diff --git a/.envrc b/.envrc deleted file mode 100644 index 3550a30..0000000 --- a/.envrc +++ /dev/null @@ -1 +0,0 @@ -use flake diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 7a4cae0..a55c0af 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -3,17 +3,16 @@ stages: build: stage: build + image: "$CI_REGISTRY_IMAGE/img-builder:latest" parallel: matrix: - IMG: - - vm-test - - sword-container-builder + - vm-test + - sword-container-builder tags: - - nix - - podman + - kubernetes script: - podman login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY - nix build ".#${IMG}" - podman load -i result - - podman tag "localhost/${IMG}:latest" $CI_REGISTRY/greg/ci-images/${IMG}:latest - - podman push "$CI_REGISTRY/greg/ci-images/${IMG}:latest" + - podman push "$CI_REGISTRY_IMAGE/${IMG}:latest" diff --git a/flake.lock b/flake.lock index c8e11b3..3efb586 100644 --- a/flake.lock +++ b/flake.lock @@ -1,100 +1,15 @@ { "nodes": { - "agenix": { - "inputs": { - "darwin": "darwin", - "home-manager": "home-manager", - "nixpkgs": [ - "greg", - "nixunstable" - ], - "systems": "systems_2" - }, - "locked": { - "lastModified": 1707830867, - "narHash": "sha256-PAdwm5QqdlwIqGrfzzvzZubM+FXtilekQ/FA0cI49/o=", - "owner": "ryantm", - "repo": "agenix", - "rev": "8cb01a0e717311680e0cbca06a76cbceba6f3ed6", - "type": "github" - }, - "original": { - "owner": "ryantm", - "repo": "agenix", - "type": "github" - } - }, - "darwin": { - "inputs": { - "nixpkgs": [ - "greg", - "agenix", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1700795494, - "narHash": "sha256-gzGLZSiOhf155FW7262kdHo2YDeugp3VuIFb4/GGng0=", - "owner": "lnl7", - "repo": "nix-darwin", - "rev": "4b9b83d5a92e8c1fbfd8eb27eda375908c11ec4d", - "type": "github" - }, - "original": { - "owner": "lnl7", - "ref": "master", - "repo": "nix-darwin", - "type": "github" - } - }, - "darwin_2": { - "inputs": { - "nixpkgs": [ - "greg", - "nixunstable" - ] - }, - "locked": { - "lastModified": 1705915768, - "narHash": "sha256-+Jlz8OAqkOwJlioac9wtpsCnjgGYUhvLpgJR/5tP9po=", - "owner": "lnl7", - "repo": "nix-darwin", - "rev": "1e706ef323de76236eb183d7784f3bd57255ec0b", - "type": "github" - }, - "original": { - "owner": "lnl7", - "ref": "master", - "repo": "nix-darwin", - "type": "github" - } - }, - "flake-compat": { - "flake": false, - "locked": { - "lastModified": 1696426674, - "narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=", - "owner": "edolstra", - "repo": "flake-compat", - "rev": "0f9255e01c2351cc7d116c072cb317785dd33b33", - "type": "github" - }, - "original": { - "owner": "edolstra", - "repo": "flake-compat", - "type": "github" - } - }, "flake-parts": { "inputs": { "nixpkgs-lib": "nixpkgs-lib" }, "locked": { - "lastModified": 1712014858, - "narHash": "sha256-sB4SWl2lX95bExY2gMFG5HIzvva5AVMJd4Igm+GpZNw=", + "lastModified": 1763759067, + "narHash": "sha256-LlLt2Jo/gMNYAwOgdRQBrsRoOz7BPRkzvNaI/fzXi2Q=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "9126214d0a59633752a136528f5f3b9aa8565b7d", + "rev": "2cccadc7357c0ba201788ae99c4dfa90728ef5e0", "type": "github" }, "original": { @@ -103,376 +18,13 @@ "type": "github" } }, - "flake-utils": { - "inputs": { - "systems": "systems" - }, - "locked": { - "lastModified": 1710146030, - "narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a", - "type": "github" - }, - "original": { - "id": "flake-utils", - "type": "indirect" - } - }, - "flake-utils_2": { - "inputs": { - "systems": "systems_3" - }, - "locked": { - "lastModified": 