From 113fabec2978f1431c51606c57c013582e45883f Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 15:22:20 +0200 Subject: [PATCH 01/16] doc(chart): update release notes --- CHANGELOG.md | 10 ++++++++++ helm-chart/Chart.yaml | 2 +- helm-chart/templates/NOTES.txt | 4 ++-- 3 files changed, 13 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 27ff379b..49a63571 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -20,6 +20,16 @@ written while it was being built. See [RELEASING.md](RELEASING.md). ### Changed +- A deployment can now be reached under any hostnames, not only + `app.` and `auth.`. The app's hostname is the first entry of + `frontend.ingress.hosts`, Keycloak's is `keycloak.hostname.hostname`, and the + chart derives the ingresses, the TLS certificates, the OIDC issuer urls and + the realm's login redirect urls from those two. Previously the subdomains were + fixed in the chart's templates, so changing either value pointed the traffic + at one name while the login flow still expected the other. Both values are now + required: the chart refuses to render rather than guessing a hostname nothing + is served under. + - A hackathon overview with no phase running no longer opens with "No phase is running" and a footnote saying the timeline follows the dates alone. The card now starts with what people can actually do; if a phase is coming up, the diff --git a/helm-chart/Chart.yaml b/helm-chart/Chart.yaml index 798cc101..a262dfc5 100644 --- a/helm-chart/Chart.yaml +++ b/helm-chart/Chart.yaml @@ -6,7 +6,7 @@ type: application # The chart's own version. Bumped by hand when the chart changes, and # independent of the app: the CI publishes whatever it finds here. -version: 0.3.0 +version: 0.4.0 # The app release this chart deploys. A new app release does # not become deployable until someone points the chart at it. appVersion: "0.9.1" diff --git a/helm-chart/templates/NOTES.txt b/helm-chart/templates/NOTES.txt index fef99450..85206c5e 100644 --- a/helm-chart/templates/NOTES.txt +++ b/helm-chart/templates/NOTES.txt @@ -1,7 +1,7 @@ Hackagon has been deployed! -Frontend: https://app.{{ .Values.baseDomain }} -Keycloak: https://auth.{{ .Values.baseDomain }} +Frontend: https://{{ include "hackagon.frontendHost" . }} +Keycloak: https://{{ include "hackagon.keycloakHost" . }} To get the generated frontend OIDC secrets, run: From dbc39ef71c9e1338a171679f3d12c45b5fceed44 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 15:23:43 +0200 Subject: [PATCH 02/16] fix(just): specify keycloak hostname in publish --- tools/just/helm.just | 4 +++- tools/keycloak-handover/README.md | 1 + 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/tools/just/helm.just b/tools/just/helm.just index c2704397..2a604f33 100644 --- a/tools/just/helm.just +++ b/tools/just/helm.just @@ -193,5 +193,7 @@ publish: echo "" echo " Install with:" echo " helm install hackagon {{ oci_repo }}/hackagon --version $chart_v \\" - echo " --set baseDomain=example.com --set-file realmJson=@path/to/realm.json" + echo " --set baseDomain=example.com \\" + echo " --set keycloak.hostname.hostname=https://auth.example.com \\" + echo " --set-file realmJson=@path/to/realm.json" echo "" diff --git a/tools/keycloak-handover/README.md b/tools/keycloak-handover/README.md index 59f2fb09..6ac6338d 100644 --- a/tools/keycloak-handover/README.md +++ b/tools/keycloak-handover/README.md @@ -49,6 +49,7 @@ decryptable by you, which is how you know the recipient key took effect. helm upgrade --install hackagon ../../helm-chart \ --set-file realmJson=./realm.json \ --set baseDomain= \ + --set keycloak.hostname.hostname=https://auth. \ --set backend.config.server.adminkeycloakid=1183370a-46a2-4dad-b8fd-dd927d083e14 \ --set frontendSecrets.clientSecret= ``` From 1b22f9c7f31198ad783c15c45d2836bd42934ba2 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 16:22:06 +0200 Subject: [PATCH 03/16] fix(chart): define frontend+keycloak hostnames based on values (no hardcoded subdomains) --- CHANGELOG.md | 3 ++- helm-chart/templates/_helpers.tpl | 29 ++++++++++++++++++++--------- 2 files changed, 22 insertions(+), 10 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 49a63571..3e4105e5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -28,7 +28,8 @@ written while it was being built. See [RELEASING.md](RELEASING.md). fixed in the chart's templates, so changing either value pointed the traffic at one name while the login flow still expected the other. Both values are now required: the chart refuses to render rather than guessing a hostname nothing - is served under. + is served under, and the two OIDC issuer settings are gone from `values.yaml` + because they only ever had one working value. - A hackathon overview with no phase running no longer opens with "No phase is running" and a footnote saying the timeline follows the dates alone. The card diff --git a/helm-chart/templates/_helpers.tpl b/helm-chart/templates/_helpers.tpl index 9ae963e1..dd41c4db 100644 --- a/helm-chart/templates/_helpers.tpl +++ b/helm-chart/templates/_helpers.tpl @@ -62,24 +62,35 @@ Create the name of the service account to use {{- end }} {{/* -Base domain with substitution +First ingress host is the canonical frontend hostname. +(in case we have multiple urls) */}} -{{- define "hackagon.baseDomain" -}} -{{- .Values.baseDomain | replace "{baseDomain}" .Values.baseDomain }} +{{- define "hackagon.frontendHost" -}} +{{- $first := first (.Values.frontend.ingress.hosts | default list) | required "frontend.ingress.hosts must name at least one host: it is the app's public name" }} +{{- $first.host | replace "{baseDomain}" .Values.baseDomain | replace "{releaseName}" .Release.Name }} {{- end }} {{/* -Frontend host with substitution +Public url Keycloak runs under. Required `enabled` or not: browsers are sent +here, and it is the `iss` claim in every token. */}} -{{- define "hackagon.frontendHost" -}} -{{- printf "app.%s" (include "hackagon.baseDomain" .) | replace "{baseDomain}" .Values.baseDomain }} +{{- define "hackagon.keycloakUrl" -}} +{{- .Values.keycloak.hostname.hostname | required "keycloak.hostname.hostname is required (e.g. \"https://auth.example.com\")" | trimSuffix "/" }} {{- end }} {{/* -Keycloak host with substitution +The `iss` claim; the backend rejects a token that does not match it. The realm +is `hackagon` chart-wide, so this is derived rather than configurable. +*/}} +{{- define "hackagon.oidcIssuer" -}} +{{- printf "%s/realms/hackagon" (include "hackagon.keycloakUrl" .) }} +{{- end }} + +{{/* +The Keycloak url as a bare hostname, for an ingress `host:` field. */}} {{- define "hackagon.keycloakHost" -}} -{{- printf "auth.%s" (include "hackagon.baseDomain" .) | replace "{baseDomain}" .Values.baseDomain }} +{{- include "hackagon.keycloakUrl" . | trimPrefix "https://" | trimPrefix "http://" }} {{- end }} {{/* @@ -127,4 +138,4 @@ Get password: use provided value or generate one {{- else }} {{- include "hackagon.randAlphaNum" .length | b64enc }} {{- end }} -{{- end }} \ No newline at end of file +{{- end }} From 95ba9f03d9eed31e706c1874ea46a269a023f357 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 16:45:46 +0200 Subject: [PATCH 04/16] refactor(chart): simplify placeholder rendering with builtin `tpl` --- helm-chart/templates/_helpers.tpl | 4 +++- helm-chart/templates/backend-configmap.yaml | 10 ++++----- helm-chart/templates/frontend-configmap.yaml | 2 +- helm-chart/templates/frontend-ingress.yaml | 10 ++------- helm-chart/values.yaml | 22 ++++++++++---------- tools/helm/lint-values.yaml | 10 ++++++++- 6 files changed, 31 insertions(+), 27 deletions(-) diff --git a/helm-chart/templates/_helpers.tpl b/helm-chart/templates/_helpers.tpl index dd41c4db..75822932 100644 --- a/helm-chart/templates/_helpers.tpl +++ b/helm-chart/templates/_helpers.tpl @@ -64,10 +64,12 @@ Create the name of the service account to use {{/* First ingress host is the canonical frontend hostname. (in case we have multiple urls) +Rendered with `tpl`, like every other host value; keep this one free of +`hackagon.frontendHost` or it recurses. */}} {{- define "hackagon.frontendHost" -}} {{- $first := first (.Values.frontend.ingress.hosts | default list) | required "frontend.ingress.hosts must name at least one host: it is the app's public name" }} -{{- $first.host | replace "{baseDomain}" .Values.baseDomain | replace "{releaseName}" .Release.Name }} +{{- tpl $first.host . }} {{- end }} {{/* diff --git a/helm-chart/templates/backend-configmap.yaml b/helm-chart/templates/backend-configmap.yaml index 36d85ed2..5c4c559b 100644 --- a/helm-chart/templates/backend-configmap.yaml +++ b/helm-chart/templates/backend-configmap.yaml @@ -1,5 +1,5 @@ -{{- if and (contains "{keycloakService}" .Values.backend.config.oidc.jwksurl) (not .Values.keycloak.enabled) -}} -{{- fail "backend.config.oidc.jwksurl uses {keycloakService}, but keycloak.enabled is false: set jwksurl to the external Keycloak's certs endpoint" -}} +{{- if and (contains "hackagon.keycloakServiceName" .Values.backend.config.oidc.jwksurl) (not .Values.keycloak.enabled) -}} +{{- fail "backend.config.oidc.jwksurl points at the in-cluster Keycloak, but keycloak.enabled is false: set it to the external Keycloak's certs endpoint" -}} {{- end -}} apiVersion: v1 kind: ConfigMap @@ -12,7 +12,7 @@ data: config.yaml: | server: port: {{ .Values.backend.config.server.port | quote }} - adminemail: {{ .Values.backend.config.server.adminemail | replace "{baseDomain}" .Values.baseDomain | quote }} + adminemail: {{ tpl .Values.backend.config.server.adminemail . | quote }} adminkeycloakid: {{ .Values.backend.config.server.adminkeycloakid | quote }} database: driver: {{ .Values.backend.config.database.driver | quote }} @@ -22,8 +22,8 @@ data: user: {{ .Values.backend.config.database.user | quote }} password: {{ .Values.backend.config.database.postgresPassword | required "postgresql.auth.postgresPassword is required" | quote }} oidc: - jwksurl: {{ .Values.backend.config.oidc.jwksurl | replace "{baseDomain}" .Values.baseDomain | replace "{keycloakService}" (include "hackagon.keycloakServiceName" .) | quote }} - issuerurl: {{ .Values.backend.config.oidc.issuerurl | replace "{baseDomain}" .Values.baseDomain | quote }} + jwksurl: {{ tpl .Values.backend.config.oidc.jwksurl . | quote }} + issuerurl: {{ include "hackagon.oidcIssuer" . | quote }} algorithm: {{ .Values.backend.config.oidc.algorithm | quote }} logging: level: {{ .Values.backend.config.logging.level | quote }} diff --git a/helm-chart/templates/frontend-configmap.yaml b/helm-chart/templates/frontend-configmap.yaml index 67a7d073..8ee07355 100644 --- a/helm-chart/templates/frontend-configmap.yaml +++ b/helm-chart/templates/frontend-configmap.yaml @@ -16,5 +16,5 @@ data: useSecure: {{ .Values.frontend.config.cookies.useSecure }} oidc: clientId: {{ .Values.frontend.config.oidc.clientId | quote }} - issuer: {{ .Values.frontend.config.oidc.issuer | replace "{baseDomain}" .Values.baseDomain | quote }} + issuer: {{ include "hackagon.oidcIssuer" . | quote }} audience: {{ .Values.frontend.config.oidc.audience | quote }} \ No newline at end of file diff --git a/helm-chart/templates/frontend-ingress.yaml b/helm-chart/templates/frontend-ingress.yaml index b72f6e40..2af3129e 100644 --- a/helm-chart/templates/frontend-ingress.yaml +++ b/helm-chart/templates/frontend-ingress.yaml @@ -15,7 +15,7 @@ spec: ingressClassName: {{ .Values.frontend.ingress.ingressClass }} rules: {{- range .Values.frontend.ingress.hosts }} - - host: {{ .host | replace "{baseDomain}" $.Values.baseDomain | replace "{releaseName}" $.Release.Name }} + - host: {{ tpl .host $ }} http: paths: {{- range .paths }} @@ -30,12 +30,6 @@ spec: {{- end }} {{- with .Values.frontend.ingress.tls }} tls: - {{- range . }} - - hosts: - {{- range .hosts }} - - {{ . | replace "{baseDomain}" $.Values.baseDomain | replace "{releaseName}" $.Release.Name }} - {{- end }} - secretName: {{ .secretName | replace "{releaseName}" $.Release.Name }} - {{- end }} + {{- tpl (toYaml .) $ | nindent 4 }} {{- end }} {{- end }} \ No newline at end of file diff --git a/helm-chart/values.yaml b/helm-chart/values.yaml index a1810889..21183769 100644 --- a/helm-chart/values.yaml +++ b/helm-chart/values.yaml @@ -52,7 +52,6 @@ frontend: useSecure: true oidc: clientId: hackagon-frontend - issuer: "https://auth.{baseDomain}/realms/hackagon" audience: hackagon-backend service: @@ -70,15 +69,17 @@ frontend: nginx.ingress.kubernetes.io/proxy-buffers: 8 16k nginx.ingress.kubernetes.io/proxy_busy_buffers_size: 32k nginx.ingress.kubernetes.io/ssl-redirect: "true" + # -- Public hostname of the app. The TLS host below and the realm's login + # redirects follow the first entry. hosts: - - host: "app.{baseDomain}" + - host: "app.{{ .Values.baseDomain }}" paths: - path: / pathType: Prefix tls: - - secretName: "{releaseName}-frontend-tls" + - secretName: '{{ .Release.Name }}-frontend-tls' hosts: - - "app.