mirror of
https://github.com/rzuasti/oott.git
synced 2026-07-08 19:21:54 +02:00
Build front-end via Nix and harden Docker/Nix image generation
- Build the Flutter web app at release time (nix/frontend.nix) and bundle
it next to the binary at $out/share/oott/web; resolve it at runtime
relative to the executable. Remove the prebuilt backend/web from git.
- Add web_server.{ip_address,port,api_key} options to the NixOS module so
the generated config deserializes (was missing, causing a startup panic).
- Docker image: set SSL_CERT_FILE for outbound TLS, drop the heavy
nixos/nix base image, trim contents to [oott cacert], and ensure /tmp
exists.
- Remove the unused "nix" flake input and commit flake.lock.
- Provide Swagger UI to utoipa-swagger-ui offline via a pinned fetchurl so
the package builds in the Nix sandbox; skip the redundant check phase
(tests run via backend/run_tests.sh).
- sample_oott.toml: set database.path to /db/oott.db for the Docker image.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
a90bcc360d
commit
20c51faaea
+34
-10
@@ -1,12 +1,36 @@
|
||||
{pkgs}:
|
||||
pkgs.rustPlatform.buildRustPackage rec {
|
||||
pname = "oott";
|
||||
version = "0.0.1";
|
||||
src = ./../backend;
|
||||
cargoLock = {
|
||||
lockFile = ./../backend/Cargo.lock;
|
||||
{
|
||||
pkgs,
|
||||
oott-frontend,
|
||||
}: let
|
||||
# utoipa-swagger-ui's build script downloads Swagger UI from GitHub at build
|
||||
# time, which fails in Nix's network-free sandbox. Fetch the pinned archive
|
||||
# (the version bundled with utoipa-swagger-ui 9.0.2) and point the crate at it.
|
||||
swaggerUi = pkgs.fetchurl {
|
||||
url = "https://github.com/swagger-api/swagger-ui/archive/refs/tags/v5.17.14.zip";
|
||||
hash = "sha256-SBJE0IEgl7Efuu73n3HZQrFxYX+cn5UU5jrL4T5xzNw=";
|
||||
};
|
||||
in
|
||||
pkgs.rustPlatform.buildRustPackage rec {
|
||||
pname = "oott";
|
||||
version = "0.1.0";
|
||||
src = ./../backend;
|
||||
cargoLock = {
|
||||
lockFile = ./../backend/Cargo.lock;
|
||||
};
|
||||
|
||||
nativeBuildInputs = [pkgs.pkg-config];
|
||||
PKG_CONFIG_PATH = "${pkgs.openssl.dev}/lib/pkgconfig";
|
||||
}
|
||||
nativeBuildInputs = [pkgs.pkg-config];
|
||||
PKG_CONFIG_PATH = "${pkgs.openssl.dev}/lib/pkgconfig";
|
||||
SWAGGER_UI_DOWNLOAD_URL = "file://${swaggerUi}";
|
||||
|
||||
# The test suite is run separately via `backend/run_tests.sh`; this is an
|
||||
# artifact build. Skipping the check phase also avoids re-running the
|
||||
# utoipa-swagger-ui build script against its read-only OUT_DIR copy.
|
||||
doCheck = false;
|
||||
|
||||
# Bundle the Flutter web build next to the binary. The backend resolves it at
|
||||
# runtime via `<exe_dir>/../share/oott/web` (see web_server::resolve_web_root).
|
||||
postInstall = ''
|
||||
mkdir -p $out/share/oott
|
||||
cp -r --no-preserve=mode ${oott-frontend} $out/share/oott/web
|
||||
'';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user