{ description = "deepsky — a Gemini window onto Bluesky"; inputs = { nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; flake-utils.url = "github:numtide/flake-utils"; }; outputs = { self, nixpkgs, flake-utils }: flake-utils.lib.eachDefaultSystem ( system: let pkgs = import nixpkgs { inherit system; }; # Cosmetic version, derived from the commit. The published image is # tagged from the git tag (TANGLED_REF_NAME) in CI, not this. version = self.shortRev or self.dirtyShortRev or "dev"; # Where the repo lives, so atcr.io can show its README and source link. repoURL = "https://tangled.org/byjp.me/deepsky"; deepsky = pkgs.buildGoModule { pname = "deepsky"; inherit version; src = ./.; # Hash of the fetched Go module sources. Regenerate after changing # go.mod/go.sum with `./scripts/update_flake.sh` (uses Docker, no # local Nix needed). It does NOT change when you edit app code. vendorHash = "sha256-VYG3mj2jKf5OFPMzuX9TFxib8CM27LY1n9wAKnT3J9Y="; env.CGO_ENABLED = 0; ldflags = [ "-s" "-w" ]; # No tests need network; keep the build hermetic and fast. doCheck = true; }; # A minimal OCI image: just the static binary plus CA roots so the # server can verify TLS to the Bluesky AppView, plc.directory, etc. dockerImage = pkgs.dockerTools.buildLayeredImage { name = "deepsky"; tag = "latest"; contents = [ deepsky pkgs.cacert ]; config = { Entrypoint = [ "/bin/deepsky" ]; ExposedPorts = { "1965/tcp" = { }; }; Env = [ "SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt" ]; # atcr.io reads these on push: it fetches io.atcr.readme and shows # the title/description/source/version on the image's page. Labels = { "org.opencontainers.image.title" = "DeepSky"; "org.opencontainers.image.description" = "A Gemini window onto Bluesky."; "org.opencontainers.image.source" = repoURL; "org.opencontainers.image.documentation" = repoURL; "org.opencontainers.image.version" = version; "io.atcr.readme" = "${repoURL}/raw/main/README.md"; }; }; }; in { packages = { default = deepsky; deepsky = deepsky; dockerImage = dockerImage; }; devShells.default = pkgs.mkShell { packages = [ pkgs.go pkgs.skopeo ]; }; } ); }