{baseDomain}" + - '{{ include "hackagon.frontendHost" . }}' # ============================================================ # Backend @@ -104,7 +105,7 @@ backend: config: server: port: "3000" - adminemail: "admin@{baseDomain}" + adminemail: "admin@{{ .Values.baseDomain }}" # -- Keycloak user id of the platform admin. Must equal the `id` of the # `hackagon-admin` user in realmJson: casbin grants the `admin` role to # exactly this id, and the backend seeds the admin row by it. Importing @@ -123,10 +124,7 @@ backend: # -- Where the backend fetches Keycloak's signing keys. # With an external Keycloak (keycloak.enabled: false), # override this with a url the backend pod can actually reach. - jwksurl: "http://{keycloakService}:8080/realms/hackagon/protocol/openid-connect/certs" - # -- Must stay the PUBLIC url: this is the `iss` claim Keycloak stamps into - # tokens, and the backend rejects any token whose issuer does not match. - issuerurl: "https://auth.{baseDomain}/realms/hackagon" + jwksurl: 'http://{{ include "hackagon.keycloakServiceName" . }}:8080/realms/hackagon/protocol/openid-connect/certs' algorithm: RS256 logging: level: info @@ -145,9 +143,11 @@ keycloak: # -- Production mode requires hostname and database mode: production - # -- Hostname for Keycloak (public admin UI) + # -- Public url Keycloak runs under; the auth hostname and the OIDC issuer + # derive from it. Required. Passed verbatim to the subchart, so `{...}` + # placeholders are not substituted here. e.g. "https://auth.example.com" hostname: - hostname: "" # e.g. "https://auth.{baseDomain}" + hostname: "" # -- Keycloak's own console admin, which lives in the `master` realm. Its # password is NOT in realmJson: a realm export carries only that realm's diff --git a/tools/helm/lint-values.yaml b/tools/helm/lint-values.yaml index a856756d..fc8decd3 100644 --- a/tools/helm/lint-values.yaml +++ b/tools/helm/lint-values.yaml @@ -5,6 +5,14 @@ baseDomain: lint.invalid +frontend: + ingress: + hosts: + - host: "hackagon-app.lint.invalid" + paths: + - path: / + pathType: Prefix + backend: config: server: @@ -14,7 +22,7 @@ backend: keycloak: hostname: - hostname: "https://auth.lint.invalid" + hostname: "https://hackagon-auth.lint.invalid" database: external: host: "hackagon-postgresql" From 9b52fd53c22a9615cf3926f2ef32c79b25d3e1fa Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 17:29:05 +0200 Subject: [PATCH 05/16] chore(nix): bump inputs --- tools/nix/flake.lock | 1147 +++++++++++++++++++++++++++++++++++++----- 1 file changed, 1030 insertions(+), 117 deletions(-) diff --git a/tools/nix/flake.lock b/tools/nix/flake.lock index 00588aa6..79b2fc8d 100644 --- a/tools/nix/flake.lock +++ b/tools/nix/flake.lock @@ -19,11 +19,11 @@ ] }, "locked": { - "lastModified": 1760971495, - "narHash": "sha256-IwnNtbNVrlZIHh7h4Wz6VP0Furxg9Hh0ycighvL5cZc=", + "lastModified": 1788181969, + "narHash": "sha256-OUB6hPlFBB9FRdZgZXSye4lDOg+fbrqKe8ePv2IM7NY=", "owner": "cachix", "repo": "cachix", - "rev": "c5bfd933d1033672f51a863c47303fc0e093c2d2", + "rev": "98093e8eea6c1635ef1337a576fa76f3e8bd4f39", "type": "github" }, "original": { @@ -41,7 +41,8 @@ ], "flake-compat": [ "quitsh", - "devenv" + "devenv", + "flake-compat" ], "git-hooks": [ "quitsh", @@ -55,11 +56,73 @@ ] }, "locked": { - "lastModified": 1748883665, - "narHash": "sha256-R0W7uAg+BLoHjMRMQ8+oiSbTq8nkGz5RDpQ+ZfxxP3A=", + "lastModified": 1777487137, + "narHash": "sha256-TuvKVBX60mqyMT6OB5JqVEh1YIWtFMR/igLCaCdC9tw=", + "owner": "cachix", + "repo": "cachix", + "rev": "a66a440c321d35f7193472c317f42a55ccd1cb93", + "type": "github" + }, + "original": { + "owner": "cachix", + "ref": "latest", + "repo": "cachix", + "type": "github" + } + }, + "cachix_3": { + "inputs": { + "devenv": [ + "quitsh", + "devenv", + "crate2nix" + ], + "flake-compat": [ + "quitsh", + "devenv", + "crate2nix" + ], + "git-hooks": "git-hooks_2", + "nixpkgs": "nixpkgs_2" + }, + "locked": { + "lastModified": 1767714506, + "narHash": "sha256-WaTs0t1CxhgxbIuvQ97OFhDTVUGd1HA+KzLZUZBhe0s=", + "owner": "cachix", + "repo": "cachix", + "rev": "894c649f0daaa38bbcfb21de64be47dfa7cd0ec9", + "type": "github" + }, + "original": { + "owner": "cachix", + "ref": "latest", + "repo": "cachix", + "type": "github" + } + }, + "cachix_4": { + "inputs": { + "devenv": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable" + ], + "flake-compat": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable" + ], + "git-hooks": "git-hooks_3", + "nixpkgs": "nixpkgs_3" + }, + "locked": { + "lastModified": 1767714506, + "narHash": "sha256-WaTs0t1CxhgxbIuvQ97OFhDTVUGd1HA+KzLZUZBhe0s=", "owner": "cachix", "repo": "cachix", - "rev": "f707778d902af4d62d8dd92c269f8e70de09acbe", + "rev": "894c649f0daaa38bbcfb21de64be47dfa7cd0ec9", "type": "github" }, "original": { @@ -69,28 +132,109 @@ "type": "github" } }, + "crate2nix": { + "flake": false, + "locked": { + "lastModified": 1772186516, + "narHash": "sha256-8s28pzmQ6TOIUzznwFibtW1CMieMUl1rYJIxoQYor58=", + "owner": "rossng", + "repo": "crate2nix", + "rev": "ba5dd398e31ee422fbe021767eb83b0650303a6e", + "type": "github" + }, + "original": { + "owner": "rossng", + "repo": "crate2nix", + "rev": "ba5dd398e31ee422fbe021767eb83b0650303a6e", + "type": "github" + } + }, + "crate2nix_2": { + "inputs": { + "cachix": "cachix_3", + "crate2nix_stable": "crate2nix_stable", + "devshell": "devshell_2", + "flake-compat": "flake-compat_3", + "flake-parts": "flake-parts_4", + "nix-test-runner": "nix-test-runner_2", + "nixpkgs": [ + "quitsh", + "devenv", + "nixpkgs" + ], + "pre-commit-hooks": "pre-commit-hooks_2" + }, + "locked": { + "lastModified": 1772186516, + "narHash": "sha256-8s28pzmQ6TOIUzznwFibtW1CMieMUl1rYJIxoQYor58=", + "owner": "rossng", + "repo": "crate2nix", + "rev": "ba5dd398e31ee422fbe021767eb83b0650303a6e", + "type": "github" + }, + "original": { + "owner": "rossng", + "repo": "crate2nix", + "rev": "ba5dd398e31ee422fbe021767eb83b0650303a6e", + "type": "github" + } + }, + "crate2nix_stable": { + "inputs": { + "cachix": "cachix_4", + "crate2nix_stable": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable" + ], + "devshell": "devshell", + "flake-compat": "flake-compat_2", + "flake-parts": "flake-parts_3", + "nix-test-runner": "nix-test-runner", + "nixpkgs": "nixpkgs_4", + "pre-commit-hooks": "pre-commit-hooks" + }, + "locked": { + "lastModified": 1769627083, + "narHash": "sha256-SUuruvw1/moNzCZosHaa60QMTL+L9huWdsCBN6XZIic=", + "owner": "nix-community", + "repo": "crate2nix", + "rev": "7c33e664668faecf7655fa53861d7a80c9e464a2", + "type": "github" + }, + "original": { + "owner": "nix-community", + "ref": "0.15.0", + "repo": "crate2nix", + "type": "github" + } + }, "devenv": { "inputs": { "cachix": "cachix", + "crate2nix": "crate2nix", "flake-compat": "flake-compat", "flake-parts": "flake-parts", + "ghostty": "ghostty", "git-hooks": "git-hooks", "nix": "nix", + "nixd": "nixd", "nixpkgs": [ "nixpkgs-devenv" - ] + ], + "rust-overlay": "rust-overlay" }, "locked": { - "lastModified": 1764115230, - "narHash": "sha256-xfvW7aF2bDXDXzUeaSOXE+bARfcDbf4YCMVfNp8DTv0=", + "lastModified": 1789478654, + "narHash": "sha256-4GFDdFKT4wXYpzSrL8+rA2WrgwT/9LvCbubdfWWfy68=", "owner": "cachix", "repo": "devenv", - "rev": "51440964cd26a47e90064f9d59aa230a5cefc88b", + "rev": "5d0b738ae13d3a12f9f426884d34b13d74c368fa", "type": "github" }, "original": { "owner": "cachix", - "ref": "v1.11.1", "repo": "devenv", "type": "github" } @@ -122,37 +266,89 @@ "devenv_2": { "inputs": { "cachix": "cachix_2", - "flake-compat": "flake-compat_2", - "git-hooks": "git-hooks_2", + "crate2nix": "crate2nix_2", + "flake-compat": "flake-compat_4", + "flake-parts": "flake-parts_5", + "ghostty": "ghostty_2", + "git-hooks": "git-hooks_4", "nix": "nix_2", + "nixd": "nixd_2", "nixpkgs": [ "quitsh", "nixpkgs-devenv" - ] + ], + "rust-overlay": "rust-overlay_2" }, "locked": { - "lastModified": 1754418859, - "narHash": "sha256-6fnM9o5RIG3OtuBF0yhQMECtqzc5pXAc1uSkVaffy58=", + "lastModified": 1778705847, + "narHash": "sha256-EQnZCy7r4VMO6KDoytxHBa0mFbM1D9g1kaDfs/s0YZA=", "owner": "cachix", "repo": "devenv", - "rev": "e13cd53579f6a0f441ac09230178dccb3008dd36", + "rev": "ea3d94ac9d6bf6a1313773170122ca4e2ef5a0be", "type": "github" }, "original": { "owner": "cachix", - "ref": "main", + "ref": "v2.1.2", "repo": "devenv", "type": "github" } }, + "devshell": { + "inputs": { + "nixpkgs": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1768818222, + "narHash": "sha256-460jc0+CZfyaO8+w8JNtlClB2n4ui1RbHfPTLkpwhU8=", + "owner": "numtide", + "repo": "devshell", + "rev": "255a2b1725a20d060f566e4755dbf571bbbb5f76", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "devshell", + "type": "github" + } + }, + "devshell_2": { + "inputs": { + "nixpkgs": [ + "quitsh", + "devenv", + "crate2nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1768818222, + "narHash": "sha256-460jc0+CZfyaO8+w8JNtlClB2n4ui1RbHfPTLkpwhU8=", + "owner": "numtide", + "repo": "devshell", + "rev": "255a2b1725a20d060f566e4755dbf571bbbb5f76", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "devshell", + "type": "github" + } + }, "flake-compat": { "flake": false, "locked": { - "lastModified": 1761588595, - "narHash": "sha256-XKUZz9zewJNUj46b4AJdiRZJAvSZ0Dqj2BNfXvFlJC4=", + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", "owner": "edolstra", "repo": "flake-compat", - "rev": "f387cd2afec9419c8ee37694406ca490c3f34ee5", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", "type": "github" }, "original": { @@ -162,13 +358,41 @@ } }, "flake-compat_2": { + "locked": { + "lastModified": 1733328505, + "narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=", + "rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec", + "revCount": 69, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/edolstra/flake-compat/1.1.0/01948eb7-9cba-704f-bbf3-3fa956735b52/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz" + } + }, + "flake-compat_3": { + "locked": { + "lastModified": 1733328505, + "narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=", + "rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec", + "revCount": 69, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/edolstra/flake-compat/1.1.0/01948eb7-9cba-704f-bbf3-3fa956735b52/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz" + } + }, + "flake-compat_4": { "flake": false, "locked": { - "lastModified": 1747046372, - "narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=", + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", "owner": "edolstra", "repo": "flake-compat", - "rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", "type": "github" }, "original": { @@ -177,14 +401,14 @@ "type": "github" } }, - "flake-compat_3": { + "flake-compat_5": { "flake": false, "locked": { - "lastModified": 1650374568, - "narHash": "sha256-Z+s0J8/r907g149rllvwhb4pKi8Wam5ij0st8PwAh+E=", + "lastModified": 1761588595, + "narHash": "sha256-XKUZz9zewJNUj46b4AJdiRZJAvSZ0Dqj2BNfXvFlJC4=", "owner": "edolstra", "repo": "flake-compat", - "rev": "b4a34015c698c7793d592d66adbab377907a2be8", + "rev": "f387cd2afec9419c8ee37694406ca490c3f34ee5", "type": "github" }, "original": { @@ -201,11 +425,11 @@ ] }, "locked": { - "lastModified": 1760948891, - "narHash": "sha256-TmWcdiUUaWk8J4lpjzu4gCGxWY6/Ok7mOK4fIFfBuU4=", + "lastModified": 1788306937, + "narHash": "sha256-lbrI1UYVpFgKSsyrU9oeF7FHfnu8nLD9ja0ou9f2rxk=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "864599284fc7c0ba6357ed89ed5e2cd5040f0c04", + "rev": "f16b25b8c3d2809b87925d0b76652d7821a75c68", "type": "github" }, "original": { @@ -218,6 +442,30 @@ "inputs": { "nixpkgs-lib": "nixpkgs-lib" }, + "locked": { + "lastModified": 1788450739, + "narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, + "flake-parts_3": { + "inputs": { + "nixpkgs-lib": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable", + "nixpkgs" + ] + }, "locked": { "lastModified": 1768135262, "narHash": "sha256-PVvu7OqHBGWN16zSi6tEmPwwHQ4rLPU9Plvs8/1TUBY=", @@ -232,21 +480,21 @@ "type": "github" } }, - "flake-parts_3": { + "flake-parts_4": { "inputs": { "nixpkgs-lib": [ "quitsh", "devenv", - "nix", + "crate2nix", "nixpkgs" ] }, "locked": { - "lastModified": 1733312601, - "narHash": "sha256-4pDvzqnegAfRkPwO3wmwBhVi/Sye1mzps0zHWYnP88c=", + "lastModified": 1768135262, + "narHash": "sha256-PVvu7OqHBGWN16zSi6tEmPwwHQ4rLPU9Plvs8/1TUBY=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "205b12d8b7cd4802fbcb8e8ef6a0f1408781a4f9", + "rev": "80daad04eddbbf5a4d883996a73f3f542fa437ac", "type": "github" }, "original": { @@ -255,40 +503,83 @@ "type": "github" } }, - "flake-utils": { + "flake-parts_5": { "inputs": { - "systems": "systems" + "nixpkgs-lib": [ + "quitsh", + "devenv", + "nixpkgs" + ] }, "locked": { - "lastModified": 1694529238, - "narHash": "sha256-zsNZZGTGnMOf9YpHKJqMSsa0dXbfmxeoJ7xHlrt+xmY=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "ff7b65b44d01cf9ba6a71320833626af21126384", + "lastModified": 1777678872, + "narHash": "sha256-EPIFsulyon7Z1vLQq5Fk64GR8L7cQsT+IPhcsukVbgk=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "5250617bffd85403b14dbf43c3870e7f255d2c16", "type": "github" }, "original": { - "owner": "numtide", - "repo": "flake-utils", + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, + "flake-parts_6": { + "inputs": { + "nixpkgs-lib": "nixpkgs-lib_2" + }, + "locked": { + "lastModified": 