Compare commits
1 commit
9b593ddd4b
...
6655ed0d57
| Author | SHA1 | Date | |
|---|---|---|---|
| 6655ed0d57 |
9 changed files with 102 additions and 39 deletions
|
|
@ -1,8 +1,10 @@
|
||||||
#!/usr/bin/env nu
|
#!/usr/bin/env nu
|
||||||
|
|
||||||
|
let shell_files = ls **/*.sh | get name
|
||||||
let nix_files = ls **/*.nix | where name !~ "hardware-configuration.nix|_sources" | get name
|
let nix_files = ls **/*.nix | where name !~ "hardware-configuration.nix|_sources" | get name
|
||||||
|
|
||||||
let linters = [
|
let linters = [
|
||||||
|
([shellcheck] ++ $shell_files)
|
||||||
([nixfmt --check --strict] ++ $nix_files)
|
([nixfmt --check --strict] ++ $nix_files)
|
||||||
([deadnix --fail] ++ $nix_files)
|
([deadnix --fail] ++ $nix_files)
|
||||||
([statix check] ++ $nix_files)
|
([statix check] ++ $nix_files)
|
||||||
|
|
|
||||||
28
flake.nix
28
flake.nix
|
|
@ -37,6 +37,7 @@
|
||||||
}@inputs:
|
}@inputs:
|
||||||
let
|
let
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
|
pkgs = nixpkgs.legacyPackages.${system};
|
||||||
|
|
||||||
vm = nixpkgs.lib.nixosSystem {
|
vm = nixpkgs.lib.nixosSystem {
|
||||||
inherit system;
|
inherit system;
|
||||||
|
|
@ -96,10 +97,15 @@
|
||||||
# Garbage collection root #
|
# Garbage collection root #
|
||||||
###########################
|
###########################
|
||||||
|
|
||||||
packages.${system} = {
|
packages.${system} =
|
||||||
|
let
|
||||||
|
localPkgs = import ./pkgs { inherit pkgs; };
|
||||||
|
in
|
||||||
|
{
|
||||||
default = vm.config.system.build.vm;
|
default = vm.config.system.build.vm;
|
||||||
}
|
crowdsec-hub = localPkgs.crowdsec.hub;
|
||||||
// import ./pkgs { pkgs = nixpkgs.legacyPackages.${system}; };
|
crowdsec-firewall-bouncer = localPkgs.crowdsec.firewall-bouncer;
|
||||||
|
};
|
||||||
|
|
||||||
###################
|
###################
|
||||||
# Utility scripts #
|
# Utility scripts #
|
||||||
|
|
@ -110,7 +116,7 @@
|
||||||
run-vm = {
|
run-vm = {
|
||||||
type = "app";
|
type = "app";
|
||||||
program =
|
program =
|
||||||
(nixpkgs.legacyPackages.${system}.writeShellScript "" ''
|
(pkgs.writeShellScript "" ''
|
||||||
${vm.config.system.build.vm.outPath}/bin/run-testvm-vm
|
${vm.config.system.build.vm.outPath}/bin/run-testvm-vm
|
||||||
'').outPath;
|
'').outPath;
|
||||||
};
|
};
|
||||||
|
|
@ -125,16 +131,16 @@
|
||||||
"./keys/hosts/"
|
"./keys/hosts/"
|
||||||
"./keys/users/"
|
"./keys/users/"
|
||||||
];
|
];
|
||||||
|
nativeBuildInputs = [ sops-nix.packages.${system}.sops-import-keys-hook ];
|
||||||
|
|
||||||
packages = nixpkgs.lib.attrValues {
|
packages = with pkgs; [
|
||||||
inherit (sops-nix.packages.${system}) sops-import-keys-hook sops-init-gpg-key;
|
sops-nix.packages.${system}.sops-init-gpg-key
|
||||||
inherit (deploy-rs.packages.${system}) default;
|
deploy-rs.packages.${system}.default
|
||||||
|
nixpkgs-fmt
|
||||||
|
];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
minecraft = nixpkgs.legacyPackages.${system}.mkShell {
|
minecraft = nixpkgs.legacyPackages.${system}.mkShell { packages = [ pkgs.packwiz ]; };
|
||||||
packages = nixpkgs.lib.attrValues { inherit (nixpkgs.legacyPackages.${system}) packwiz; };
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
9
pkgs/crowdsec/default.nix
Normal file
9
pkgs/crowdsec/default.nix
Normal file
|
|
@ -0,0 +1,9 @@
|
||||||
|
{ pkgs }:
|
||||||
|
let
|
||||||
|
sources = pkgs.callPackage ./_sources/generated.nix { };
|
||||||
|
callPackage = pkgs.lib.callPackageWith (pkgs // { inherit sources; });
|
||||||
|
in
|
||||||
|
{
|
||||||
|
hub = callPackage ./hub.nix { };
|
||||||
|
firewall-bouncer = callPackage ./firewall-bouncer.nix { };
|
||||||
|
}
|
||||||
|
|
@ -1,5 +1,5 @@
|
||||||
{ pkgs }:
|
{ pkgs }:
|
||||||
pkgs.lib.packagesFromDirectoryRecursive {
|
{
|
||||||
inherit (pkgs) callPackage;
|
crowdsec = import ./crowdsec { inherit pkgs; };
|
||||||
directory = ./packages;
|
starbound = pkgs.callPackage ./starbound { };
