flake.nix
1{
2 description = "secrets - age-encrypted secrets with a path-like, tag-friendly layout";
3
4 inputs = {
5 nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
6 flake-utils.url = "github:numtide/flake-utils";
7 };
8
9 outputs =
10 { self, nixpkgs, flake-utils }:
11 flake-utils.lib.eachDefaultSystem (
12 system:
13 let
14 pkgs = nixpkgs.legacyPackages.${system};
15 lib = pkgs.lib;
16
17 version = "1.0.0";
18
19 secrets = pkgs.stdenvNoCC.mkDerivation {
20 pname = "secrets";
21 inherit version;
22 src = ./.;
23
24 nativeBuildInputs = [ pkgs.makeWrapper ];
25
26 dontBuild = true;
27
28 installPhase = ''
29 runHook preInstall
30 install -Dm755 secrets $out/bin/secrets
31 runHook postInstall
32 '';
33
34 # The script shells out to age/age-keygen and coreutils/findutils
35 # utilities. Bundle them on its PATH so it works in a bare dev env
36 # without the consumer having to add them separately.
37 postFixup = ''
38 wrapProgram $out/bin/secrets \
39 --prefix PATH : ${lib.makeBinPath [ pkgs.age pkgs.coreutils pkgs.findutils ]}
40 '';
41
42 meta = with lib; {
43 description = "Manage age-encrypted secrets with a path-like, tag-friendly layout";
44 homepage = "https://git.kilimanjaro.io/secrets";
45 license = licenses.mit;
46 mainProgram = "secrets";
47 platforms = platforms.all;
48 };
49 };
50 in
51 {
52 packages = {
53 inherit secrets;
54 default = secrets;
55 };
56
57 apps.default = flake-utils.lib.mkApp {
58 drv = secrets;
59 exePath = "/bin/secrets";
60 };
61
62 # `nixpkgs.overlays = [ secrets.overlays.default ];` then use pkgs.secrets.
63 overlays.default = final: _prev: {
64 secrets = self.packages.${final.stdenv.hostPlatform.system}.default;
65 };
66
67 # For hacking on the script itself. Consumers who only want the tool
68 # should add `secrets.packages.${system}.default` to their own shell.
69 devShells.default = pkgs.mkShell {
70 packages = [
71 secrets
72 pkgs.age
73 pkgs.shellcheck
74 ];
75 };
76 }
77 );
78}