Files
AZ-NIX-SERVERS/flake.nix
T
sascha.koenig 705702abee feat: AtroPIM image pipeline with secret-free build (AZ-NIX-ava.1)
- flake input atrocore-docker rev-pinned (e1e9bed)
- pkgs/atropim-image: atropim-build/atropim-push scripts + 2-stage
  podman build (vendor pdf target + entrypoint wrapper)
- entrypoint writes ATRO_DB_* to data/config.php at runtime,
  guarded by isInstalled (idempotent); no DB credentials in layers
- devShell documents build/push commands and ENV variables
2026-08-17 13:00:06 +02:00

204 lines
6.4 KiB
Nix

{
description = ''
For questions just DM me on X: https://twitter.com/@m3tam3re
There is also some NIXOS content on my YT channel: https://www.youtube.com/@m3tam3re
One of the best ways to learn NIXOS is to read other peoples configurations. I have personally learned a lot from Gabriel Fontes configs:
https://github.com/Misterio77/nix-starter-configs
https://github.com/Misterio77/nix-config
Please also check out the starter configs mentioned above.
'';
inputs = {
home-manager = {
url = "github:nix-community/home-manager/release-26.05";
inputs.nixpkgs.follows = "nixpkgs";
};
nixpkgs.url = "github:nixos/nixpkgs/nixos-26.05";
nixpkgs-unstable.url = "github:nixos/nixpkgs/nixos-unstable";
m3ta-nixpkgs.url = "git+https://code.m3ta.dev/m3tam3re/nixpkgs";
m3ta-home = {
url = "git+ssh://gitea@code.m3ta.dev/m3tam3re/m3ta-home";
inputs.nixpkgs.follows = "nixpkgs";
};
llm-agents.url = "github:numtide/llm-agents.nix";
nur = {
url = "github:nix-community/NUR";
inputs.nixpkgs.follows = "nixpkgs";
};
disko = {
url = "github:nix-community/disko";
inputs.nixpkgs.follows = "nixpkgs";
};
agenix.url = "github:ryantm/agenix";
nixos-anywhere = {
url = "github:nix-community/nixos-anywhere";
inputs.nixpkgs.follows = "nixpkgs";
};
nix-colors.url = "github:misterio77/nix-colors";
agents = {
url = "git+https://code.m3ta.dev/m3tam3re/AGENTS";
flake = false;
};
zugferd-service = {
url = "git+https://git.az-gruppe.com/AZ-Intec-GmbH/zugferd-service";
# url = "path:/home/sascha.koenig/p/CODE/python/zugferd-service";
};
azion-scheduler = {
url = "git+https://git.az-gruppe.com/AZ-Intec-GmbH/AZion";
inputs.nixpkgs.follows = "nixpkgs";
};
azess = {
url = "git+https://git.az-gruppe.com/AZ-Intec-GmbH/AZess";
inputs.nixpkgs.follows = "nixpkgs";
};
phishboard = {
url = "git+https://git.az-gruppe.com/AZ-Intec-GmbH/phishboard.git";
inputs.nixpkgs.follows = "nixpkgs";
};
atrocore-docker = {
# Rev-pinned vendor Dockerfiles for the AtroPIM image pipeline (AZ-NIX-ava.1)
url = "github:atrocore/docker/e1e9bed1f6ae983d1aac474657cbeba1c004e313";
flake = false;
};
};
outputs = {
self,
agenix,
agents,
nixpkgs,
m3ta-nixpkgs,
...
} @ inputs: let
inherit (self) outputs;
systems = [
"aarch64-linux"
"i686-linux"
"x86_64-linux"
"aarch64-darwin"
"x86_64-darwin"
];
forAllSystems = nixpkgs.lib.genAttrs systems;
in {
packages = forAllSystems (system:
import ./pkgs {
pkgs = nixpkgs.legacyPackages.${system};
atrocore-docker = inputs.atrocore-docker;
});
overlays = let
all = import ./overlays {inherit inputs;};
in
removeAttrs all ["mkLlmAgentsOverlay"];
lib.mkLlmAgentsOverlay = (import ./overlays {inherit inputs;}).mkLlmAgentsOverlay;
devShells = forAllSystems (system: let
pkgs = import nixpkgs {
inherit system;
config.allowUnfree = true; # Allow unfree packages in devShell
};
m3taLib = m3ta-nixpkgs.lib.${system};
rules = m3taLib.coding-rules.mkCodingRules {
inherit agents;
languages = ["nix"];
};
in {
default = pkgs.mkShell {
buildInputs = with pkgs; [
alejandra
nixd
opencode
# pi-coding-agent
inputs.agenix.packages.${system}.default
outputs.packages.${system}.atropim-tools
];
shellHook = ''
${rules.shellHook}
echo "🚀 NixOS Infrastructure Development Shell with Opencode Rules"
echo ""
echo "Active rules:"
echo " - Nix language conventions"
echo " - Coding-style best practices"
echo " - Naming conventions"
echo " - Documentation standards"
echo " - Testing guidelines"
echo " - Git workflow patterns"
echo " - Project structure guidelines"
echo ""
echo "Generated files:"
echo " - .opencode-rules/ (symlink to AGENTS repo rules)"
echo " - coding-rules.json (configuration file)"
echo ""
echo "Useful commands:"
echo " - cat coding-rules.json View rules configuration"
echo " - ls .opencode-rules/ Browse available rules"
echo " - nix develop Re-enter this shell"
echo ""
echo "🐘 AtroPIM Image Pipeline (AZ-NIX-ava)"
echo " Commands:"
echo " atropim-build Build secret-free AtroPIM image (podman, 2 stages)"
echo " atropim-push [version] Tag + push to Gitea registry (default tag: YYYYMMDD)"
echo " Build parameters (pkgs/atropim-image/default.nix):"
echo " SKELETON_VARIANT=pim-no-demo BUILD_VARIANT=pdf PRODUCTION_STABILITY=stable"
echo " PRODUCTION_DOMAIN=pim.l.az-gruppe.com DB build args deliberately EMPTY"
echo " Runtime ENV (written to data/config.php at container start):"
echo " ATRO_DB_HOST ATRO_DB_NAME ATRO_DB_USER ATRO_DB_PASSWORD"
echo " Registry: git.az-gruppe.com/az-intec-gmbh/atrocore-web (podman login git.az-gruppe.com)"
echo " Quick test:"
echo " podman run -d --name atropim -p 127.0.0.1:8080:80 <image>"
echo ""
echo "Remember to add to .gitignore:"
echo " .opencode-rules"
echo " coding-rules.json"
echo "======================================"
'';
};
});
nixosConfigurations = {
AZ-CLD-1 = nixpkgs.lib.nixosSystem {
specialArgs = {
inherit inputs outputs;
system = "x86_64-linux";
};
modules = [
./hosts/AZ-CLD-1
agenix.nixosModules.default
inputs.disko.nixosModules.disko
];
};
AZ-PRM-1 = nixpkgs.lib.nixosSystem {
specialArgs = {
inherit inputs outputs;
system = "x86_64-linux";
};
modules = [
./hosts/AZ-PRM-1
agenix.nixosModules.default
inputs.disko.nixosModules.disko
inputs.azion-scheduler.nixosModules.default
inputs.zugferd-service.nixosModules.default
inputs.azess.nixosModules.default
inputs.phishboard.nixosModules.default
];
};
};
};
}