]> git.immae.eu Git - perso/Immae/Config/Nix.git/blob - mastodon.nix
d4e437ac67cbcda1a2a4ac264df7093d1dde6b27
[perso/Immae/Config/Nix.git] / mastodon.nix
1 { env, ruby_2_6, bundlerEnv, defaultGemConfig, yarn2nixPackage, fetchedGithub, stdenv, writeText, pkgs }:
2 let
3 varDir = "/var/lib/mastodon_immae";
4 socketsDir = "/run/mastodon";
5 gems = bundlerEnv {
6 name = "mastodon-env";
7 ruby = ruby_2_6;
8 gemset = ./gemset.nix;
9 gemdir = (fetchedGithub ./mastodon.json).src;
10 groups = [ "default" "production" "test" "development" ];
11 gemConfig = defaultGemConfig // {
12 redis-rack = attrs: {
13 preBuild = ''
14 sed -i 's!s\.files.*!!' redis-rack.gemspec
15 '';
16 };
17 tzinfo = attrs: {
18 preBuild = ''
19 sed -i 's!s\.files.*!!' tzinfo.gemspec
20 '';
21 };
22 cld3 = attrs: {
23 buildInputs = with pkgs; [ protobuf protobufc pkgconfig ];
24 };
25 idn-ruby = attrs: {
26 buildInputs = with pkgs; [ libidn ];
27 };
28 rpam2 = attrs: {
29 buildInputs = with pkgs; [ pam ];
30 };
31 };
32 };
33 yarnModules = let
34 info = fetchedGithub ./mastodon.json;
35 packagejson = pkgs.runCommand "package.json" { buildInputs = [ pkgs.jq ]; } ''
36 cat ${info.src}/package.json | jq -r '.version = "${info.version}"' > $out
37 '';
38 in
39 yarn2nixPackage.mkYarnModules rec {
40 name = "mastodon-yarn";
41 pname = name;
42 version = info.version;
43 packageJSON = packagejson;
44 yarnLock = "${info.src}/yarn.lock";
45 yarnNix = ./yarn-packages.nix;
46 pkgConfig = {
47 uws = {
48 postInstall = ''
49 npx node-gyp rebuild > build_log.txt 2>&1 || true
50 '';
51 };
52 };
53 };
54 mastodon = stdenv.mkDerivation (fetchedGithub ./mastodon.json // rec {
55 installPhase = ''
56 cp -a . $out
57 cp -a ${yarnModules}/node_modules $out
58 '';
59 buildInputs = [ yarnModules ];
60 });
61 config = writeText "mastodon_environment" ''
62 REDIS_HOST=${env.redis.host}
63 REDIS_PORT=${env.redis.port}
64 REDIS_DB=${env.redis.db}
65 DB_HOST=${env.postgresql.socket}
66 DB_USER=${env.postgresql.user}
67 DB_NAME=${env.postgresql.database}
68 DB_PASS=${env.postgresql.password}
69 DB_PORT=${env.postgresql.port}
70
71 LOCAL_DOMAIN=mastodon.immae.eu
72 LOCAL_HTTPS=true
73 ALTERNATE_DOMAINS=immae.eu
74
75 PAPERCLIP_SECRET=${env.paperclip_secret}
76 SECRET_KEY_BASE=${env.secret_key_base}
77 OTP_SECRET=${env.otp_secret}
78
79 VAPID_PRIVATE_KEY=${env.vapid.private}
80 VAPID_PUBLIC_KEY=${env.vapid.public}
81
82 SMTP_DELIVERY_METHOD=sendmail
83 SMTP_FROM_ADDRESS=notifications@mastodon.immae.eu
84 SENDMAIL_LOCATION="/run/wrappers/bin/sendmail"
85 PAPERCLIP_ROOT_PATH=${varDir}
86
87 STREAMING_CLUSTER_NUM=1
88
89 RAILS_LOG_LEVEL=warn
90
91 # LDAP authentication (optional)
92 LDAP_ENABLED=true
93 LDAP_HOST=ldap.immae.eu
94 LDAP_PORT=636
95 LDAP_METHOD=simple_tls
96 LDAP_BASE="dc=immae,dc=eu"
97 LDAP_BIND_DN="cn=mastodon,ou=services,dc=immae,dc=eu"
98 LDAP_PASSWORD="${env.ldap.password}"
99 LDAP_UID="uid"
100 LDAP_SEARCH_FILTER="(&(%{uid}=%{email})(memberOf=cn=users,cn=mastodon,ou=services,dc=immae,dc=eu))"
101 '';
102
103 railsRoot = stdenv.mkDerivation {
104 name = "mastodon_immae";
105 inherit config mastodon;
106 builder = writeText "build_mastodon_immae" ''
107 source $stdenv/setup
108 set -a
109 source $config
110 set +a
111 cp -a $mastodon $out
112 cd $out
113 chmod u+rwX . public
114 chmod -R u+rwX config/
115 sed -i -e 's@^end$@ config.action_mailer.sendmail_settings = { location: ENV.fetch("SENDMAIL_LOCATION", "/usr/sbin/sendmail") }\nend@' config/environments/production.rb
116 RAILS_ENV=production ${gems}/bin/rails assets:precompile
117 rm -rf tmp/cache
118 ln -sf ${varDir}/tmp/cache tmp
119 '';
120 buildInputs = [ gems gems.ruby pkgs.nodejs pkgs.yarn ];
121 };
122 in
123 {
124 inherit railsRoot config varDir socketsDir gems;
125 nodeSocket = "${socketsDir}/live_immae_node.sock";
126 railsSocket = "${socketsDir}/live_immae_puma.sock";
127 }