Build front-end via Nix and harden Docker/Nix image generation

- Build the Flutter web app at release time (nix/frontend.nix) and bundle
  it next to the binary at $out/share/oott/web; resolve it at runtime
  relative to the executable. Remove the prebuilt backend/web from git.
- Add web_server.{ip_address,port,api_key} options to the NixOS module so
  the generated config deserializes (was missing, causing a startup panic).
- Docker image: set SSL_CERT_FILE for outbound TLS, drop the heavy
  nixos/nix base image, trim contents to [oott cacert], and ensure /tmp
  exists.
- Remove the unused "nix" flake input and commit flake.lock.
- Provide Swagger UI to utoipa-swagger-ui offline via a pinned fetchurl so
  the package builds in the Nix sandbox; skip the redundant check phase
  (tests run via backend/run_tests.sh).
- sample_oott.toml: set database.path to /db/oott.db for the Docker image.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
rzuasti
2026-06-01 21:43:08 -04:00
co-authored by Claude Opus 4.8
parent a90bcc360d
commit 20c51faaea
40 changed files with 138 additions and 166284 deletions
+15
View File
@@ -101,6 +101,21 @@ in {
description = "How long to retain device events and notifications. Records older than this are purged daily. Accepts duration strings (e.g. 90d, 1y, 6m).";
default = "365d";
};
web_server.ip_address = mkOption {
type = types.str;
description = "IP address to bind the web server (API and web UI) to. Use 0.0.0.0 to bind to all interfaces.";
default = "0.0.0.0";
};
web_server.port = mkOption {
type = types.port;
description = "Port the web server listens on.";
default = 3000;
};
web_server.api_key = mkOption {
type = types.str;
description = "API key required to access the system's API. Change this from the default empty value.";
default = "";
};
};
# Service implementation