
listen 8080; listen 8080;
root /srv/http/public; root @web_root@;
location / { location / {
try_files $uri $uri/ =404; try_files $uri $uri/ =404;
@@ -47,24 +47,24 @@ http {
} }
location /.well-known/ { location /.well-known/ {
alias /srv/http/public/well-known/; alias @web_root@/well-known/;
default_type text/plain; default_type text/plain;
} }
location /.well-known/openpgpkey/hu/ { location /.well-known/openpgpkey/hu/ {
alias /srv/http/public/well-known/openpgpkey/fizz.buzz/hu/; alias @web_root@/well-known/openpgpkey/fizz.buzz/hu/;
default_type "application/octet-stream"; default_type "application/octet-stream";
add_header Access-Control-Allow-Origin * always; add_header Access-Control-Allow-Origin * always;
} }
location /.well-known/openpgpkey/policy { location /.well-known/openpgpkey/policy {
alias /srv/http/public/well-known/openpgpkey/fizz.buzz/policy; alias @web_root@/well-known/openpgpkey/fizz.buzz/policy;
default_type "application/octet-stream"; default_type "application/octet-stream";
add_header Access-Control-Allow-Origin * always; add_header Access-Control-Allow-Origin * always;
} }
location ~ /\.well-known/(?<path>openpgpkey/[^/]+/hu/.*) { location ~ /\.well-known/(?<path>openpgpkey/[^/]+/hu/.*) {
alias /srv/http/public/well-known/$path; alias @web_root@/well-known/$path;
default_type "application/octet-stream"; default_type "application/octet-stream";
add_header Access-Control-Allow-Origin * always; add_header Access-Control-Allow-Origin * always;
} }

136
flake.lock generated Normal file
View File

@@ -0,0 +1,136 @@
{
"nodes": {
"natter": {
"inputs": {
"nixpkgs": [
"nixpkgs"
],
"rust-overlay": "rust-overlay"
},
"locked": {
"lastModified": 1783808400,
"narHash": "sha256-izeK0soRWiep4mkZ1duD1hf3fqXYrZXsHUwnBzTbTpA=",
"ref": "refs/heads/main",
"rev": "05c7ecde829f3e3843e89000e9959b8016124b2e",
"revCount": 326,
"type": "git",
"url": "https://code.fizz.buzz/talexander/natter.git"
},
"original": {
"type": "git",
"url": "https://code.fizz.buzz/talexander/natter.git"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1780749050,
"narHash": "sha256-3av0pIjlOWQ6rDbNOmpUSvbNnJkGORQKKjb4LtCZsIY=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "a799d3e3886da994fa307f817a6bc705ae538eeb",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"organic": {
"inputs": {
"nixpkgs": [
"organic_ast_explorer",
"nixpkgs"
],
"rust-overlay": "rust-overlay_2"
},
"locked": {
"lastModified": 1783734912,
"narHash": "sha256-tXPapMwegdfP0jcr3BPQXxv1Aauo6yZwS4q2sIKOF9o=",
"ref": "refs/heads/main",
"rev": "842a77fb2bc684a545fb102e16790fa902aec11c",
"revCount": 2008,
"type": "git",
"url": "https://code.fizz.buzz/talexander/organic.git"
},
"original": {
"type": "git",
"url": "https://code.fizz.buzz/talexander/organic.git"
}
},
"organic_ast_explorer": {
"inputs": {
"nixpkgs": [
"nixpkgs"
],
"organic": "organic"
},
"locked": {
"lastModified": 1783737126,
"narHash": "sha256-BM6lYBegCV8EkVGqd6wIW9YN4EQL8cnoe4T5TuV7Q2I=",
"ref": "refs/heads/main",
"rev": "de11bc7c5e08610dc006ac7b31454abc6e1f46e7",
"revCount": 74,
"type": "git",
"url": "https://code.fizz.buzz/talexander/organic_ast_explorer.git"
},
"original": {
"type": "git",
"url": "https://code.fizz.buzz/talexander/organic_ast_explorer.git"
}
},
"root": {
"inputs": {
"natter": "natter",
"nixpkgs": "nixpkgs",
"organic_ast_explorer": "organic_ast_explorer"
}
},
"rust-overlay": {
"inputs": {
"nixpkgs": [
"natter",
"nixpkgs"
]
},
"locked": {
"lastModified": 1781407245,
"narHash": "sha256-VzJq4MmD0uyNDAceudSe1hHqcQMe9Tau0U4S+5iRGh0=",
"owner": "oxalica",
"repo": "rust-overlay",
"rev": "d5f483210eb016d66102eef22baa128b3b3233fc",
"type": "github"
},
"original": {
"owner": "oxalica",
"repo": "rust-overlay",
"type": "github"
}
},
"rust-overlay_2": {
"inputs": {
"nixpkgs": [
"organic_ast_explorer",
"organic",
"nixpkgs"
]
},
"locked": {
"lastModified": 1781407245,
"narHash": "sha256-VzJq4MmD0uyNDAceudSe1hHqcQMe9Tau0U4S+5iRGh0=",
"owner": "oxalica",
"repo": "rust-overlay",
"rev": "d5f483210eb016d66102eef22baa128b3b3233fc",
"type": "github"
},
"original": {
"owner": "oxalica",
"repo": "rust-overlay",
"type": "github"
}
}
},
"root": "root",
"version": 7
}

