- flake input atrocore-docker rev-pinned (e1e9bed) - pkgs/atropim-image: atropim-build/atropim-push scripts + 2-stage podman build (vendor pdf target + entrypoint wrapper) - entrypoint writes ATRO_DB_* to data/config.php at runtime, guarded by isInstalled (idempotent); no DB credentials in layers - devShell documents build/push commands and ENV variables
204 lines
6.4 KiB
Nix
204 lines
6.4 KiB
Nix
{
|
|
description = ''
|
|
For questions just DM me on X: https://twitter.com/@m3tam3re
|
|
There is also some NIXOS content on my YT channel: https://www.youtube.com/@m3tam3re
|
|
|
|
One of the best ways to learn NIXOS is to read other peoples configurations. I have personally learned a lot from Gabriel Fontes configs:
|
|
https://github.com/Misterio77/nix-starter-configs
|
|
https://github.com/Misterio77/nix-config
|
|
|
|
Please also check out the starter configs mentioned above.
|
|
'';
|
|
|
|
inputs = {
|
|
home-manager = {
|
|
url = "github:nix-community/home-manager/release-26.05";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
nixpkgs.url = "github:nixos/nixpkgs/nixos-26.05";
|
|
nixpkgs-unstable.url = "github:nixos/nixpkgs/nixos-unstable";
|
|
|
|
m3ta-nixpkgs.url = "git+https://code.m3ta.dev/m3tam3re/nixpkgs";
|
|
|
|
m3ta-home = {
|
|
url = "git+ssh://gitea@code.m3ta.dev/m3tam3re/m3ta-home";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
llm-agents.url = "github:numtide/llm-agents.nix";
|
|
|
|
nur = {
|
|
url = "github:nix-community/NUR";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
disko = {
|
|
url = "github:nix-community/disko";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
agenix.url = "github:ryantm/agenix";
|
|
|
|
nixos-anywhere = {
|
|
url = "github:nix-community/nixos-anywhere";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
nix-colors.url = "github:misterio77/nix-colors";
|
|
|
|
agents = {
|
|
url = "git+https://code.m3ta.dev/m3tam3re/AGENTS";
|
|
flake = false;
|
|
};
|
|
|
|
zugferd-service = {
|
|
url = "git+https://git.az-gruppe.com/AZ-Intec-GmbH/zugferd-service";
|
|
# url = "path:/home/sascha.koenig/p/CODE/python/zugferd-service";
|
|
};
|
|
|
|
azion-scheduler = {
|
|
url = "git+https://git.az-gruppe.com/AZ-Intec-GmbH/AZion";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
azess = {
|
|
url = "git+https://git.az-gruppe.com/AZ-Intec-GmbH/AZess";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
phishboard = {
|
|
url = "git+https://git.az-gruppe.com/AZ-Intec-GmbH/phishboard.git";
|
|
inputs.nixpkgs.follows = "nixpkgs";
|
|
};
|
|
|
|
atrocore-docker = {
|
|
# Rev-pinned vendor Dockerfiles for the AtroPIM image pipeline (AZ-NIX-ava.1)
|
|
url = "github:atrocore/docker/e1e9bed1f6ae983d1aac474657cbeba1c004e313";
|
|
flake = false;
|
|
};
|
|
};
|
|
|
|
outputs = {
|
|
self,
|
|
agenix,
|
|
agents,
|
|
nixpkgs,
|
|
m3ta-nixpkgs,
|
|
...