1694529238, - "narHash": "sha256-zsNZZGTGnMOf9YpHKJqMSsa0dXbfmxeoJ7xHlrt+xmY=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "ff7b65b44d01cf9ba6a71320833626af21126384", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, - "flake-utils_3": { - "inputs": { - "systems": "systems_4" - }, - "locked": { - "lastModified": 1705309234, - "narHash": "sha256-uNRRNRKmJyCRC/8y1RqBkqWBLM034y4qN7EprSdmgyA=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "1ef2e671c3b0c19053962c07dbda38332dcebf26", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, - "flake-utils_4": { - "inputs": { - "systems": "systems_5" - }, - "locked": { - "lastModified": 1705309234, - "narHash": "sha256-uNRRNRKmJyCRC/8y1RqBkqWBLM034y4qN7EprSdmgyA=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "1ef2e671c3b0c19053962c07dbda38332dcebf26", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" - } - }, - "greg": { - "inputs": { - "agenix": "agenix", - "darwin": "darwin_2", - "flake-utils": "flake-utils_2", - "hm": "hm", - "hmunstable": "hmunstable", - "nix23_05": "nix23_05", - "nixneovim": "nixneovim", - "nixstable": "nixstable", - "nixunstable": "nixunstable", - "nurpkgs": "nurpkgs", - "wsl": "wsl" - }, - "locked": { - "lastModified": 1713276302, - "narHash": "sha256-fPJL/mXJnhX7/n+GvuBk/zyiG69n5VY+YjC1WTSvrUE=", - "owner": "greg-hellings", - "repo": "nixos-config", - "rev": "861588f217ff551b29cf9b431d98de3aee0a15f4", - "type": "github" - }, - "original": { - "owner": "greg-hellings", - "repo": "nixos-config", - "type": "github" - } - }, - "haumea": { - "inputs": { - "nixpkgs": "nixpkgs" - }, - "locked": { - "lastModified": 1685133229, - "narHash": "sha256-FePm/Gi9PBSNwiDFq3N+DWdfxFq0UKsVVTJS3cQPn94=", - "owner": "nix-community", - "repo": "haumea", - "rev": "34dd58385092a23018748b50f9b23de6266dffc2", - "type": "github" - }, - "original": { - "owner": "nix-community", - "ref": "v0.2.2", - "repo": "haumea", - "type": "github" - } - }, - "hm": { - "inputs": { - "nixpkgs": [ - "greg", - "nixstable" - ] - }, - "locked": { - "lastModified": 1705659542, - "narHash": "sha256-WA3xVfAk1AYmFdwghT7mt/erYpsU6JPu9mdTEP/e9HQ=", - "owner": "nix-community", - "repo": "home-manager", - "rev": "10cd9c53115061aa6a0a90aad0b0dde6a999cdb9", - "type": "github" - }, - "original": { - "owner": "nix-community", - "ref": "release-23.11", - "repo": "home-manager", - "type": "github" - } - }, - "hmunstable": { - "inputs": { - "nixpkgs": [ - "greg", - "nixstable" - ] - }, - "locked": { - "lastModified": 1706798041, - "narHash": "sha256-BbvuF4CsVRBGRP8P+R+JUilojk0M60D7hzqE0bEvJBQ=", - "owner": "nix-community", - "repo": "home-manager", - "rev": "4d53427bce7bf3d17e699252fd84dc7468afc46e", - "type": "github" - }, - "original": { - "owner": "nix-community", - "ref": "master", - "repo": "home-manager", - "type": "github" - } - }, - "home-manager": { - "inputs": { - "nixpkgs": [ - "greg", - "agenix", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1703113217, - "narHash": "sha256-7ulcXOk63TIT2lVDSExj7XzFx09LpdSAPtvgtM7yQPE=", - "owner": "nix-community", - "repo": "home-manager", - "rev": "3bfaacf46133c037bb356193bd2f1765d9dc82c1", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "home-manager", - "type": "github" - } - }, - "home-manager_2": { - "inputs": { - "nixpkgs": [ - "greg", - "nixneovim", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1705535278, - "narHash": "sha256-V5+XKfNbiY0bLKLQlH+AXyhHttEL7XcZBH9iSbxxexA=", - "owner": "nix-community", - "repo": "home-manager", - "rev": "b84191db127c16a92cbdf7f7b9969d58bb456699", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "home-manager", - "type": "github" - } - }, - "nix-flake-tests": { - "locked": { - "lastModified": 1677844186, - "narHash": "sha256-ErJZ/Gs1rxh561CJeWP5bohA2IcTq1rDneu1WT6CVII=", - "owner": "antifuchs", - "repo": "nix-flake-tests", - "rev": "bbd9216bd0f6495bb961a8eb8392b7ef55c67afb", - "type": "github" - }, - "original": { - "owner": "antifuchs", - "repo": "nix-flake-tests", - "type": "github" - } - }, - "nix-github-actions": { - "inputs": { - "nixpkgs": [ - "greg", - "nixneovim", - "nixneovimplugins", - "poetry2nix", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1688870561, - "narHash": "sha256-4UYkifnPEw1nAzqqPOTL2MvWtm3sNGw1UTYTalkTcGY=", - "owner": "nix-community", - "repo": "nix-github-actions", - "rev": "165b1650b753316aa7f1787f3005a8d2da0f5301", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "nix-github-actions", - "type": "github" - } - }, - "nix23_05": { - "locked": { - "lastModified": 1702759837, - "narHash": "sha256-u3XeJVRe/Q975nwFE+6ALEwypMKJEELMJKDAhSKyq3M=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "b2566f4f897ac6224e094b167d9488d03e157f28", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-23.05", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixneovim": { - "inputs": { - "flake-utils": "flake-utils_3", - "haumea": "haumea", - "home-manager": "home-manager_2", - "nix-flake-tests": "nix-flake-tests", - "nixneovimplugins": "nixneovimplugins", - "nixpkgs": "nixpkgs_2", - "nmd": "nmd", - "nmt": "nmt" - }, - "locked": { - "lastModified": 1705702328, - "narHash": "sha256-yDPcAUzGlQ4e7JKHVligTUpXcB2X18QNOrA5pzmeus0=", - "owner": "NixNeovim", - "repo": "NixNeovim", - "rev": "30e3b1854039a16d8fd08a1ed3f5aaf6c114060e", - "type": "github" - }, - "original": { - "owner": "NixNeovim", - "repo": "NixNeovim", - "type": "github" - } - }, - "nixneovimplugins": { - "inputs": { - "flake-utils": [ - "greg", - "nixneovim", - "flake-utils" - ], - "nixpkgs": [ - "greg", - "nixneovim", - "nixpkgs" - ], - "poetry2nix": "poetry2nix" - }, - "locked": { - "lastModified": 1705344848, - "narHash": "sha256-Ns//Yrqug/OmupDUS4ue1tTvv4/UmLtY9oI6dIeWcMM=", - "owner": "nixneovim", - "repo": "nixneovimplugins", - "rev": "1054b77f33b54727082fb17170ce91d121b8a496", - "type": "github" - }, - "original": { - "owner": "nixneovim", - "repo": "nixneovimplugins", - "type": "github" - } - }, "nixpkgs": { "locked": { - "lastModified": 1681001314, - "narHash": "sha256-5sDnCLdrKZqxLPK4KA8+f4A3YKO/u6ElpMILvX0g72c=", - "owner": "nix-community", - "repo": "nixpkgs.lib", - "rev": "367c0e1086a4eb4502b24d872cea2c7acdd557f4", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "nixpkgs.lib", - "type": "github" - } - }, - "nixpkgs-lib": { - "locked": { - "dir": "lib", - "lastModified": 1711703276, - "narHash": "sha256-iMUFArF0WCatKK6RzfUJknjem0H9m4KgorO/p3Dopkk=", + "lastModified": 1763934636, + "narHash": "sha256-9glbI7f1uU+yzQCq5LwLgdZqx6svOhZWkd4JRY265fc=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "d8fe5e6c92d0d190646fb9f1056741a229980089", - "type": "github" - }, - "original": { - "dir": "lib", - "owner": "NixOS", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_2": { - "locked": { - "lastModified": 1705496572, - "narHash": "sha256-rPIe9G5EBLXdBdn9ilGc0nq082lzQd0xGGe092R/5QE=", - "owner": "nixos", - "repo": "nixpkgs", - "rev": "842d9d80cfd4560648c785f8a4e6f3b096790e19", - "type": "github" - }, - "original": { - "owner": "nixos", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_3": { - "locked": { - "lastModified": 1713254108, - "narHash": "sha256-0TZIsfDbHG5zibtlw6x0yOp3jkInIGaJ35B7Y4G8Pec=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "2fd19c8be2551a61c1ddc3d9f86d748f4db94f00", + "rev": "ee09932cedcef15aaf476f9343d1dea2cb77e261", "type": "github" }, "original": { @@ -482,220 +34,25 @@ "type": "github" } }, - "nixstable": { + "nixpkgs-lib": { "locked": { - "lastModified": 1708831307, - "narHash": "sha256-0iL/DuGjiUeck1zEaL+aIe2WvA3/cVhp/SlmTcOZXH4=", - "owner": "nixos", - "repo": "nixpkgs", - "rev": "5bf1cadb72ab4e77cb0b700dab76bcdaf88f706b", - "type": "github" - }, - "original": { - "owner": "nixos", - "ref": "nixos-23.11", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixunstable": { - "locked": { - "lastModified": 1709961763, - "narHash": "sha256-6H95HGJHhEZtyYA3rIQpvamMKAGoa8Yh2rFV29QnuGw=", - "owner": "nixos", - "repo": "nixpkgs", - "rev": "3030f185ba6a4bf4f18b87f345f104e6a6961f34", - "type": "github" - }, - "original": { - "owner": "nixos", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nmd": { - "flake": false, - "locked": { - "lastModified": 1672949361, - "narHash": "sha256-WWg1kbilAb3sA+RoJtSYfAZvyYu1Nk79ocHaerwbQxQ=", - "owner": "~rycee", - "repo": "nmd", - "rev": "fb9cf8e991487c6923f3c654b8ae51b6f0f205ce", - "type": "sourcehut" - }, - "original": { - "owner": "~rycee", - "repo": "nmd", - "rev": "fb9cf8e991487c6923f3c654b8ae51b6f0f205ce", - "type": "sourcehut" - } - }, - "nmt": { - "flake": false, - "locked": { - "lastModified": 1694274695, - "narHash": "sha256-PufoLMSuBYkga8hTqYf/cIQzSuy2lfFj+cdKcp2nLEI=", - "owner": "jooooscha", - "repo": "nmt", - "rev": "29595267923b4a6ce766ff0d85afaa930842b88d", - "type": "github" - }, - "original": { - "owner": "jooooscha", - "repo": "nmt", - "type": "github" - } - }, - "nurpkgs": { - "locked": { - "lastModified": 1706910257, - "narHash": "sha256-w0EN3LJS+4HlkTBb3rgImSWCkzNdFWxsIbgsYpKh09E=", + "lastModified": 1761765539, + "narHash": "sha256-b0yj6kfvO8ApcSE+QmA6mUfu8IYG6/uU28OFn4PaC8M=", "owner": "nix-community", - "repo": "NUR", - "rev": "96b0e9d38890afb8e4af6d6a556ee27e79fd6e22", + "repo": "nixpkgs.lib", + "rev": "719359f4562934ae99f5443f20aa06c2ffff91fc", "type": "github" }, "original": { "owner": "nix-community", - "repo": "NUR", - "type": "github" - } - }, - "poetry2nix": { - "inputs": { - "flake-utils": [ - "greg", - "nixneovim", - "nixneovimplugins", - "flake-utils" - ], - "nix-github-actions": "nix-github-actions", - "nixpkgs": [ - "greg", - "nixneovim", - "nixneovimplugins", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1689849924, - "narHash": "sha256-d259Z2S7CS7Na04qQNQ6LYQILuI7cf4Rpe76qc4mz40=", - "owner": "nix-community", - "repo": "poetry2nix", - "rev": "1d7eda9336f336392d24e9602be5cb9be7ae405c", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "poetry2nix", + "repo": "nixpkgs.lib", "type": "github" } }, "root": { "inputs": { "flake-parts": "flake-parts", - "flake-utils": "flake-utils", - "greg": "greg", - "nixpkgs": "nixpkgs_3" - } - }, - "systems": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "systems_2": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "systems_3": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "systems_4": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "systems_5": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, - "wsl": { - "inputs": { - "flake-compat": "flake-compat", - "flake-utils": "flake-utils_4", - "nixpkgs": [ - "greg", - "nixunstable" - ] - }, - "locked": { - "lastModified": 1709211223, - "narHash": "sha256-1cjd+yXbTlnCwNwEDjn289rJ2f0er5M8pOig4PxniEM=", - "owner": "nix-community", - "repo": "NixOS-WSL", - "rev": "3257ad7f173b0314c8a42fec450fa6556495b97c", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "NixOS-WSL", - "type": "github" + "nixpkgs": "nixpkgs" } } }, diff --git a/flake.nix b/flake.nix index c84a0ac..b5a5388 100644 --- a/flake.nix +++ b/flake.nix @@ -1,76 +1,48 @@ { - description = "Standard images that Greg wants to build"; - inputs = { - nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; - flake-parts.url = "github:hercules-ci/flake-parts"; - greg.url = "github:greg-hellings/nixos-config"; - }; + description = "Standard images that Greg wants to build"; + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; + flake-parts.url = "github:hercules-ci/flake-parts"; + }; - outputs = inputs@{ self, nixpkgs, flake-utils, greg, flake-parts }: - flake-parts.lib.mkFlake { inherit inputs; } { - flake = { - }; - systems = [ - "x86_64-linux" - "aarch64-linux" - "x86_64-darwin" - "aarch64-darwin" - ]; - perSystem = sys@{ config, pkgs, system, ... }: { - _module.args.pkgs = import nixpkgs { - inherit system; - config.allowUnfree = true; - }; - packages = { - sword-container-builder = pkgs.dockerTools.buildLayeredImage { - name = "sword-container-builder"; - tag = "latest"; - contents = with pkgs; [ - podman - dockerTools.binSh - dockerTools.caCertificates - coreutils - findutils - gnugrep - gnused - sword - dockerTools.usrBinEnv - ]; - config.Env = [ - "CURL_CA_BUNDLE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt" - ]; - }; - vm-test = let - basicPython = (pkgs.python3.withPackages (p: with p; [ pyyaml ])); - in pkgs.dockerTools.buildLayeredImage { - name = "vm-test"; - tag = "latest"; - contents = with pkgs; [ - bash - pkgs.dockerTools.binSh - pkgs.dockerTools.caCertificates - coreutils - curlWithGnuTls - pkgs.dockerTools.fakeNss - gawk - gnugrep - findutils - jq - packer - pup - shellcheck - pkgs.dockerTools.usrBinEnv - (xonsh.overridePythonAttrs (old: rec { python3 = basicPython; propagatedBuildInputs = old.propagatedBuildInputs ++ [ basicPython.pkgs.pyyaml ];})) - ]; - extraCommands = builtins.concatStringsSep "\n" [ - "mkdir -p tmp" - "chmod 1777 tmp" - ]; - config.Env = [ - "CURL_CA_BUNDLE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt" - ]; - }; - }; - }; - }; + outputs = + inputs@{ + nixpkgs, + flake-parts, + ... + }: + flake-parts.lib.mkFlake { inherit inputs; } { + flake = { + }; + systems = [ + "x86_64-linux" + "aarch64-linux" + "x86_64-darwin" + "aarch64-darwin" + ]; + perSystem = + { + pkgs, + system, + ... + }: + { + _module.args.pkgs = import nixpkgs { + inherit system; + config.allowUnfree = true; + }; + packages = + let + inherit (pkgs) callPackage; + name = n: "registry.thehellings.com/greg/ci-images/${n}"; + in + { + bitwarden = callPackage ./img/bitwarden.nix { inherit name; }; + builder = callPackage ./img/builder.nix { inherit name; }; + immich = callPackage ./immg/immich.nix { inherit name; }; + sword-container-builder = callPackage ./img/sword-container-builder.nix { inherit name; }; + vm-test = callPackage ./img/vm-test.nix { inherit name; }; + }; + }; + }; } diff --git a/img/bitwarden.nix b/img/bitwarden.nix new file mode 100644 index 0000000..1dd183e --- /dev/null +++ b/img/bitwarden.nix @@ -0,0 +1,48 @@ +{ + bitwarden-cli, + cacert, + dockerTools, + lib, + wget, + writeShellApplication, + + name, + ... +}: +dockerTools.buildLayeredImage { + name = name "bitwarden"; + tag = "latest"; + contents = [ + dockerTools.binSh + dockerTools.caCertificates + wget + ]; + config = { + Cmd = [ + (lib.getExe (writeShellApplication { + name = "bitwarden-cli-entrypoint.sh"; + runtimeInputs = [ bitwarden-cli ]; + text = '' + set -ex + + # Uncomment if you need to hit a custom host + #bw config server ''${BW_HOST} + + echo "Using apikey to log in" + bw login --apikey --raw + BW_SESSION="$(bw unlock --passwordenv BW_PASSWORD --raw)" + export BW_SESSION + + echo 'Running "bw serve" on port 8087' + bw