109
flake.nix Normal file
View File

@@ -0,0 +1,109 @@
{
description = "Fizz.buzz homepage";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
natter = {
url = "git+https://code.fizz.buzz/talexander/natter.git";
inputs.nixpkgs.follows = "nixpkgs";
};
organic_ast_explorer = {
url = "git+https://code.fizz.buzz/talexander/organic_ast_explorer.git";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs =
{
self,
nixpkgs,
natter,
organic_ast_explorer,
}:
let
forAllSystems =
func:
builtins.listToAttrs (
map (system: {
name = system;
value = func system;
}) nixpkgs.lib.systems.flakeExposed
);
in
{
devShells = forAllSystems (
system:
let
overlays = [
natter.overlays.default
organic_ast_explorer.overlays.default
];
pkgs = import nixpkgs {
inherit system overlays;
};
in
{
default = pkgs.mkShell {
nativeBuildInputs = [
];
buildInputs = with pkgs; [
pkgs.natter.release
];
};
}
);
packages = forAllSystems (
system:
let
overlays = [
natter.overlays.default
organic_ast_explorer.overlays.default
];
pkgs = import nixpkgs {
inherit system overlays;
};
appliedOverlay = self.overlays.default pkgs pkgs;
in
rec {
default = release;
inherit (appliedOverlay.homepage)
release
;
docker_env = pkgs.buildEnv {
name = "homepage";
paths = with pkgs; [
appliedOverlay.homepage.launch_nginx
bash
uutils-coreutils-noprefix
# toybox # Smaller than uutils-coreutils?
];
};
}
);
overlays.default = final: prev: {
homepage = final.lib.makeScope final.newScope (
homepageScope:
let
natter' = (natter.overlays.default final final).natter.release;
organic_ast_explorer' =
(organic_ast_explorer.overlays.default final final).organic_ast_explorer.release;
release = homepageScope.callPackage ./nix/package.nix {
natter = natter';
organic_ast_explorer = organic_ast_explorer';
};
nginx_conf = final.replaceVars "${./docker/server/nginx.conf}" {
web_root = release;
mime_types = "${final.nginx}/conf/mime.types";
headers_include = "${./docker/server/headers.include}";
};
launch_nginx = final.writeShellScriptBin "launch_nginx" ''
${final.nginx}/bin/nginx -c ${nginx_conf} -e stderr -g "daemon off;"
'';
in
{
inherit release launch_nginx;
}
);
};
};
}

38
nix/package.nix Normal file
View File

@@ -0,0 +1,38 @@
{
hello,
lib,
pkgs,
natter,
organic_ast_explorer,
}:
let
in
pkgs.stdenv.mkDerivation rec {
pname = "homepage";
version = "0.0.0";
src = lib.cleanSource ../.;
nativeBuildInputs = [
# pkgs.simgrid
# pkgs.boost
# pkgs.cmake
];
configurePhase = "";
# TODO copy COPY --link --from=private /homepage_private/static /source/static/
buildPhase = ''
mkdir -p static/organic/ast_explorer
cp ${organic_ast_explorer}/* static/organic/ast_explorer/
${natter}/bin/natter build --config natter.toml
'';
installPhase = ''
mkdir -p $out
mv output/* $out/
'';
}

