rhi

Coordinated trade for connected markets
git clone https://radroots.dev/git/rhi.git
Log | Files | Refs | README | LICENSE

flake.nix (6240B)


      1 {
      2   description = "RHI evidence reconciliation and attestation service";
      3 
      4   inputs = {
      5     # Crane 0.23+ currently asks nixpkgs' Cargo vendor helper to fetch
      6     # semver-build-metadata crate versions through the crates.io API. That
      7     # endpoint rejects the literal `+`; the immutable v0.22.0 input avoids
      8     # that upstream fetch defect while preserving the same locked sources.
      9     crane.url = "github:ipetkov/crane/01bc1d404a51a0a07e9d8759cd50a7903e218c82";
     10     lib = {
     11       url = "github:radrootslabs/lib/055096853fca95e15d0f813d33a14aca13be3881";
     12       inputs.crane.follows = "crane";
     13     };
     14     nixpkgs.follows = "lib/nixpkgs";
     15     rust-overlay.follows = "lib/rust-overlay";
     16   };
     17 
     18   outputs =
     19     {
     20       self,
     21       crane,
     22       lib,
     23       nixpkgs,
     24       rust-overlay,
     25       ...
     26     }:
     27     let
     28       systems = lib.lib.supportedSystems;
     29       forAllSystems = function:
     30         builtins.listToAttrs (
     31           map (system: {
     32             name = system;
     33             value = function system;
     34           }) systems
     35         );
     36       serviceOutputs =
     37         system:
     38         let
     39           pkgs = import nixpkgs {
     40             inherit system;
     41             overlays = [ rust-overlay.overlays.default ];
     42           };
     43           helpers = lib.lib.mkServiceHelpers system;
     44           toolchain = helpers.mkToolchain {
     45             rustToolchainFile = ./rust-toolchain.toml;
     46           };
     47           nativeInputs = helpers.mkNativeInputs { };
     48           craneLib = (crane.mkLib pkgs).overrideToolchain toolchain;
     49           source = pkgs.lib.cleanSourceWith {
     50             src = ./.;
     51             filter =
     52               path: type:
     53               craneLib.filterCargoSources path type
     54               || pkgs.lib.hasSuffix ".json" (baseNameOf path)
     55               || baseNameOf path == "README";
     56             name = "rhi-source";
     57           };
     58           commonArgs = {
     59             src = source;
     60             cargoLock = ./Cargo.lock;
     61             strictDeps = true;
     62             nativeBuildInputs = nativeInputs.nativeBuildInputs;
     63             buildInputs = nativeInputs.buildInputs;
     64             env = nativeInputs.environment;
     65             doCheck = false;
     66           };
     67           cargoArtifacts = craneLib.buildDepsOnly commonArgs;
     68           package = craneLib.buildPackage (
     69             commonArgs
     70             // {
     71               inherit cargoArtifacts;
     72               pname = "rhi";
     73               version = "0.1.0";
     74               CARGO_PROFILE = "release";
     75               cargoExtraArgs = "--locked --package rhi --bin rhi";
     76             }
     77           );
     78           mkCargoCheck =
     79             name: command: extraArgs:
     80             craneLib.mkCargoDerivation (
     81               commonArgs
     82               // extraArgs
     83               // {
     84                 inherit cargoArtifacts;
     85                 pname = "rhi-${name}";
     86                 version = "1";
     87                 buildPhaseCargoCommand = command;
     88                 installPhaseCommand = "mkdir -p $out";
     89               }
     90             );
     91           checks = {
     92             fmt = craneLib.cargoFmt (
     93               commonArgs
     94               // {
     95                 pname = "rhi-fmt";
     96                 version = "1";
     97               }
     98             );
     99             check = mkCargoCheck "check" "cargo check --workspace --all-targets --locked" { };
    100             test = mkCargoCheck "test" "cargo test --workspace --all-targets --locked" { };
    101             clippy = mkCargoCheck "clippy" "cargo clippy --workspace --all-targets --locked -- -D warnings" { };
    102             docs = mkCargoCheck "docs" "cargo doc --workspace --no-deps --locked" {
    103               RUSTDOCFLAGS = "-D warnings";
    104             };
    105             config = package;
    106             integration = package;
    107             package = package;
    108             source-lock = package;
    109             sqlx = package;
    110           };
    111           apps = helpers.mkServiceApps {
    112             serviceName = "rhi";
    113             binaryName = "rhi";
    114             inherit nativeInputs package toolchain;
    115             releaseAcceptanceCommand = ''
    116               ${package}/bin/rhi \
    117                 --profile repo-local \
    118                 --instance nix-release-acceptance \
    119                 --repo-local-root "$PWD" \
    120                 config schema >/dev/null
    121             '';
    122           };
    123           devShells.default = helpers.mkServiceDevShell {
    124             serviceName = "rhi";
    125             inherit nativeInputs toolchain;
    126           };
    127           oci = helpers.mkServiceOciImage {
    128             serviceName = "rhi";
    129             binaryName = "rhi";
    130             inherit package;
    131             buildInfo = {
    132               serviceVersion = "0.1.0";
    133               serviceCommit = self.rev or "0000000000000000000000000000000000000000";
    134               libRevision = "055096853fca95e15d0f813d33a14aca13be3881";
    135               rustVersion = "1.97.1";
    136               target = "x86_64-unknown-linux-gnu";
    137               featureProfile = "service-host";
    138               contractVersions = {
    139                 config = 1;
    140                 state = 11;
    141                 admin = 1;
    142                 status = 1;
    143                 provider = 1;
    144               };
    145             };
    146           };
    147         in
    148         helpers.mkServiceOutputs {
    149           serviceName = "rhi";
    150           inherit
    151             apps
    152             checks
    153             devShells
    154             nativeInputs
    155             package
    156             ;
    157           extraPackages = if system == "x86_64-linux" then { inherit oci; } else { };
    158         };
    159     in
    160     {
    161       packages = forAllSystems (system: (serviceOutputs system).packages);
    162       apps = forAllSystems (system: (serviceOutputs system).apps);
    163       checks = forAllSystems (system: (serviceOutputs system).checks);
    164       devShells = forAllSystems (system: (serviceOutputs system).devShells);
    165 
    166       nixosModules.default =
    167         let
    168           helpers = lib.lib.mkServiceHelpers "x86_64-linux";
    169         in
    170         helpers.mkServiceNixosModule {
    171           serviceName = "rhi";
    172           binaryName = "rhi";
    173           packageFor = _pkgs: self.packages.x86_64-linux.default;
    174           commandForInstance = instance: [
    175             "--profile"
    176             "service-host"
    177             "--instance"
    178             instance
    179             "--config"
    180             "/etc/radroots/services/rhi/${instance}/config.toml"
    181             "run"
    182           ];
    183         };
    184     };
    185 }