|
|
} @ inputs: let
|
|
inherit (self) outputs;
|
|
systems = [
|
|
"aarch64-linux"
|
|
"i686-linux"
|
|
"x86_64-linux"
|
|
"aarch64-darwin"
|
|
"x86_64-darwin"
|
|
];
|
|
forAllSystems = nixpkgs.lib.genAttrs systems;
|
|
in {
|
|
packages = forAllSystems (system:
|
|
import ./pkgs {
|
|
pkgs = nixpkgs.legacyPackages.${system};
|
|
atrocore-docker = inputs.atrocore-docker;
|
|
});
|
|
overlays = let
|
|
all = import ./overlays {inherit inputs;};
|
|
in
|
|
removeAttrs all ["mkLlmAgentsOverlay"];
|
|
lib.mkLlmAgentsOverlay = (import ./overlays {inherit inputs;}).mkLlmAgentsOverlay;
|
|
|
|
devShells = forAllSystems (system: let
|
|
pkgs = import nixpkgs {
|
|
inherit system;
|
|
config.allowUnfree = true; # Allow unfree packages in devShell
|
|
};
|
|
m3taLib = m3ta-nixpkgs.lib.${system};
|
|
rules = m3taLib.coding-rules.mkCodingRules {
|
|
inherit agents;
|
|
languages = ["nix"];
|
|
};
|
|
in {
|
|
default = pkgs.mkShell {
|
|
buildInputs = with pkgs; [
|
|
alejandra
|
|
nixd
|
|
opencode
|
|
# pi-coding-agent
|
|
inputs.agenix.packages.${system}.default
|
|
outputs.packages.${system}.atropim-tools
|
|
];
|
|
|
|
shellHook = ''
|
|
${rules.shellHook}
|
|
echo "🚀 NixOS Infrastructure Development Shell with Opencode Rules"
|
|
echo ""
|
|
echo "Active rules:"
|
|
echo " - Nix language conventions"
|
|
echo " - Coding-style best practices"
|
|
echo " - Naming conventions"
|
|
echo " - Documentation standards"
|
|
echo " - Testing guidelines"
|
|
echo " - Git workflow patterns"
|
|
echo " - Project structure guidelines"
|
|
echo ""
|
|
echo "Generated files:"
|
|
echo " - .opencode-rules/ (symlink to AGENTS repo rules)"
|
|
echo " - coding-rules.json (configuration file)"
|
|
echo ""
|
|
echo "Useful commands:"
|
|
echo " - cat coding-rules.json View rules configuration"
|
|
echo " - ls .opencode-rules/ Browse available rules"
|
|
echo " - nix develop Re-enter this shell"
|
|
echo ""
|
|
echo "🐘 AtroPIM Image Pipeline (AZ-NIX-ava)"
|
|
echo " Commands:"
|
|
echo " atropim-build Build secret-free AtroPIM image (podman, 2 stages)"
|
|
echo " atropim-push [version] Tag + push to Gitea registry (default tag: YYYYMMDD)"
|
|
echo " Build parameters (pkgs/atropim-image/default.nix):"
|
|
echo " SKELETON_VARIANT=pim-no-demo BUILD_VARIANT=pdf PRODUCTION_STABILITY=stable"
|
|
echo " PRODUCTION_DOMAIN=pim.l.az-gruppe.com DB build args deliberately EMPTY"
|
|
echo " Runtime ENV (written to data/config.php at container start):"
|
|
echo " ATRO_DB_HOST ATRO_DB_NAME ATRO_DB_USER ATRO_DB_PASSWORD"
|
|
echo " Registry: git.az-gruppe.com/az-intec-gmbh/atrocore-web (podman login git.az-gruppe.com)"
|
|
echo " Quick test:"
|
|
echo " podman run -d --name atropim -p 127.0.0.1:8080:80 <image>"
|
|
echo ""
|
|
echo "Remember to add to .gitignore:"
|
|
echo " .opencode-rules"
|
|
echo " coding-rules.json"
|
|
echo "======================================"
|
|
'';
|
|
};
|
|
});
|
|
|
|
nixosConfigurations = {
|
|
AZ-CLD-1 = nixpkgs.lib.nixosSystem {
|
|
specialArgs = {
|
|
inherit inputs outputs;
|
|
system = "x86_64-linux";
|
|
};
|
|
modules = [
|
|
./hosts/AZ-CLD-1
|
|
agenix.nixosModules.default
|
|
inputs.disko.nixosModules.disko
|
|
];
|
|
};
|
|
AZ-PRM-1 = nixpkgs.lib.nixosSystem {
|
|
specialArgs = {
|
|
inherit inputs outputs;
|
|
system = "x86_64-linux";
|
|
};
|
|
modules = [
|
|
./hosts/AZ-PRM-1
|
|
agenix.nixosModules.default
|
|
inputs.disko.nixosModules.disko
|
|
inputs.azion-scheduler.nixosModules.default
|
|
inputs.zugferd-service.nixosModules.default
|
|
inputs.azess.nixosModules.default
|
|
inputs.phishboard.nixosModules.default
|
|
];
|
|
};
|
|
};
|
|
};
|
|
}
|