View File

@@ -1,94 +0,0 @@
#+OPTIONS: html-postamble:nil
#+title: Declutter NixOS EFI System Partition
#+date: <2025-11-08 Sat>
#+author: Tom Alexander
#+email:
#+language: en
#+select_tags: export
#+exclude_tags: noexport
What does the EFI system partition look like on a NixOS system look like?
#+begin_src text
/boot
├── EFI
│   ├── BOOT
│   │   └── BOOTX64.EFI
│   ├── memtest86
│   │   └── memtest.efi
│   ├── nixos
│   │   ├── 0p4jsn66rw6gm6rc2wnzpmzhd5aldpab-initrd-linux-6.16.12-initrd.efi
│   │   └── 7zhgbsmhsch25y51ry39di8s7d5aa3b1-linux-6.16.12-bzImage.efi
│   └── systemd
│   └── systemd-bootx64.efi
└── loader
├── entries
│   ├── memtest86.conf
│   ├── nixos-generation-1.conf
│   └── nixos-generation-2.conf
├── entries.srel
├── keys
├── loader.conf
└── random-seed
#+end_src
Or maybe [[https://github.com/nix-community/lanzaboote][you care about security]], in which case your EFI system partition might look like:
#+begin_src text
/boot
└── EFI
    ├── BOOT
    │   └── BOOTX64.EFI
    ├── Linux
    │   ├── nixos-generation-819-4rahvvcu2fvsjfwgnfzu4hp5sm6pjir7ivy65unygrzlmnt2wmfa.efi
    │   ├── nixos-generation-820-hfu7owhqplrumyvkudyxuiem6ocrgb5z7ujqncl6aoemj4ekktkq.efi
    │   └── nixos-generation-821-g2l3xmw6w5c26n3ixl53jejzslttdmvs3wajnb7aittwsfttwypq.efi
    └── systemd
    └── systemd-bootx64.efi
#+end_src
Regardless, they both have the same problem: they are storing information that is specific to my system and necessary for booting in the EFI system partition.
What does *my* NixOS EFI system partition look like?
#+begin_src text
/efi
└── EFI
└── BOOT
└── BOOTX64.EFI
#+end_src
That src_text[:exports code]{BOOTX64.EFI} contains no information specific to my system. It does not change when I make new generations of my system config. If I ever lost it, I could copy it off another one of my machines or build it again from publicly-available sources.
* Why
** Backups
One of the best features of ZFS is [[https://klarasystems.com/articles/introduction-to-zfs-replication/][ZFS send/recv]]. But with the old way of booting, I couldn't simply use ZFS send/recv to make a functional backup of my system: I also needed the information in the EFI system partition. Now, all of the information about my system is stored on ZFS, so I can use ZFS send/recv to make full, functional backups.
** Dual Booting
I like to boot multiple different systems off the same ZFS pool. For example, you might want to have a NixOS system for productive work encrypted with one password, and another NixOS system encrypted with a different password for running video games to keep your data safe from the closed-source +spyware+ anti-cheat bundled in games. I wouldn't want the two NixOS systems overwriting each other's entries in the shared EFI system partition. Since 100% of the data about my system is stored on ZFS, I can have as many separate NixOS systems as I want, all on the same ZFS pool, without fighting each other. On top of that, I can also seamless boot other Linux distros, also sharing the same pool.
** Not filling up the EFI system partition
This is an issue many new NixOS users encounter. They get their system configuration written, and start happily using their system, until [[https://discourse.nixos.org/t/what-to-do-with-a-full-boot-partition/2049][one day it suddenly breaks]]. Avoiding the problem is easy (if you know to do it) through limiting the number of generations that are kept, but recovering from it after it breaks is less fun.
With my system, I can store as many generations as I want, since all of my kernels and ramdisks are stored on my main ZFS partition instead of my EFI system partition.
* What this is not
** More secure
If you set up your NixOS system with [[https://github.com/nix-community/lanzaboote][Lanzaboote]], your EFI system partition files are cryptographically signed so they cannot be modified without your consent. While your kernel and init ramdisk won't be encrypted (and therefore won't be private), those two files seldom contain any private information. I do not think my new method of booting NixOS is any more private or secure than Lanzaboote.
* How
* Why aren't you upstreaming this?
I would love for this functionality to make it into upstream ZFSBootMenu. The reasons I am not sending this patch upstream are:
1. I am not confident in the quality of my changes. ZFSBootMenu is implemented in bash. Bash doesn't have data structures, so structured data is passed around by writing tabular data to files in the tmpfs filesystem. Bash likes to keep running, even after encountering errors, unless you use [[http://redsymbol.net/articles/unofficial-bash-strict-mode/][Unofficial Bash Strict Mode]] (which ZFSBootMenu did not). Returning data from functions is handled by writing to stdout. Variables are global by default. Some impressive scripters have demonstrably been able to create large complex projects with shell scripting (for example, ZFSBootMenu or poudriere) but my bash skills are not at their level, and I have no interest in reaching that level in bash.
2. My extlinux.conf parsing code is incredibly crude, largely because I am parsing it in bash.
3. I haven't tested my changes on the vast combinations of ZFSBootMenu environments. ZFSBootMenu can be run via bios or UEFI. It can be run as a kernel+ramdisk or as an EFI executable. It can be built with mkinitcpio or dracut. It can boot a multitude of Linux distros. All I know is this works on my system.
4. I don't know if the ZFSBootMenu maintainers are interested in maintaining this code. They already have so many environments to test, I can see them not wanting to add another to the pile, especially for something less mainstream like NixOS. My boot code currently only has 1 user, so it is hard to make an argument for the value of this code.