From bd18b624963bea69743a620b2318b4cc87580553 Mon Sep 17 00:00:00 2001 From: Aly Raffauf Date: Mon, 10 Aug 2026 10:46:02 -0400 Subject: [PATCH] chore: build the cattery package via the flake Replace the devShell-only flake with a real buildGoModule package exposed via flake-parts and treefmt-nix. CI now runs nix build and nix flake check instead of shelling out from nix develop; go test runs in a separate job. --- .github/workflows/ci.yml | 24 ++++++----------- README.md | 9 ++++++- flake.lock | 57 +++++++++++++++++++++++++++++++++++++++- flake.nix | 41 +++++++++++++++-------------- flake/default.nix | 7 +++++ flake/devShell.nix | 17 ++++++++++++ flake/packages.nix | 10 +++++++ flake/treefmt.nix | 12 +++++++++ nix/cattery.nix | 30 +++++++++++++++++++++ 9 files changed, 169 insertions(+), 38 deletions(-) create mode 100644 flake/default.nix create mode 100644 flake/devShell.nix create mode 100644 flake/packages.nix create mode 100644 flake/treefmt.nix create mode 100644 nix/cattery.nix diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ff3c02b..12cb6ee 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,8 +12,8 @@ concurrency: cancel-in-progress: true jobs: - build-linux: - name: build-linux + build: + name: build runs-on: ubuntu-22.04 steps: # actions/checkout v7.0.1 @@ -22,22 +22,14 @@ jobs: persist-credentials: false # cachix/install-nix-action v31.11.0 - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 - - run: nix develop -c bash -euo pipefail -c 'CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -o /tmp/cattery-linux-amd64 ./cmd/cattery' - - build-darwin: - name: build-darwin-arm64 - runs-on: ubuntu-22.04 - steps: - # actions/checkout v7.0.1 - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with: - persist-credentials: false - # cachix/install-nix-action v31.11.0 - - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 - - run: nix develop -c bash -euo pipefail -c 'CGO_ENABLED=0 GOOS=darwin GOARCH=arm64 go build -o /tmp/cattery-darwin-arm64 ./cmd/cattery' + extra-nix-config: | + access-tokens = github.com=${{ secrets.GITHUB_TOKEN }} + - run: nix --extra-experimental-features 'nix-command flakes' build .#cattery + - run: nix --extra-experimental-features 'nix-command flakes' flake check - test-linux: - name: test-linux + test: + name: test runs-on: ubuntu-22.04 steps: # actions/checkout v7.0.1 diff --git a/README.md b/README.md index 3e29fec..80aec8f 100644 --- a/README.md +++ b/README.md @@ -17,7 +17,14 @@ Cattery is a single static binary. Build it with Go 1.25 or newer: go build ./cmd/cattery ``` -A Nix flake is provided for development: +Or with the Nix flake: + +``` +nix build +nix run . -- version +``` + +A development shell is also available: ``` nix develop diff --git a/flake.lock b/flake.lock index 6336889..619e7ef 100644 --- a/flake.lock +++ b/flake.lock @@ -1,5 +1,23 @@ { "nodes": { + "flake-parts": { + "inputs": { + "nixpkgs-lib": "nixpkgs-lib" + }, + "locked": { + "lastModified": 1785627969, + "narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, "nixpkgs": { "locked": { "lastModified": 1786313170, @@ -16,9 +34,46 @@ "type": "github" } }, + "nixpkgs-lib": { + "locked": { + "lastModified": 1785031560, + "narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, "root": { "inputs": { - "nixpkgs": "nixpkgs" + "flake-parts": "flake-parts", + "nixpkgs": "nixpkgs", + "treefmt-nix": "treefmt-nix" + } + }, + "treefmt-nix": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1785945821, + "narHash": "sha256-NLSyTCW4K4ofhNBllt3omPasm6QpralXH1DBZOc91Dw=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "ae7910970dddc408fe6ab1c8e4b277bb21d72dc0", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" } } }, diff --git a/flake.nix b/flake.nix index cfcff78..5707fb6 100644 --- a/flake.nix +++ b/flake.nix @@ -1,27 +1,28 @@ { description = "Cattery — a safe, cross-platform dotfiles manager"; - inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; + flake-parts.url = "github:hercules-ci/flake-parts"; - outputs = { self, nixpkgs }: - let - supportedSystems = [ "x86_64-linux" ]; - forAllSystems = function: - nixpkgs.lib.genAttrs supportedSystems (system: function system); - pkgsFor = system: import nixpkgs { inherit system; }; - shellPackages = pkgs: with pkgs; [ go_1_26 just ]; - in - { - devShells = forAllSystems (system: - let pkgs = pkgsFor system; in - { - default = pkgs.mkShell { - packages = shellPackages pkgs; - }; - }); + treefmt-nix = { + url = "github:numtide/treefmt-nix"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + }; + + outputs = inputs @ {flake-parts, ...}: + flake-parts.lib.mkFlake {inherit inputs;} { + systems = [ + "aarch64-linux" + "x86_64-linux" + "aarch64-darwin" + "x86_64-darwin" + ]; - checks = forAllSystems (system: { - devShell = self.devShells.${system}.default; - }); + imports = [ + ./flake + inputs.treefmt-nix.flakeModule + ]; }; } diff --git a/flake/default.nix b/flake/default.nix new file mode 100644 index 0000000..a1ab094 --- /dev/null +++ b/flake/default.nix @@ -0,0 +1,7 @@ +{ + imports = [ + ./devShell.nix + ./packages.nix + ./treefmt.nix + ]; +} diff --git a/flake/devShell.nix b/flake/devShell.nix new file mode 100644 index 0000000..f35a83a --- /dev/null +++ b/flake/devShell.nix @@ -0,0 +1,17 @@ +_: { + perSystem = { + config, + lib, + pkgs, + ... + }: { + devShells.default = pkgs.mkShell { + packages = + (with pkgs; [ + go_1_26 + just + ]) + ++ lib.attrValues config.treefmt.build.programs; + }; + }; +} diff --git a/flake/packages.nix b/flake/packages.nix new file mode 100644 index 0000000..297d8b3 --- /dev/null +++ b/flake/packages.nix @@ -0,0 +1,10 @@ +_: { + perSystem = {pkgs, ...}: let + cattery = pkgs.callPackage ../nix/cattery.nix {}; + in { + packages = { + inherit cattery; + default = cattery; + }; + }; +} diff --git a/flake/treefmt.nix b/flake/treefmt.nix new file mode 100644 index 0000000..06dd603 --- /dev/null +++ b/flake/treefmt.nix @@ -0,0 +1,12 @@ +_: { + perSystem = _: { + treefmt.config = { + programs = { + alejandra.enable = true; + deadnix.enable = true; + gofmt.enable = true; + statix.enable = true; + }; + }; + }; +} diff --git a/nix/cattery.nix b/nix/cattery.nix new file mode 100644 index 0000000..18b27f2 --- /dev/null +++ b/nix/cattery.nix @@ -0,0 +1,30 @@ +{ + buildGoModule, + lib, +}: +buildGoModule { + pname = "cattery"; + version = "dev"; + src = ../.; + proxyVendor = true; + vendorHash = "sha256-UIGv/yN4FHE9smAgvsjDpnKyPXbjewPs5x4q2aOiFlE="; + subPackages = ["cmd/cattery"]; + + # The unit and integration suites shell out to `go build` and run real + # subprocesses, which doesn't fit the hermetic build sandbox. CI runs + # `go test ./...` against a full Go toolchain instead. + doCheck = false; + + ldflags = [ + "-s" + "-w" + ]; + + meta = with lib; { + description = "Safe, cross-platform dotfiles manager"; + homepage = "https://github.com/alyraffauf/cattery"; + license = licenses.mit; + platforms = platforms.unix; + mainProgram = "cattery"; + }; +} -- 2.51.2