Package sovrnd and backup-route-sync with Nix

closed
#d6ee5d9 opened by agent Sep 29

Build every sovrn-owned binary with Nix so hosts get store paths, not controller-built copies patched with patchelf.

Sketch: - nix/pkgs/sovrnd.nix via buildGoModule (vendorHash). Generated/embedded assets (templ, tailwind, htmx) must be inputs, so a stale-asset build is impossible; this replaces just gen-check as a deploy gate. - nix/pkgs/backup-route-sync.nix (cmd/backup-route-sync). - ZDS already exists (nix/pkgs/zds.nix). - Expose them as flake outputs and as an overlay the NixOS modules consume. - Binary cache for our own packages: attic, cachix, or just build on the deployer. Decide; these builds are small next to Stalwart. - Retire after cutover: just build-stalwart, nix/pkgs/stalwart.nix + stalwart-Cargo.lock (nixpkgs stalwart_0_16 replaces them), the glibc-ceiling checks, and the patchelf tasks.

Done when nix build .#sovrnd .#backup-route-sync .#zds succeeds on x86_64 and aarch64.

1 Comment

agent d662e8e Sep 30

Done (pending review)

  • nix/pkgs/go-commands.nix: a single buildGoModule builds cmd/sovrnd, cmd/backup-route-sync and cmd/metrics-healthz, with cgo on for mattn/go-sqlite3.
    • The overlay attributes sovrnd, backup-route-sync and metrics-healthz are the same store path, each with its own meta.mainProgram.
    • It’s a plain // update on purpose. lib.addMetaAttrs and overrideAttrs push mainProgram into NIX_MAIN_PROGRAM and would build the module three times.
  • Source filter: go.mod, go.sum, *.go, api/, cmd/, internal/. Edits to site/, nix/, docs or deployment don’t rebuild.
  • No binary cache (user decision). It builds on the deployer: about 1.5 min cold including the module fetch.
  • Generated assets: the templ/tailwind/esbuild/Astro outputs are committed and embedded, so the build needs only Go. Staleness is caught by just gen-check in CI, not inside the derivation (this changes the original plan).
  • doCheck = false: tests run in the CI test stage, not on every deploy.
  • just -f Justfile.nix update-vendor-hash refreshes vendorHash after go.mod/go.sum changes.
  • Verified:
    • All three binaries run (-h).
    • aarch64 evaluates.
    • nix flake check --no-build --all-systems passes.
    • The closure is the binaries plus glibc and libgcc.