flake.nix

 1{
 2  description = "secrets - age-encrypted secrets with a path-like, tag-friendly layout";
 3
 4  inputs = {
 5    nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
 6    flake-utils.url = "github:numtide/flake-utils";
 7  };
 8
 9  outputs =
10    { self, nixpkgs, flake-utils }:
11    flake-utils.lib.eachDefaultSystem (
12      system:
13      let
14        pkgs = nixpkgs.legacyPackages.${system};
15        lib = pkgs.lib;
16
17        version = "1.0.0";
18
19        secrets = pkgs.stdenvNoCC.mkDerivation {
20          pname = "secrets";
21          inherit version;
22          src = ./.;
23
24          nativeBuildInputs = [ pkgs.makeWrapper ];
25
26          dontBuild = true;
27
28          installPhase = ''
29            runHook preInstall
30            install -Dm755 secrets $out/bin/secrets
31            runHook postInstall
32          '';
33
34          # The script shells out to age/age-keygen and coreutils/findutils
35          # utilities. Bundle them on its PATH so it works in a bare dev env
36          # without the consumer having to add them separately.
37          postFixup = ''
38            wrapProgram $out/bin/secrets \
39              --prefix PATH : ${lib.makeBinPath [ pkgs.age pkgs.coreutils pkgs.findutils ]}
40          '';
41
42          meta = with lib; {
43            description = "Manage age-encrypted secrets with a path-like, tag-friendly layout";
44            homepage = "https://git.kilimanjaro.io/secrets";
45            license = licenses.mit;
46            mainProgram = "secrets";
47            platforms = platforms.all;
48          };
49        };
50      in
51      {
52        packages = {
53          inherit secrets;
54          default = secrets;
55        };
56
57        apps.default = flake-utils.lib.mkApp {
58          drv = secrets;
59          exePath = "/bin/secrets";
60        };
61
62        # `nixpkgs.overlays = [ secrets.overlays.default ];` then use pkgs.secrets.
63        overlays.default = final: _prev: {
64          secrets = self.packages.${final.stdenv.hostPlatform.system}.default;
65        };
66
67        # For hacking on the script itself. Consumers who only want the tool
68        # should add `secrets.packages.${system}.default` to their own shell.
69        devShells.default = pkgs.mkShell {
70          packages = [
71            secrets
72            pkgs.age
73            pkgs.shellcheck
74          ];
75        };
76      }
77    );
78}