1785627969, + "narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, + "ghostty": { + "flake": false, + "locked": { + "lastModified": 1786026742, + "narHash": "sha256-tRtgTg/i3w1nFdRHU2IGekfJN8EyP+HARW4MtoUZyqk=", + "owner": "ghostty-org", + "repo": "ghostty", + "rev": "22d13172cde98a0a4dda05d3d6a3fcb0dd8ed018", + "type": "github" + }, + "original": { + "owner": "ghostty-org", + "repo": "ghostty", + "rev": "22d13172cde98a0a4dda05d3d6a3fcb0dd8ed018", "type": "github" } }, - "flake-utils-plus": { + "ghostty_2": { "inputs": { - "flake-utils": "flake-utils" + "flake-compat": "flake-compat_5", + "home-manager": "home-manager", + "nixpkgs": "nixpkgs_5", + "systems": "systems", + "zig": "zig", + "zon2nix": "zon2nix" }, "locked": { - "lastModified": 1715533576, - "narHash": "sha256-fT4ppWeCJ0uR300EH3i7kmgRZnAVxrH+XtK09jQWihk=", - "owner": "gytis-ivaskevicius", - "repo": "flake-utils-plus", - "rev": "3542fe9126dc492e53ddd252bb0260fe035f2c0f", + "lastModified": 1777773742, + "narHash": "sha256-dZFc+8az7BUIs8+v45XqNnY5G6oXEwVfVVHZQuATSGQ=", + "owner": "ghostty-org", + "repo": "ghostty", + "rev": "1547dd667ab6d1f4ebcdc7282adc54c95752ee67", "type": "github" }, "original": { - "owner": "gytis-ivaskevicius", - "repo": "flake-utils-plus", - "rev": "3542fe9126dc492e53ddd252bb0260fe035f2c0f", + "owner": "ghostty-org", + "repo": "ghostty", "type": "github" } }, @@ -298,18 +589,17 @@ "devenv", "flake-compat" ], - "gitignore": "gitignore", "nixpkgs": [ "devenv", "nixpkgs" ] }, "locked": { - "lastModified": 1760663237, - "narHash": "sha256-BflA6U4AM1bzuRMR8QqzPXqh8sWVCNDzOdsxXEguJIc=", + "lastModified": 1788267358, + "narHash": "sha256-nt+lUqYVpc9Y6JeMd2WmXzCDojasdadKo0mWcluvY2Y=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "ca5b894d3e3e151ffc1db040b6ce4dcc75d31c37", + "rev": "27555e2624241fb116b49095df4caaee85a25691", "type": "github" }, "original": { @@ -323,21 +613,87 @@ "flake-compat": [ "quitsh", "devenv", + "crate2nix", + "cachix", + "flake-compat" + ], + "gitignore": "gitignore", + "nixpkgs": [ + "quitsh", + "devenv", + "crate2nix", + "cachix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1765404074, + "narHash": "sha256-+ZDU2d+vzWkEJiqprvV5PR26DVFN2vgddwG5SnPZcUM=", + "owner": "cachix", + "repo": "git-hooks.nix", + "rev": "2d6f58930fbcd82f6f9fd59fb6d13e37684ca529", + "type": "github" + }, + "original": { + "owner": "cachix", + "repo": "git-hooks.nix", + "type": "github" + } + }, + "git-hooks_3": { + "inputs": { + "flake-compat": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable", + "cachix", "flake-compat" ], "gitignore": "gitignore_2", "nixpkgs": [ "quitsh", "devenv", + "crate2nix", + "crate2nix_stable", + "cachix", "nixpkgs" ] }, "locked": { - "lastModified": 1750779888, - "narHash": "sha256-wibppH3g/E2lxU43ZQHC5yA/7kIKLGxVEnsnVK1BtRg=", + "lastModified": 1765404074, + "narHash": "sha256-+ZDU2d+vzWkEJiqprvV5PR26DVFN2vgddwG5SnPZcUM=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "16ec914f6fb6f599ce988427d9d94efddf25fe6d", + "rev": "2d6f58930fbcd82f6f9fd59fb6d13e37684ca529", + "type": "github" + }, + "original": { + "owner": "cachix", + "repo": "git-hooks.nix", + "type": "github" + } + }, + "git-hooks_4": { + "inputs": { + "flake-compat": [ + "quitsh", + "devenv", + "flake-compat" + ], + "gitignore": "gitignore_5", + "nixpkgs": [ + "quitsh", + "devenv", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1776796298, + "narHash": "sha256-PcRvlWayisPSjd0UcRQbhG8Oqw78AcPE6x872cPRHN8=", + "owner": "cachix", + "repo": "git-hooks.nix", + "rev": "3cfd774b0a530725a077e17354fbdb87ea1c4aad", "type": "github" }, "original": { @@ -349,7 +705,10 @@ "gitignore": { "inputs": { "nixpkgs": [ + "quitsh", "devenv", + "crate2nix", + "cachix", "git-hooks", "nixpkgs" ] @@ -373,6 +732,9 @@ "nixpkgs": [ "quitsh", "devenv", + "crate2nix", + "crate2nix_stable", + "cachix", "git-hooks", "nixpkgs" ] @@ -391,13 +753,123 @@ "type": "github" } }, - "import-tree": { + "gitignore_3": { + "inputs": { + "nixpkgs": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable", + "pre-commit-hooks", + "nixpkgs" + ] + }, "locked": { - "lastModified": 1763762820, - "narHash": "sha256-ZvYKbFib3AEwiNMLsejb/CWs/OL/srFQ8AogkebEPF0=", + "lastModified": 1709087332, + "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", + "owner": "hercules-ci", + "repo": "gitignore.nix", + "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "gitignore.nix", + "type": "github" + } + }, + "gitignore_4": { + "inputs": { + "nixpkgs": [ + "quitsh", + "devenv", + "crate2nix", + "pre-commit-hooks", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1709087332, + "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", + "owner": "hercules-ci", + "repo": "gitignore.nix", + "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "gitignore.nix", + "type": "github" + } + }, + "gitignore_5": { + "inputs": { + "nixpkgs": [ + "quitsh", + "devenv", + "git-hooks", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1709087332, + "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", + "owner": "hercules-ci", + "repo": "gitignore.nix", + "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "gitignore.nix", + "type": "github" + } + }, + "home-manager": { + "inputs": { + "nixpkgs": [ + "quitsh", + "devenv", + "ghostty", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1770586272, + "narHash": "sha256-Ucci8mu8QfxwzyfER2DQDbvW9t1BnTUJhBmY7ybralo=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "b1f916ba052341edc1f80d4b2399f1092a4873ca", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "home-manager", + "type": "github" + } + }, + "import-tree": { + "locked": { + "lastModified": 1788467110, + "narHash": "sha256-ljEMTXP/rH0tOvDzc9gzwww6KcHRPRnEHzd9lK48V7s=", "owner": "vic", "repo": "import-tree", - "rev": "3c23749d8013ec6daa1d7255057590e9ca726646", + "rev": "eb1b52eaecc57f7c136d07ae8a93e724dfecac46", + "type": "github" + }, + "original": { + "owner": "vic", + "repo": "import-tree", + "type": "github" + } + }, + "import-tree_2": { + "locked": { + "lastModified": 1784254960, + "narHash": "sha256-iI88R3wHz8wTKQb5orvpc51L/Xr64AJyxid/0MKa/b8=", + "owner": "vic", + "repo": "import-tree", + "rev": "4ebb10ae17d5f1ad366e7aef5b92cb8eecf24f69", "type": "github" }, "original": { @@ -432,20 +904,52 @@ ] }, "locked": { - "lastModified": 1761648602, - "narHash": "sha256-H97KSB/luq/aGobKRuHahOvT1r7C03BgB6D5HBZsbN8=", + "lastModified": 1788036898, + "narHash": "sha256-3NT3yTvoRT7+rxLDNovpyeTDIJkZlBoO72rcu2x9Y9o=", "owner": "cachix", "repo": "nix", - "rev": "3e5644da6830ef65f0a2f7ec22830c46285bfff6", + "rev": "b9b81726b38469c55b9706d80d37d6c73cc7f76c", "type": "github" }, "original": { "owner": "cachix", - "ref": "devenv-2.30.6", + "ref": "devenv-2.35", "repo": "nix", "type": "github" } }, + "nix-test-runner": { + "flake": false, + "locked": { + "lastModified": 1588761593, + "narHash": "sha256-FKJykltAN/g3eIceJl4SfDnnyuH2jHImhMrXS2KvGIs=", + "owner": "stoeffel", + "repo": "nix-test-runner", + "rev": "c45d45b11ecef3eb9d834c3b6304c05c49b06ca2", + "type": "github" + }, + "original": { + "owner": "stoeffel", + "repo": "nix-test-runner", + "type": "github" + } + }, + "nix-test-runner_2": { + "flake": false, + "locked": { + "lastModified": 1588761593, + "narHash": "sha256-FKJykltAN/g3eIceJl4SfDnnyuH2jHImhMrXS2KvGIs=", + "owner": "stoeffel", + "repo": "nix-test-runner", + "rev": "c45d45b11ecef3eb9d834c3b6304c05c49b06ca2", + "type": "github" + }, + "original": { + "owner": "stoeffel", + "repo": "nix-test-runner", + "type": "github" + } + }, "nix_2": { "inputs": { "flake-compat": [ @@ -453,7 +957,11 @@ "devenv", "flake-compat" ], - "flake-parts": "flake-parts_3", + "flake-parts": [ + "quitsh", + "devenv", + "flake-parts" + ], "git-hooks-nix": [ "quitsh", "devenv", @@ -474,27 +982,77 @@ ] }, "locked": { - "lastModified": 1752773918, - "narHash": "sha256-dOi/M6yNeuJlj88exI+7k154z+hAhFcuB8tZktiW7rg=", + "lastModified": 1776511668, + "narHash": "sha256-g2KEBuHpc3a56c+jPcg0+w6LSuIj6f+zzdztLCOyIhc=", "owner": "cachix", "repo": "nix", - "rev": "031c3cf42d2e9391eee373507d8c12e0f9606779", + "rev": "42d4b7de21c15f28c568410f4383fa06a8458a40", "type": "github" }, "original": { "owner": "cachix", - "ref": "devenv-2.30", + "ref": "devenv-2.34", "repo": "nix", "type": "github" } }, + "nixd": { + "inputs": { + "flake-parts": [ + "devenv", + "flake-parts" + ], + "nixpkgs": [ + "devenv", + "nixpkgs" + ], + "treefmt-nix": "treefmt-nix" + }, + "locked": { + "lastModified": 1788165251, + "narHash": "sha256-ITHt6eU6DuwQqlNV1/wehvKYPE6J8sZIlv75CpDjcHI=", + "owner": "nix-community", + "repo": "nixd", + "rev": "e2ca72c353cfbc3d63e942fe9aeae4ec497863bf", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixd", + "type": "github" + } + }, + "nixd_2": { + "inputs": { + "flake-parts": [ + "quitsh", + "devenv", + "flake-parts" + ], + "nixpkgs": "nixpkgs_6", + "treefmt-nix": "treefmt-nix_2" + }, + "locked": { + "lastModified": 1777345723, + "narHash": "sha256-BhY3D5DhpDnnUcaY+AL/cpyYX+OIjQgnAkbPLZ08C38=", + "owner": "nix-community", + "repo": "nixd", + "rev": "6bf30951a3dc407a798d30db427e3f96ac9b39f5", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixd", + "type": "github" + } + }, "nixpkgs": { "locked": { - "lastModified": 1769170682, - "narHash": "sha256-oMmN1lVQU0F0W2k6OI3bgdzp2YOHWYUAw79qzDSjenU=", + "lastModified": 1789286504, + "narHash": "sha256-eiEK7cKZORNEvX0GeF3RtNEF/JXhgf2RqSp3230q13E=", "owner": "nixos", "repo": "nixpkgs", - "rev": "c5296fdd05cfa2c187990dd909864da9658df755", + "rev": "ef34387ddd751e1ab8857adf4676492d32eb24ec", "type": "github" }, "original": { @@ -506,59 +1064,63 @@ }, "nixpkgs-codecov": { "locked": { - "lastModified": 1762596750, - "narHash": "sha256-rXXuz51Bq7DHBlfIjN7jO8Bu3du5TV+3DSADBX7/9YQ=", + "lastModified": 1789485466, + "narHash": "sha256-Gu58HB6Do4+CUqjEqZ7FhyTqGnuUFRCGnAxwkFow2oM=", "owner": "nixos", "repo": "nixpkgs", - "rev": "b6a8526db03f735b89dd5ff348f53f752e7ddc8e", + "rev": "89b943e11a59691286c6600c92334057c1f1dd93", "type": "github" }, "original": { "owner": "nixos", - "ref": "b6a8526db03f735b89dd5ff348f53f752e7ddc8e", "repo": "nixpkgs", "type": "github" } }, "nixpkgs-devenv": { + "inputs": { + "nixpkgs-src": "nixpkgs-src" + }, "locked": { - "lastModified": 1761313199, - "narHash": "sha256-wCIACXbNtXAlwvQUo1Ed++loFALPjYUA3dpcUJiXO44=", + "lastModified": 1789386988, + "narHash": "sha256-lGaWnDC3IZWfLSLTdqKXJgkPPBzM0ptk26wVGCOfDaM=", "owner": "cachix", "repo": "devenv-nixpkgs", - "rev": "d1c30452ebecfc55185ae6d1c983c09da0c274ff", + "rev": "a9f756cc5ccbe0732f671d21190622213ad0b521", "type": "github" }, "original": { "owner": "cachix", - "ref": "d1c30452ebecfc55185ae6d1c983c09da0c274ff", "repo": "devenv-nixpkgs", "type": "github" } }, "nixpkgs-devenv_2": { + "inputs": { + "nixpkgs-src": "nixpkgs-src_2" + }, "locked": { - "lastModified": 1753719760, - "narHash": "sha256-GG9WAqR1BWNNBHONF4jQtkwPNQt5EK/zERl5Tbc8Bqk=", + "lastModified": 1776852779, + "narHash": "sha256-WwO/ITisCXwyiRgtktZgv3iGhAGO+IB5Av4kKCwezR0=", "owner": "cachix", "repo": "devenv-nixpkgs", - "rev": "0f871fffdc0e5852ec25af99ea5f09ca7be9b632", + "rev": "ec3063523dcd911aeadb50faa589f237cdab5853", "type": "github" }, "original": { "owner": "cachix", - "ref": "rolling", + "ref": "ec3063523dcd911aeadb50faa589f237cdab5853", "repo": "devenv-nixpkgs", "type": "github" } }, "nixpkgs-lib": { "locked": { - "lastModified": 1765674936, - "narHash": "sha256-k00uTP4JNfmejrCLJOwdObYC9jHRrr/5M/a/8L2EIdo=", + "lastModified": 1788057806, + "narHash": "sha256-DTQSMxzDWmT0zhguthvegnVkn7CFqGCv4IHCzk5ZUpM=", "owner": "nix-community", "repo": "nixpkgs.lib", - "rev": "2075416fcb47225d9b68ac469a5c4801a9c4dd85", + "rev": "596e2e3940e09b2abbeb03f75fa1828c57fcd72c", "type": "github" }, "original": { @@ -567,24 +1129,211 @@ "type": "github" } }, + "nixpkgs-lib_2": { + "locked": { + "lastModified": 1785031560, + "narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, + "nixpkgs-src": { + "flake": false, + "locked": { + "lastModified": 1789264731, + "narHash": "sha256-llGJbC0CcU8DfROr6mZjRJgMLQd/SKwfpzxJH/2lHO4=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "02f5696b0e6097e589076d886b317b83ff0437d7", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs-src_2": { + "flake": false, + "locked": { + "lastModified": 1776329215, + "narHash": "sha256-a8BYi3mzoJ/AcJP8UldOx8emoPRLeWqALZWu4ZvjPXw=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "b86751bc4085f48661017fa226dee99fab6c651b", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_2": { + "locked": { + "lastModified": 1765186076, + "narHash": "sha256-hM20uyap1a0M9d344I692r+ik4gTMyj60cQWO+hAYP8=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "addf7cf5f383a3101ecfba091b98d0a1263dc9b8", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_3": { + "locked": { + "lastModified": 1765186076, + "narHash": "sha256-hM20uyap1a0M9d344I692r+ik4gTMyj60cQWO+hAYP8=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "addf7cf5f383a3101ecfba091b98d0a1263dc9b8", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_4": { + "locked": { + "lastModified": 1769433173, + "narHash": "sha256-Gf1dFYgD344WZ3q0LPlRoWaNdNQq8kSBDLEWulRQSEs=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "13b0f9e6ac78abbbb736c635d87845c4f4bee51b", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixpkgs-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_5": { + "locked": { + "lastModified": 1770537093, + "narHash": "sha256-XV30uo8tXuxdzuV8l3sojmlPRLd/8tpMsOp4lNzLGUo=", + "rev": "fef9403a3e4d31b0a23f0bacebbec52c248fbb51", + "type": "tarball", + "url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.05pre942631.fef9403a3e4d/nixexprs.tar.xz" + }, + "original": { + "type": "tarball", + "url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.xz" + } + }, + "nixpkgs_6": { + "locked": { + "lastModified": 1776877367, + "narHash": "sha256-wMN1gM00sUQ2KC9CNr/XEOGdfOrl67PabIRv9AYayTo=", + "rev": "0726a0ecb6d4e08f6adced58726b95db924cef57", + "type": "tarball", + "url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre985613.0726a0ecb6d4/nixexprs.tar.xz" + }, + "original": { + "type": "tarball", + "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz" + } + }, + "pre-commit-hooks": { + "inputs": { + "flake-compat": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable", + "flake-compat" + ], + "gitignore": "gitignore_3", + "nixpkgs": [ + "quitsh", + "devenv", + "crate2nix", + "crate2nix_stable", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1769069492, + "narHash": "sha256-Efs3VUPelRduf3PpfPP2ovEB4CXT7vHf8W+xc49RL/U=", + "owner": "cachix", + "repo": "pre-commit-hooks.nix", + "rev": "a1ef738813b15cf8ec759bdff5761b027e3e1d23", + "type": "github" + }, + "original": { + "owner": "cachix", + "repo": "pre-commit-hooks.nix", + "type": "github" + } + }, + "pre-commit-hooks_2": { + "inputs": { + "flake-compat": [ + "quitsh", + "devenv", + "crate2nix", + "flake-compat" + ], + "gitignore": "gitignore_4", + "nixpkgs": [ + "quitsh", + "devenv", + "crate2nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1769069492, + "narHash": "sha256-Efs3VUPelRduf3PpfPP2ovEB4CXT7vHf8W+xc49RL/U=", + "owner": "cachix", + "repo": "pre-commit-hooks.nix", + "rev": "a1ef738813b15cf8ec759bdff5761b027e3e1d23", + "type": "github" + }, + "original": { + "owner": "cachix", + "repo": "pre-commit-hooks.nix", + "type": "github" + } + }, "quitsh": { "inputs": { "devenv": "devenv_2", "devenv-root": "devenv-root_2", + "flake-parts": "flake-parts_6", + "import-tree": "import-tree_2", "nixpkgs": [ "nixpkgs" ], "nixpkgs-devenv": "nixpkgs-devenv_2", - "snowfall-lib": "snowfall-lib", - "treefmt-nix": "treefmt-nix" + "systems": "systems_2", + "treefmt-nix": "treefmt-nix_3" }, "locked": { "dir": "tools/nix", - "lastModified": 1773912389, - "narHash": "sha256-RBziGwWho9E8qczLSANKm7VLtZvz7kHmlaLSxQf4vjU=", + "lastModified": 1788770040, + "narHash": "sha256-ptQDCmGjiMwvZVfn7lMCOtplgQHrdCnZf6AKVWwK0fI=", "owner": "sdsc-ordes", "repo": "quitsh", - "rev": "2c1439a969614c2f58040b215439d31e5373d75e", + "rev": "eff0987627d97073db5971d429cce40fd98625d0", "type": "github" }, "original": { @@ -605,33 +1354,54 @@ "nixpkgs-codecov": "nixpkgs-codecov", "nixpkgs-devenv": "nixpkgs-devenv", "quitsh": "quitsh", - "treefmt-nix": "treefmt-nix_2" + "treefmt-nix": "treefmt-nix_4" } }, - "snowfall-lib": { + "rust-overlay": { + "inputs": { + "nixpkgs": [ + "devenv", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1788332415, + "narHash": "sha256-BTFrmyh0oaVDsvA9NNw0YpbbeppTwU0t70iVx672Ew8=", + "owner": "oxalica", + "repo": "rust-overlay", + "rev": "860d7c835ab91bfc8972b67092f5f2db8e9390a0", + "type": "github" + }, + "original": { + "owner": "oxalica", + "repo": "rust-overlay", + "type": "github" + } + }, + "rust-overlay_2": { "inputs": { - "flake-compat": "flake-compat_3", - "flake-utils-plus": "flake-utils-plus", "nixpkgs": [ "quitsh", + "devenv", "nixpkgs" ] }, "locked": { - "lastModified": 1736130495, - "narHash": "sha256-4i9nAJEZFv7vZMmrE0YG55I3Ggrtfo5/T07JEpEZ/RM=", - "owner": "snowfallorg", - "repo": "lib", - "rev": "02d941739f98a09e81f3d2d9b3ab08918958beac", + "lastModified": 1777778183, + "narHash": "sha256-Lqv9MZO0XAGcMbXJU+ULBSMD41Pf391uJehylUQKe7Y=", + "owner": "oxalica", + "repo": "rust-overlay", + "rev": "dbba5f888c82ef3ce594c451c33ac2474eb80847", "type": "github" }, "original": { - "owner": "snowfallorg", - "repo": "lib", + "owner": "oxalica", + "repo": "rust-overlay", "type": "github" } }, "systems": { + "flake": false, "locked": { "lastModified": 1681028828, "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", @@ -646,19 +1416,34 @@ "type": "github" } }, + "systems_2": { + "flake": false, + "locked": { + "path": "./flake/systems.nix", + "type": "path" + }, + "original": { + "path": "./flake/systems.nix", + "type": "path" + }, + "parent": [ + "quitsh" + ] + }, "treefmt-nix": { "inputs": { "nixpkgs": [ - "quitsh", + "devenv", + "nixd", "nixpkgs" ] }, "locked": { - "lastModified": 1750931469, - "narHash": "sha256-0IEdQB1nS+uViQw4k3VGUXntjkDp7aAlqcxdewb/hAc=", + "lastModified": 1786901030, + "narHash": "sha256-WSFCsDSE5ffgD2MqzkM2CYjeFiKhRF/dJUN8uedb6YE=", "owner": "numtide", "repo": "treefmt-nix", - "rev": "ac8e6f32e11e9c7f153823abc3ab007f2a65d3e1", + "rev": "27b3b12a8e6375f28ebe122f07d230ca5459bbfa", "type": "github" }, "original": { @@ -670,15 +1455,39 @@ "treefmt-nix_2": { "inputs": { "nixpkgs": [ + "quitsh", + "devenv", + "nixd", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1775636079, + "narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" + } + }, + "treefmt-nix_3": { + "inputs": { + "nixpkgs": [ + "quitsh", "nixpkgs" ] }, "locked": { - "lastModified": 1769515380, - "narHash": "sha256-CWWK3PaQ7zhr+Jcf5zyaTR2cfRBXPo09H7+5nWApL8s=", + "lastModified": 1775636079, + "narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=", "owner": "numtide", "repo": "treefmt-nix", - "rev": "9911802c2822def2eec3d22e2cafd1619ede94a5", + "rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba", "type": "github" }, "original": { @@ -686,6 +1495,110 @@ "repo": "treefmt-nix", "type": "github" } + }, + "treefmt-nix_4": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1786901030, + "narHash": "sha256-WSFCsDSE5ffgD2MqzkM2CYjeFiKhRF/dJUN8uedb6YE=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "27b3b12a8e6375f28ebe122f07d230ca5459bbfa", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" + } + }, + "zig": { + "inputs": { + "flake-compat": [ + "quitsh", + "devenv", + "ghostty", + "flake-compat" + ], + "nixpkgs": [ + "quitsh", + "devenv", + "ghostty", + "nixpkgs" + ], + "systems": [ + "quitsh", + "devenv", + "ghostty", + "systems" + ] + }, + "locked": { + "lastModified": 