diff --git a/Rocket.toml b/Rocket.toml index 78a6b2f..324f089 100644 --- a/Rocket.toml +++ b/Rocket.toml @@ -6,4 +6,3 @@ public_url = "https://localhost:8000" [release] address = "127.0.0.1" port = 8000 -public_url = "https://crashkeys.dev" diff --git a/flake.nix b/flake.nix index dc7e3f6..0c14470 100644 --- a/flake.nix +++ b/flake.nix @@ -6,35 +6,124 @@ naersk.inputs.nixpkgs.follows = "nixpkgs"; }; - outputs = { self, nixpkgs, naersk }: - let - supportedSystems = [ "x86_64-linux" "aarch64-linux" "x86_64-darwin" "aarch64-darwin" ]; - forAllSystems = nixpkgs.lib.genAttrs supportedSystems; - in - { - packages = forAllSystems (system: - let - pkgs = (import nixpkgs) { - inherit system; - }; - cargo-toml = builtins.fromTOML (builtins.readFile ./Cargo.toml); - naersk' = pkgs.callPackage naersk {}; - app = naersk'.buildPackage { - src = ./.; - }; - in { - default = app; + outputs = + { + self, + nixpkgs, + naersk, + }: + let + supportedSystems = [ + "x86_64-linux" + "aarch64-linux" + "x86_64-darwin" + "aarch64-darwin" + ]; + forAllSystems = nixpkgs.lib.genAttrs supportedSystems; + cargo-toml = builtins.fromTOML (builtins.readFile ./Cargo.toml); + in + { + packages = forAllSystems ( + system: + let + pkgs = (import nixpkgs) { + inherit system; + }; + naersk' = pkgs.callPackage naersk { }; + app = naersk'.buildPackage { + src = ./.; + postInstall = '' + cp -r ./templates ./static $out + ''; + }; + in + { + default = app; docker = pkgs.dockerTools.streamLayeredImage { name = "localhost/${cargo-toml.package.name}"; tag = "latest"; - contents = [ app pkgs.bash ]; + contents = [ + app + pkgs.bash + ]; config.Cmd = [ "${app}/bin/${cargo-toml.package.name}" ]; }; - }); + } + ); - # For `nix develop` (optional, can be skipped): - devShells = - forAllSystems (system: + nixosModules.default = + { config, lib, ... }: + let + cfg = config.crashkeys.services.audsite; + in + { + options = { + crashkeys.services.audsite = { + enable = lib.mkEnableOption "Enables the crashkeys.dev web server"; + system = lib.mkOption { + type = lib.types.enum [ supportedSystems ]; + example = "x86_64-linux"; + description = "The architecture of the system for which to run the web server."; + }; + package = lib.mkOption { + type = lib.types.package; + default = self.packages.${cfg.system}.default; + description = "The Nix package corresponding to the web server to run."; + }; + public_url = lib.mkOption { + type = lib.types.str; + default = "https://crashkeys.dev"; + example = "https://crashkeys.dev"; + description = "The base public URL the site will be available at."; + }; + address = lib.mkOption { + type = lib.types.str; + default = "127.0.0.1"; + example = "127.0.0.1"; + description = "The IP address which the web server will bind to."; + }; + port = lib.mkOption { + type = lib.types.port; + default = 8000; + example = 8000; + description = "The TCP port on which the web server will be exposed."; + }; + }; + }; + config = lib.mkIf cfg.enable { + systemd.services."crashkeys.audsite" = { + wantedBy = [ "multi-user.target" ]; + serviceConfig = + let + pkg = cfg.package; + in + { + Restart = "on-failure"; + ExecStart = "${pkg}/bin/${cargo-toml.project.name}"; + DynamicUser = "yes"; + RuntimeDirectory = "${pkg}"; + RuntimeDirectoryMode = "0555"; + StateDirectory = "crashkeys.audsite"; + StateDirectoryMode = "0700"; + CacheDirectory = "crashkeys.audsite"; + CacheDirectoryMode = "0750"; + BindReadOnlyPaths = [ + "${pkg}" + "/nix/store" + ]; + Environment = [ + "ROCKET_ADDRESS=${cfg.address}" + "ROCKET_PORT=${cfg.port}" + "ROCKET_PUBLIC_URL=${cfg.public_url}" + ]; + }; + }; + }; + }; + + # For `nix develop` (optional, can be skipped): + devShells = forAllSystems ( + system: let pkgs = (import nixpkgs) { inherit system; @@ -42,8 +131,23 @@ in { default = pkgs.mkShell { - nativeBuildInputs = with pkgs; [ rustc cargo jujutsu ]; + nativeBuildInputs = with pkgs; [ + rustc + cargo + jujutsu + ]; }; - }); - }; + } + ); + + formatter = forAllSystems ( + system: + let + pkgs = (import nixpkgs) { + inherit system; + }; + in + pkgs.nixfmt-tree + ); + }; }