serve --hostname all --port 8087 + ''; + })) + ]; + Env = [ + "CURL_CA_BUNDLE=${cacert}/etc/ssl/certs/ca-bundle.crt" + ]; + ExposedPorts = { + "8087/tcp" = { }; + }; + }; +} diff --git a/img/builder.nix b/img/builder.nix new file mode 100644 index 0000000..fb1d131 --- /dev/null +++ b/img/builder.nix @@ -0,0 +1,71 @@ +{ + bashInteractive, + dockerTools, + git, + lib, + nix, + nix-output-monitor, + pkgs, + podman, + writeShellApplication, + + name, + ... +}: +let + policy = ( + pkgs.writeTextFile { + name = "policy.json"; + text = '' + { + "default": [{"type": "insecureAcceptAnything"}] + } + ''; + destination = "/etc/containers/policy.json"; + } + ); + activate = writeShellApplication { + name = "activate"; + runtimeInputs = [ bashInteractive ]; + text = '' + mkdir -p /etc/containers + cp ${policy}/etc/containers/policy.json /etc/containers/policy.json; + bash "$@" + ''; + }; +in +(import "${nix.src.outPath}/docker.nix" { + inherit pkgs; + name = name "builder"; + tag = "latest"; + + bundleNixpkgs = false; + Cmd = [ + (lib.getExe activate) + ]; + extraPkgs = [ + dockerTools.caCertificates + nix-output-monitor + podman + policy + ]; + flake-registry = (pkgs.formats.json { }).generate "flake-registry.json" ({ + version = 2; + flakes.nixpkgs = { + exact = true; + from = { + id = "nixpkgs"; + type = "indirect"; + }; + to = "${pkgs.path}"; + }; + }); + gitMinimal = git; # We want the full version in this + maxLayers = 111; + nixConf = { + experimental-features = [ + "nix-command" + "flakes" + ]; + }; +}) diff --git a/img/immich.nix b/img/immich.nix new file mode 100644 index 0000000..aee3180 --- /dev/null +++ b/img/immich.nix @@ -0,0 +1,26 @@ +{ + immich-go, + cacert, + dockerTools, + lib, + + name, + ... +}: +dockerTools.buildLayeredImage { + name = name "immich"; + tag = "latest"; + contents = [ + dockerTools.binSh + dockerTools.caCertificates + immich-go + ]; + config = { + Cmd = [ + (lib.getExe immich-go) + ]; + Env = [ + "CURL_CA_BUNDLE=${cacert}/etc/ssl/certs/ca-bundle.crt" + ]; + }; +} diff --git a/img/sword-container-builer.nix b/img/sword-container-builer.nix new file mode 100644 index 0000000..387dd5d --- /dev/null +++ b/img/sword-container-builer.nix @@ -0,0 +1,30 @@ +{ + cacert, + coreutils, + dockerTools, + findutils, + gnugrep, + gnused, + podman, + sword, + + name, +}: +dockerTools.buildLayeredImage { + name = name "sword-container-builder"; + tag = "latest"; + contents = [ + podman + dockerTools.binSh + dockerTools.caCertificates + coreutils + findutils + gnugrep + gnused + sword + dockerTools.usrBinEnv + ]; + config.Env = [ + "CURL_CA_BUNDLE=${cacert}/etc/ssl/certs/ca-bundle.crt" + ]; +} diff --git a/img/vm-test.nix b/img/vm-test.nix new file mode 100644 index 0000000..d61f920 --- /dev/null +++ b/img/vm-test.nix @@ -0,0 +1,52 @@ +{ + bash, + cacert, + coreutils, + curlWithGnuTls, + dockerTools, + gawk, + gnugrep, + findutils, + jq, + packer, + pup, + shellcheck, + python3, + xonsh, +}: +let + basicPython = (python3.withPackages (p: with p; [ pyyaml ])); + x = xonsh.overridePtyhonAttrs (old: + { + python3 = basicPython; + propagatedbuildInputs = old.propagatedBuildInputs ++ [ basicPython.pkgs.pyyaml ]; + }); +in +dockerTools.buildLayeredImage { + name = "vm-test"; + tag = "latest"; + contents = [ + bash + dockerTools.binSh + dockerTools.caCertificates + coreutils + curlWithGnuTls + dockerTools.fakeNss + gawk + gnugrep + findutils + jq + packer + pup + shellcheck + dockerTools.usrBinEnv + x + ]; + extraCommands = '' + mkdir -p tmp + chmod 1777 tmp + ''; + config.Env = [ + "CURL_CA_BUNDLE=${cacert}/etc/ssl/certs/ca-bundle.crt" + ]; +};