2021-01-08 01:58:22 +00:00
|
|
|
{ buildGoModule
|
|
|
|
, fetchFromGitHub
|
|
|
|
, lib
|
|
|
|
, envoy
|
|
|
|
, zip
|
2021-01-08 03:04:24 +00:00
|
|
|
, nixosTests
|
2021-01-08 01:58:22 +00:00
|
|
|
}:
|
|
|
|
|
|
|
|
let
|
|
|
|
inherit (lib) concatStringsSep mapAttrsToList;
|
|
|
|
in
|
|
|
|
buildGoModule rec {
|
|
|
|
pname = "pomerium";
|
2021-09-18 02:57:32 +00:00
|
|
|
version = "0.15.7";
|
2021-01-08 01:58:22 +00:00
|
|
|
src = fetchFromGitHub {
|
|
|
|
owner = "pomerium";
|
|
|
|
repo = "pomerium";
|
|
|
|
rev = "v${version}";
|
2021-09-18 02:57:32 +00:00
|
|
|
hash = "sha256:0adlk4ylny1z43x1dw3ny0s1932vhb61hpf5wdz4r65y8k9qyfgr";
|
2021-01-08 01:58:22 +00:00
|
|
|
};
|
|
|
|
|
2021-09-18 02:57:32 +00:00
|
|
|
vendorSha256 = "sha256:1fszfbra84pcs8v1h2kf7iy603vf9v2ysg6il76aqmqrxmb1p7nv";
|
2021-01-08 01:58:22 +00:00
|
|
|
subPackages = [
|
|
|
|
"cmd/pomerium"
|
|
|
|
"cmd/pomerium-cli"
|
|
|
|
];
|
|
|
|
|
2021-08-26 06:45:51 +00:00
|
|
|
ldflags = let
|
2021-01-08 01:58:22 +00:00
|
|
|
# Set a variety of useful meta variables for stamping the build with.
|
|
|
|
setVars = {
|
|
|
|
Version = "v${version}";
|
|
|
|
BuildMeta = "nixpkgs";
|
|
|
|
ProjectName = "pomerium";
|
|
|
|
ProjectURL = "github.com/pomerium/pomerium";
|
|
|
|
};
|
|
|
|
varFlags = concatStringsSep " " (mapAttrsToList (name: value: "-X github.com/pomerium/pomerium/internal/version.${name}=${value}") setVars);
|
|
|
|
in [
|
2021-08-26 06:45:51 +00:00
|
|
|
"${varFlags}"
|
2021-01-08 01:58:22 +00:00
|
|
|
];
|
|
|
|
|
2021-09-18 02:57:32 +00:00
|
|
|
preBuild = ''
|
|
|
|
rm internal/envoy/files/files_{darwin,linux}*.go
|
|
|
|
cat <<EOF >internal/envoy/files/files_generic.go
|
|
|
|
package files
|
|
|
|
|
|
|
|
import _ "embed" // embed
|
|
|
|
|
|
|
|
//go:embed envoy
|
|
|
|
var rawBinary []byte
|
2021-01-08 01:58:22 +00:00
|
|
|
|
2021-09-18 02:57:32 +00:00
|
|
|
//go:embed envoy.sha256
|
|
|
|
var rawChecksum string
|
2021-01-08 01:58:22 +00:00
|
|
|
|
2021-09-18 02:57:32 +00:00
|
|
|
//go:embed envoy.version
|
|
|
|
var rawVersion string
|
|
|
|
EOF
|
|
|
|
cp ${envoy}/bin/envoy internal/envoy/files/envoy
|
|
|
|
sha256sum ${envoy}/bin/envoy > internal/envoy/files/envoy.sha256
|
|
|
|
echo ${envoy.version} > internal/envoy/files/envoy.version
|
2021-01-08 01:58:22 +00:00
|
|
|
'';
|
|
|
|
|
|
|
|
# We also need to set dontStrip to avoid having the envoy ZIP stripped off the end.
|
|
|
|
dontStrip = true;
|
|
|
|
|
|
|
|
installPhase = ''
|
|
|
|
install -Dm0755 $GOPATH/bin/pomerium $out/bin/pomerium
|
|
|
|
install -Dm0755 $GOPATH/bin/pomerium-cli $out/bin/pomerium-cli
|
|
|
|
'';
|
|
|
|
|
2021-01-08 03:04:24 +00:00
|
|
|
passthru.tests = {
|
|
|
|
inherit (nixosTests) pomerium;
|
|
|
|
};
|
|
|
|
|
2021-01-08 01:58:22 +00:00
|
|
|
meta = with lib; {
|
|
|
|
homepage = "https://pomerium.io";
|
|
|
|
description = "Authenticating reverse proxy";
|
|
|
|
license = licenses.asl20;
|
|
|
|
maintainers = with maintainers; [ lukegb ];
|
|
|
|
platforms = [ "x86_64-linux" ]; # Envoy derivation is x86_64-linux only.
|
|
|
|
};
|
|
|
|
}
|