diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index fc8c224..73c0b60 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -14,6 +14,48 @@ jobs: - uses: actions/checkout@v4 - uses: DeterminateSystems/flake-checker-action@v9 + build-container: + runs-on: ubuntu-latest + permissions: + packages: write + env: + image_name: ocf-docs + registry: ghcr.io/${{ github.repository_owner }} + steps: + - uses: actions/checkout@v7 + + - uses: cachix/install-nix-action@v31 + + - name: Build and tag image + run: | + IMAGE_TAG=$(sh $(nix build .#image --no-link --print-out-paths) 2>/dev/null | podman load -q | grep -oe "$image_name:.*$" | sed -e "s/$image_name://") + echo "image_tags=$IMAGE_TAG" >> $GITHUB_ENV + + - name: Tag latest + if: github.ref == 'refs/heads/main' + run: | + podman tag $image_name:$image_tags $image_name:latest + echo "image_tags=$image_tags latest" >> $GITHUB_ENV + + - name: Log in to GHCR + uses: redhat-actions/podman-login@v1 + with: + username: ${{ github.actor }} + password: ${{ github.token }} + registry: ${{ env.registry }} + + - name: Push to GHCR + id: push-ghcr + uses: redhat-actions/push-to-registry@v2 + with: + image: ${{ env.image_name }} + tags: ${{ env.image_tags }} + registry: ${{ env.registry }} + + - name: Print image url + run: echo "Image pushed to ${{ steps.push-ghcr.outputs.registry-paths }}" + + build_and_deploy: runs-on: ci-ocf-mkdocs if: github.ref == 'refs/heads/main' diff --git a/default.nix b/default.nix index f27314e..f7fc683 100644 --- a/default.nix +++ b/default.nix @@ -13,10 +13,14 @@ stdenvNoCC.mkDerivation { ]; buildPhase = '' + runHook preBuild mkdocs build + runHook postBuild ''; installPhase = '' + runHook preInstall mv site $out + runHook postInstall ''; } diff --git a/flake.lock b/flake.lock index 2c0748e..7db0993 100644 --- a/flake.lock +++ b/flake.lock @@ -2,16 +2,16 @@ "nodes": { "nixpkgs": { "locked": { - "lastModified": 1752480373, - "narHash": "sha256-JHQbm+OcGp32wAsXTE/FLYGNpb+4GLi5oTvCxwSoBOA=", + "lastModified": 1790750587, + "narHash": "sha256-VfjaoJ1Uyb7JZTrBgE5Jf2nhjtQPmD9KOd19HJwmZwM=", "owner": "nixos", "repo": "nixpkgs", - "rev": "62e0f05ede1da0d54515d4ea8ce9c733f12d9f08", + "rev": "78e9c786dc08cd4f3420c2395cd977206a9b1da2", "type": "github" }, "original": { "owner": "nixos", - "ref": "nixos-unstable", + "ref": "nixos-26.05", "repo": "nixpkgs", "type": "github" } diff --git a/flake.nix b/flake.nix index 94fb1c5..b6d8bb3 100644 --- a/flake.nix +++ b/flake.nix @@ -1,17 +1,80 @@ { description = "Mkdocs configuration for the Open Computing Facility"; inputs = { - nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable"; + nixpkgs.url = "github:nixos/nixpkgs/nixos-26.05"; systems.url = "github:nix-systems/default"; }; - outputs = { self, nixpkgs, systems }: + outputs = + { + self, + nixpkgs, + systems, + }: let - pkgsFor = system: nixpkgs.legacyPackages.${system}; + pkgsFor = system: import nixpkgs { inherit system; }; forAllSystems = fn: nixpkgs.lib.genAttrs (import systems) (system: fn (pkgsFor system)); in { - packages = forAllSystems (pkgs: { + packages = forAllSystems (pkgs: rec { default = pkgs.callPackage ./. { }; + image = pkgs.dockerTools.streamLayeredImage ( + let + timestamp = builtins.readFile ( + pkgs.runCommand "timestamp" { } '' + date --date='@${toString self.lastModified}' --iso-8601=minutes > $out + '' + ); + + docsPath = default; + + nginxPort = "80"; + nginxConf = pkgs.writeText "nginx.conf" '' + user nobody nobody; + daemon off; + error_log /dev/stdout info; + pid /dev/null; + events {} + http { + include ${pkgs.nginx}/conf/mime.types; + default_type application/octet-stream; + access_log /dev/stdout; + server { + listen ${nginxPort}; + root ${docsPath}; + } + } + ''; + in + { + name = "ocf-docs"; + created = timestamp; + mtime = timestamp; + + contents = with pkgs; [ + busybox + nginx + dockerTools.fakeNss + ]; + + extraCommands = '' + # nginx requires these dirs to exist, see: + # https://github.com/NixOS/nixpkgs/blob/master/pkgs/build-support/docker/examples.nix + mkdir -p tmp/nginx_client_body + mkdir -p var/log/nginx + ''; + + config = { + Cmd = [ + "nginx" + "-c" + nginxConf + ]; + ExposedPorts = { + "${nginxPort}/tcp" = { }; + }; + }; + } + ); }); devShells = forAllSystems (pkgs: { default = pkgs.mkShell { @@ -19,12 +82,12 @@ shellHook = "mkdocs serve -f mkdocs-dev.yml"; }; deploy = pkgs.mkShell { - packages = with pkgs; [ - rsync - openssh - ]; + packages = with pkgs; [ + rsync + openssh + ]; }; }); - formatter = forAllSystems (pkgs: pkgs.nixpkgs-fmt); + formatter = forAllSystems (pkgs: pkgs.nixfmt-tree); }; }