1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
|
{ env, ruby_2_5, bundlerEnv, defaultGemConfig, fetchedGithub, stdenv, writeText, pkgs }:
let
varDir = "/var/lib/mastodon_immae";
socketsDir = "/run/mastodon";
gems = bundlerEnv {
name = "mastodon-env";
ruby = ruby_2_5;
gemset = ./gemset.nix;
gemdir = (fetchedGithub ./mastodon.json).src;
groups = [ "default" "production" "test" "development" ];
gemConfig = defaultGemConfig // {
cld3 = attrs: {
buildInputs = with pkgs; [ protobuf protobufc pkgconfig ];
};
idn-ruby = attrs: {
buildInputs = with pkgs; [ libidn ];
};
rpam2 = attrs: {
buildInputs = with pkgs; [ pam ];
};
};
};
yarnModules = let
info = fetchedGithub ./mastodon.json;
in
pkgs.yarn2nix.mkYarnModules {
name = "mastodon-yarn-modules";
packageJSON = "${info.src}/package.json";
yarnLock = "${info.src}/yarn.lock";
yarnNix = ./yarn-packages.nix;
pkgConfig = {
uws = {
postInstall = ''
node-gyp rebuild > build_log.txt 2>&1 || true
'';
buildInputs = with pkgs; [ nodePackages.node-gyp ];
};
node-zopfli = {
postInstall = ''
node-pre-gyp install --fallback-to-build
'';
buildInputs = with pkgs; [ nodePackages.node-pre-gyp ];
};
node-sass = {
buildInputs = with pkgs; [ binutils libsass python ];
postInstall = let
nodeHeaders = pkgs.fetchurl {
url = "https://nodejs.org/download/release/v${pkgs.nodejs.version}/node-v${pkgs.nodejs.version}-headers.tar.gz";
sha256 = "12zzsf8my43b8qnlacp871ih5vqafl2vlpqp51xp6h3gckn2frwy";
};
in
''
export AR=${pkgs.binutils.bintools}/bin/ar
node scripts/build.js --tarball=${nodeHeaders}
'';
};
};
};
mastodon = stdenv.mkDerivation (fetchedGithub ./mastodon.json // rec {
installPhase = ''
cp -a . $out
cp -a ${yarnModules}/node_modules $out
'';
buildInputs = [ yarnModules gems ];
});
config = writeText "mastodon_environment" ''
REDIS_HOST=${env.redis.host}
REDIS_PORT=${env.redis.port}
REDIS_DB=${env.redis.db}
DB_HOST=${env.postgresql.socket}
DB_USER=${env.postgresql.user}
DB_NAME=${env.postgresql.database}
DB_PASS=${env.postgresql.password}
DB_PORT=${env.postgresql.port}
LOCAL_DOMAIN=mastodon.immae.eu
LOCAL_HTTPS=true
ALTERNATE_DOMAINS=immae.eu
PAPERCLIP_SECRET=${env.paperclip_secret}
SECRET_KEY_BASE=${env.secret_key_base}
OTP_SECRET=${env.otp_secret}
VAPID_PRIVATE_KEY=${env.vapid.private}
VAPID_PUBLIC_KEY=${env.vapid.public}
SMTP_SERVER=mail.immae.eu
SMTP_PORT=587
SMTP_FROM_ADDRESS=notifications@mastodon.immae.eu
SMTP_DELIVERY_METHOD=smtp
PAPERCLIP_ROOT_PATH=${varDir}
STREAMING_CLUSTER_NUM=1
# LDAP authentication (optional)
LDAP_ENABLED=true
LDAP_HOST=ldap.immae.eu
LDAP_PORT=636
LDAP_METHOD=simple_tls
LDAP_BASE="dc=immae,dc=eu"
LDAP_BIND_DN="cn=mastodon,ou=services,dc=immae,dc=eu"
LDAP_PASSWORD="${env.ldap.password}"
LDAP_UID="uid"
LDAP_SEARCH_FILTER="(&(%{uid}=%{email})(memberOf=cn=users,cn=mastodon,ou=services,dc=immae,dc=eu))"
'';
railsRoot = stdenv.mkDerivation {
name = "mastodon_immae";
inherit config mastodon;
builder = writeText "build_mastodon_immae" ''
source $stdenv/setup
set -a
source $config
set +a
cp -a $mastodon $out
cd $out
chmod u+rwX . public
RAILS_ENV=production ${gems}/bin/rails assets:precompile
rm -rf tmp/cache
ln -sf ../../../../../../../${varDir}/tmp/cache tmp
'';
buildInputs = [ gems gems.ruby pkgs.nodejs pkgs.yarn ];
};
in
{
inherit railsRoot config varDir socketsDir gems;
nodeSocket = "${socketsDir}/live_immae_node.sock";
railsSocket = "${socketsDir}/live_immae_puma.sock";
}
|