Localize external-secrets for ringtail (amd64) via nix build
container.py builds arm64 (indri/Dagger); add default.nix to build the amd64 image on ringtail's nix-container-builder (Go 1.26, -tags all_providers). external-secrets-ringtail now uses a thin overlay over the shared manifest, overriding only the image to the -nix tag. Repoints the app at the overlay. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
30c82079b9
commit
59dace8b1a
4 changed files with 74 additions and 1 deletions
56
containers/external-secrets/default.nix
Normal file
56
containers/external-secrets/default.nix
Normal file
|
|
@ -0,0 +1,56 @@
|
|||
# Nix-built External Secrets Operator (amd64, for ringtail k3s).
|
||||
# Builds v2.2.0 from the forge mirror with all secret providers compiled in,
|
||||
# faithful to upstream's `make build` (-tags all_providers). The container.py
|
||||
# sibling builds the arm64 image for indri's minikube; this default.nix builds
|
||||
# the amd64 image on ringtail's nix-container-builder.
|
||||
{ pkgs ? import <nixpkgs> { } }:
|
||||
|
||||
let
|
||||
version = "2.2.0";
|
||||
|
||||
src = pkgs.fetchgit {
|
||||
url = "https://forge.ops.eblu.me/mirrors/external-secrets.git";
|
||||
rev = "v${version}";
|
||||
hash = "sha256-eAocOAp5s4CFRrpKfQr2lf3Ji+6nQQ1A5/eTw5B7v9U=";
|
||||
};
|
||||
|
||||
# external-secrets v2.2.0 requires Go >= 1.26.1; nixpkgs default go is 1.25.x.
|
||||
external-secrets = (pkgs.buildGoModule.override { go = pkgs.go_1_26; }) {
|
||||
inherit src version;
|
||||
pname = "external-secrets";
|
||||
vendorHash = "sha256-0xuBK3fjAplPLAElHvKB6d+2lDz+De/s91fV4dPZwjE=";
|
||||
|
||||
doCheck = false;
|
||||
|
||||
subPackages = [ "." ];
|
||||
|
||||
tags = [ "all_providers" ];
|
||||
|
||||
ldflags = [ "-s" "-w" ];
|
||||
|
||||
meta = with pkgs.lib; {
|
||||
description = "Kubernetes operator that integrates external secret management systems";
|
||||
homepage = "https://github.com/external-secrets/external-secrets";
|
||||
license = licenses.asl20;
|
||||
mainProgram = "external-secrets";
|
||||
};
|
||||
};
|
||||
in
|
||||
|
||||
pkgs.dockerTools.buildLayeredImage {
|
||||
name = "blumeops/external-secrets";
|
||||
contents = [
|
||||
external-secrets
|
||||
pkgs.cacert
|
||||
pkgs.tzdata
|
||||
];
|
||||
|
||||
config = {
|
||||
Entrypoint = [ "${external-secrets}/bin/external-secrets" ];
|
||||
Env = [
|
||||
"SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt"
|
||||
"TZDIR=${pkgs.tzdata}/share/zoneinfo"
|
||||
];
|
||||
User = "65534";
|
||||
};
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue