1 { env, ruby_2_6, bundlerEnv, defaultGemConfig, yarn2nixPackage, fetchedGithub, stdenv, writeText, pkgs }:
3 varDir = "/var/lib/mastodon_immae";
4 socketsDir = "/run/mastodon";
9 gemdir = (fetchedGithub ./mastodon.json).src;
10 groups = [ "default" "production" "test" "development" ];
11 gemConfig = defaultGemConfig // {
14 sed -i 's!s\.files.*!!' redis-rack.gemspec
19 sed -i 's!s\.files.*!!' tzinfo.gemspec
23 buildInputs = with pkgs; [ protobuf protobufc pkgconfig ];
26 buildInputs = with pkgs; [ libidn ];
29 buildInputs = with pkgs; [ pam ];
34 info = fetchedGithub ./mastodon.json;
35 packagejson = pkgs.runCommand "package.json" { buildInputs = [ pkgs.jq ]; } ''
36 cat ${info.src}/package.json | jq -r '.version = "${info.version}"' > $out
39 yarn2nixPackage.mkYarnModules rec {
40 name = "mastodon-yarn";
42 version = info.version;
43 packageJSON = packagejson;
44 yarnLock = "${info.src}/yarn.lock";
45 yarnNix = ./yarn-packages.nix;
49 npx node-gyp rebuild > build_log.txt 2>&1 || true
54 mastodon = stdenv.mkDerivation (fetchedGithub ./mastodon.json // rec {
57 cp -a ${yarnModules}/node_modules $out
59 buildInputs = [ yarnModules ];
61 keys.tools-mastodon = {
62 destDir = "/run/keys/webapps";
67 REDIS_HOST=${env.redis.host}
68 REDIS_PORT=${env.redis.port}
69 REDIS_DB=${env.redis.db}
70 DB_HOST=${env.postgresql.socket}
71 DB_USER=${env.postgresql.user}
72 DB_NAME=${env.postgresql.database}
73 DB_PASS=${env.postgresql.password}
74 DB_PORT=${env.postgresql.port}
76 LOCAL_DOMAIN=mastodon.immae.eu
78 ALTERNATE_DOMAINS=immae.eu
80 PAPERCLIP_SECRET=${env.paperclip_secret}
81 SECRET_KEY_BASE=${env.secret_key_base}
82 OTP_SECRET=${env.otp_secret}
84 VAPID_PRIVATE_KEY=${env.vapid.private}
85 VAPID_PUBLIC_KEY=${env.vapid.public}
87 SMTP_DELIVERY_METHOD=sendmail
88 SMTP_FROM_ADDRESS=mastodon@tools.immae.eu
89 SENDMAIL_LOCATION="/run/wrappers/bin/sendmail"
90 PAPERCLIP_ROOT_PATH=${varDir}
92 STREAMING_CLUSTER_NUM=1
96 # LDAP authentication (optional)
98 LDAP_HOST=ldap.immae.eu
100 LDAP_METHOD=simple_tls
101 LDAP_BASE="dc=immae,dc=eu"
102 LDAP_BIND_DN="cn=mastodon,ou=services,dc=immae,dc=eu"
103 LDAP_PASSWORD="${env.ldap.password}"
105 LDAP_SEARCH_FILTER="(&(%{uid}=%{email})(memberOf=cn=users,cn=mastodon,ou=services,dc=immae,dc=eu))"
109 # FIXME: build machine will contain some passwords in the nix store
110 railsRoot = stdenv.mkDerivation {
111 name = "mastodon_immae";
113 builder = writeText "build_mastodon_immae" ''
116 ${keys.tools-mastodon.text}
121 chmod -R u+rwX config/
122 sed -i -e 's@^end$@ config.action_mailer.sendmail_settings = { location: ENV.fetch("SENDMAIL_LOCATION", "/usr/sbin/sendmail") }\nend@' config/environments/production.rb
123 RAILS_ENV=production ${gems}/bin/rails assets:precompile
125 ln -sf ${varDir}/tmp/cache tmp
127 buildInputs = [ gems gems.ruby pkgs.nodejs pkgs.yarn ];
131 inherit railsRoot keys varDir socketsDir gems;
132 nodeSocket = "${socketsDir}/live_immae_node.sock";
133 railsSocket = "${socketsDir}/live_immae_puma.sock";