|
||||||
}
|
}
|
||||||
|
|
|
||||||
37
pkgs/starbound/default.nix
Normal file
37
pkgs/starbound/default.nix
Normal file
|
|
@ -0,0 +1,37 @@
|
||||||
|
{
|
||||||
|
stdenv,
|
||||||
|
lib,
|
||||||
|
makeWrapper,
|
||||||
|
patchelf,
|
||||||
|
steamPackages,
|
||||||
|
replace-secret,
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
# Use the directory in which starbound is installed so steamcmd
|
||||||
|
# doesn't have to be reinstalled constantly (we're using DynamicUser
|
||||||
|
# with StateDirectory to persist this).
|
||||||
|
steamcmd = steamPackages.steamcmd.override { steamRoot = "/var/lib/starbound/.steamcmd"; };
|
||||||
|
wrapperPath = lib.makeBinPath [
|
||||||
|
patchelf
|
||||||
|
steamcmd
|
||||||
|
replace-secret
|
||||||
|
];
|
||||||
|
in
|
||||||
|
stdenv.mkDerivation {
|
||||||
|
name = "starbound-update-script";
|
||||||
|
nativeBuildInputs = [ makeWrapper ];
|
||||||
|
dontUnpack = true;
|
||||||
|
patchPhase = ''
|
||||||
|
interpreter="$(cat $NIX_CC/nix-support/dynamic-linker)"
|
||||||
|
substitute ${./launch-starbound.sh} launch-starbound --subst-var interpreter
|
||||||
|
'';
|
||||||
|
installPhase = ''
|
||||||
|
mkdir -p $out/bin
|
||||||
|
cp launch-starbound $out/bin/launch-starbound
|
||||||
|
chmod +x $out/bin/launch-starbound
|
||||||
|
'';
|
||||||
|
postFixup = ''
|
||||||
|
wrapProgram $out/bin/launch-starbound \
|
||||||
|
--prefix PATH : "${wrapperPath}"
|
||||||
|
'';
|
||||||
|
}
|
||||||
32
pkgs/starbound/launch-starbound.sh
Normal file
32
pkgs/starbound/launch-starbound.sh
Normal file
|
|
@ -0,0 +1,32 @@
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
if ! [[ -v STATE_DIRECTORY && -v CREDENTIALS_DIRECTORY ]]; then
|
||||||
|
echo "Error: Runtime dir or credential not set"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Update the server to the latest version
|
||||||
|
echo "Updating/installing starbound"
|
||||||
|
|
||||||
|
mkdir -p "${STATE_DIRECTORY}/.steamcmd"
|
||||||
|
steamcmd <<EOF
|
||||||
|
force_install_dir $STATE_DIRECTORY
|
||||||
|
login tlater $(cat "$CREDENTIALS_DIRECTORY/steam")
|
||||||
|
app_update 211820
|
||||||
|
quit
|
||||||
|
EOF
|
||||||
|
|
||||||
|
echo "Updating config"
|
||||||
|
if [ -f "$1" ]; then
|
||||||
|
mkdir -p ./storage
|
||||||
|
cp "$1" ./storage/starbound_server.config
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Running starbound server"
|
||||||
|
patchelf --set-interpreter '@interpreter@' ./linux/starbound_server
|
||||||
|
# Must be run from the directory that the binary is in (why do game
|
||||||
|
# devs do this?)
|
||||||
|
cd linux
|
||||||
|
./starbound_server
|
||||||
|
|
@ -1,23 +0,0 @@
|
||||||
use std/log
|
|
||||||
|
|
||||||
let packages_with_updatescript = (
|
|
||||||
nix flake show --json
|
|
||||||
| from json
|
|
||||||
| $in.packages.x86_64-linux
|
|
||||||
| columns
|
|
||||||
| filter {|p| nix eval $'.#($p)' --apply 'builtins.hasAttr "updateScript"' | $in == 'true' }
|
|
||||||
)
|
|
||||||
|
|
||||||
for $package in $packages_with_updatescript {
|
|
||||||
log info $'Updating ($package)'
|
|
||||||
nix run $'.#($package).updateScript'
|
|
||||||
}
|
|
||||||
|
|
||||||
log info 'Committing changes'
|
|
||||||
|
|
||||||
try {
|
|
||||||
git add pkgs
|
|
||||||
git commit -m 'update(pkgs): Update sources of all downstream packages'
|
|
||||||
} catch {
|
|
||||||
log warning 'No changes to commit'
|
|
||||||
}
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue