Package sovrnd and backup-route-sync with Nix
closedBuild every sovrn-owned binary with Nix so hosts get store paths, not controller-built copies patched with patchelf.
Sketch:
- nix/pkgs/sovrnd.nix via buildGoModule (vendorHash). Generated/embedded assets (templ, tailwind, htmx) must be inputs, so a stale-asset build is impossible; this replaces just gen-check as a deploy gate.
- nix/pkgs/backup-route-sync.nix (cmd/backup-route-sync).
- ZDS already exists (nix/pkgs/zds.nix).
- Expose them as flake outputs and as an overlay the NixOS modules consume.
- Binary cache for our own packages: attic, cachix, or just build on the deployer. Decide; these builds are small next to Stalwart.
- Retire after cutover: just build-stalwart, nix/pkgs/stalwart.nix + stalwart-Cargo.lock (nixpkgs stalwart_0_16 replaces them), the glibc-ceiling checks, and the patchelf tasks.
Done when nix build .#sovrnd .#backup-route-sync .#zds succeeds on x86_64 and aarch64.
1 Comment
Done (pending review)
nix/pkgs/go-commands.nix: a singlebuildGoModulebuildscmd/sovrnd,cmd/backup-route-syncandcmd/metrics-healthz, with cgo on for mattn/go-sqlite3.sovrnd,backup-route-syncandmetrics-healthzare the same store path, each with its ownmeta.mainProgram.//update on purpose.lib.addMetaAttrsandoverrideAttrspush mainProgram intoNIX_MAIN_PROGRAMand would build the module three times.go.mod,go.sum,*.go,api/,cmd/,internal/. Edits to site/, nix/, docs or deployment don’t rebuild.just gen-checkin CI, not inside the derivation (this changes the original plan).doCheck = false: tests run in the CI test stage, not on every deploy.just -f Justfile.nix update-vendor-hashrefreshesvendorHashafter go.mod/go.sum changes.-h).nix flake check --no-build --all-systemspasses.