Files
oott/nix/package.nix
T
rzuastiandClaude Opus 4.8 20c51faaea Build front-end via Nix and harden Docker/Nix image generation
- Build the Flutter web app at release time (nix/frontend.nix) and bundle
  it next to the binary at $out/share/oott/web; resolve it at runtime
  relative to the executable. Remove the prebuilt backend/web from git.
- Add web_server.{ip_address,port,api_key} options to the NixOS module so
  the generated config deserializes (was missing, causing a startup panic).
- Docker image: set SSL_CERT_FILE for outbound TLS, drop the heavy
  nixos/nix base image, trim contents to [oott cacert], and ensure /tmp
  exists.
- Remove the unused "nix" flake input and commit flake.lock.
- Provide Swagger UI to utoipa-swagger-ui offline via a pinned fetchurl so
  the package builds in the Nix sandbox; skip the redundant check phase
  (tests run via backend/run_tests.sh).
- sample_oott.toml: set database.path to /db/oott.db for the Docker image.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-01 21:43:08 -04:00

37 lines
1.3 KiB
Nix

{
pkgs,
oott-frontend,
}: let
# utoipa-swagger-ui's build script downloads Swagger UI from GitHub at build
# time, which fails in Nix's network-free sandbox. Fetch the pinned archive
# (the version bundled with utoipa-swagger-ui 9.0.2) and point the crate at it.
swaggerUi = pkgs.fetchurl {
url = "https://github.com/swagger-api/swagger-ui/archive/refs/tags/v5.17.14.zip";
hash = "sha256-SBJE0IEgl7Efuu73n3HZQrFxYX+cn5UU5jrL4T5xzNw=";
};
in
pkgs.rustPlatform.buildRustPackage rec {
pname = "oott";
version = "0.1.0";
src = ./../backend;
cargoLock = {
lockFile = ./../backend/Cargo.lock;
};
nativeBuildInputs = [pkgs.pkg-config];
PKG_CONFIG_PATH = "${pkgs.openssl.dev}/lib/pkgconfig";
SWAGGER_UI_DOWNLOAD_URL = "file://${swaggerUi}";
# The test suite is run separately via `backend/run_tests.sh`; this is an
# artifact build. Skipping the check phase also avoids re-running the
# utoipa-swagger-ui build script against its read-only OUT_DIR copy.
doCheck = false;
# Bundle the Flutter web build next to the binary. The backend resolves it at
# runtime via `<exe_dir>/../share/oott/web` (see web_server::resolve_web_root).
postInstall = ''
mkdir -p $out/share/oott
cp -r --no-preserve=mode ${oott-frontend} $out/share/oott/web
'';
}