1776789209, + "narHash": "sha256-G6B7Q4TXn7MZ1mB+f9rymjsYF5PLWoSvmbxijb/99bw=", + "owner": "mitchellh", + "repo": "zig-overlay", + "rev": "14fe971844e841297ddd2ce9783d6892b467af39", + "type": "github" + }, + "original": { + "owner": "mitchellh", + "repo": "zig-overlay", + "type": "github" + } + }, + "zig_2": { + "inputs": { + "nixpkgs": [ + "quitsh", + "devenv", + "ghostty", + "zon2nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1777234348, + "narHash": "sha256-fKw44a4qbUuI5eTG8k0gPbqMV5TOrjYF35PBzsYgd2U=", + "ref": "refs/heads/main", + "rev": "2c781c0609ecda600ab98f98cca417bbd981bd53", + "revCount": 1677, + "type": "git", + "url": "https://codeberg.org/jcollie/zig-overlay.git" + }, + "original": { + "type": "git", + "url": "https://codeberg.org/jcollie/zig-overlay.git" + } + }, + "zon2nix": { + "inputs": { + "nixpkgs": [ + "quitsh", + "devenv", + "ghostty", + "nixpkgs" + ], + "zig": "zig_2" + }, + "locked": { + "lastModified": 1777314365, + "narHash": "sha256-eLxQaD0wc96Neqkln8wHS0rNq/chPODifFkhwrwilEU=", + "owner": "jcollie", + "repo": "zon2nix", + "rev": "a5a1d412ad1ab6305511997bbc92b3a9dd6cb784", + "type": "github" + }, + "original": { + "owner": "jcollie", + "ref": "main", + "repo": "zon2nix", + "type": "github" + } } }, "root": "root", From fefe9311d65eae85ab7457ef9e046811c2735d23 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 17:29:33 +0200 Subject: [PATCH 06/16] fix(nix): unpin inputs, we have a lockfile --- tools/nix/flake.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/tools/nix/flake.nix b/tools/nix/flake.nix index a18def3a..62c7d60a 100644 --- a/tools/nix/flake.nix +++ b/tools/nix/flake.nix @@ -26,18 +26,18 @@ # - for codecov. # FIXME: https://github.com/getsentry/prevent-cli/issues/107 # Last working version. - nixpkgs-codecov.url = "github:nixos/nixpkgs?ref=b6a8526db03f735b89dd5ff348f53f752e7ddc8e"; + nixpkgs-codecov.url = "github:nixos/nixpkgs"; # =================================== # The devenv module to create good development shells. # The `nixpkgs-devenv` must aligned with the pinned version. devenv = { - url = "github:cachix/devenv?ref=v1.11.1"; + url = "github:cachix/devenv"; inputs.nixpkgs.follows = "nixpkgs-devenv"; }; # This is the rolling nixpkgs with what devenv was tested. nixpkgs-devenv = { - url = "github:cachix/devenv-nixpkgs?ref=d1c30452ebecfc55185ae6d1c983c09da0c274ff"; + url = "github:cachix/devenv-nixpkgs"; }; devenv-root = { url = "file+file:///dev/null"; From 24e777f654adbfb44f15ebad7540551f334dd8c9 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 17:29:51 +0200 Subject: [PATCH 07/16] fix(nix): disable devenv dotenv integration -> not supported in flakes --- tools/nix/hackagon/lib/toolchain.nix | 2 -- 1 file changed, 2 deletions(-) diff --git a/tools/nix/hackagon/lib/toolchain.nix b/tools/nix/hackagon/lib/toolchain.nix index e181c045..563441c2 100644 --- a/tools/nix/hackagon/lib/toolchain.nix +++ b/tools/nix/hackagon/lib/toolchain.nix @@ -389,8 +389,6 @@ let quitsh.config = lib.mkForce "tools/configs/quitsh/config.yaml"; quitsh.configUser = "tools/configs/quitsh/config.user.yaml"; - dotenv.enable = true; - packages = [ # Essentials. pkgs.git From b8c1093a31f89c5416ff2c6ef8b9d56259496a36 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 18:19:20 +0200 Subject: [PATCH 08/16] chore(nix): bump claude --- tools/nix/flake.nix | 6 ++++++ tools/nix/hackagon/pkgs/build.parts.nix | 2 +- 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/tools/nix/flake.nix b/tools/nix/flake.nix index 62c7d60a..51dae99d 100644 --- a/tools/nix/flake.nix +++ b/tools/nix/flake.nix @@ -50,10 +50,16 @@ inputs.nixpkgs.follows = "nixpkgs"; }; + # The list of platforms to build for. Declared so quitsh can follow it: + # quitsh declares its own as a relative `path:` input, which nix cannot + # lock, and an unlocked input is fatal when CI evaluates a pinned flake. + systems.url = "github:nix-systems/default"; + # Quitsh functionality. quitsh = { url = "github:sdsc-ordes/quitsh?ref=main&dir=tools/nix"; inputs.nixpkgs.follows = "nixpkgs"; + inputs.systems.follows = "systems"; }; # Importing flake-parts modules recursively. diff --git a/tools/nix/hackagon/pkgs/build.parts.nix b/tools/nix/hackagon/pkgs/build.parts.nix index 3cb442a9..3b081b0a 100644 --- a/tools/nix/hackagon/pkgs/build.parts.nix +++ b/tools/nix/hackagon/pkgs/build.parts.nix @@ -25,7 +25,7 @@ pkgs.codecov-cli; pkgsPinned = { - go = pkgs.go_1_25; + go = pkgs.go_1_26; python = pkgs.python314; inherit codecov-cli; nodejs = pkgs.nodejs_22; From 804b04825f749a83dcb579dfac19995e1439daf7 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 18:21:02 +0200 Subject: [PATCH 09/16] chore: changelog formatting --- CHANGELOG.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3e4105e5..42f6f75e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -20,8 +20,8 @@ written while it was being built. See [RELEASING.md](RELEASING.md). ### Changed -- A deployment can now be reached under any hostnames, not only - `app.` and `auth.`. The app's hostname is the first entry of +- A deployment can now be reached under any hostnames, not only `app.` + and `auth.`. The app's hostname is the first entry of `frontend.ingress.hosts`, Keycloak's is `keycloak.hostname.hostname`, and the chart derives the ingresses, the TLS certificates, the OIDC issuer urls and the realm's login redirect urls from those two. Previously the subdomains were From b82d6de853f6adfe6391d63bd58ab27a7e0d255f Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 18:24:23 +0200 Subject: [PATCH 10/16] chore(nix): update lock --- tools/nix/flake.lock | 24 ++++++++++++++---------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/tools/nix/flake.lock b/tools/nix/flake.lock index 79b2fc8d..5d4ce5c1 100644 --- a/tools/nix/flake.lock +++ b/tools/nix/flake.lock @@ -1324,7 +1324,9 @@ "nixpkgs" ], "nixpkgs-devenv": "nixpkgs-devenv_2", - "systems": "systems_2", + "systems": [ + "systems" + ], "treefmt-nix": "treefmt-nix_3" }, "locked": { @@ -1354,6 +1356,7 @@ "nixpkgs-codecov": "nixpkgs-codecov", "nixpkgs-devenv": "nixpkgs-devenv", "quitsh": "quitsh", + "systems": "systems_2", "treefmt-nix": "treefmt-nix_4" } }, @@ -1417,18 +1420,19 @@ } }, "systems_2": { - "flake": false, "locked": { - "path": "./flake/systems.nix", - "type": "path" + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" }, "original": { - "path": "./flake/systems.nix", - "type": "path" - }, - "parent": [ - "quitsh" - ] + "owner": "nix-systems", + "repo": "default", + "type": "github" + } }, "treefmt-nix": { "inputs": { From 531e03334e125521339dc1ce52fd4c944687d8b9 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Tue, 15 Sep 2026 18:37:51 +0200 Subject: [PATCH 11/16] fix(nix): macos friendly fakeroot setup --- .../tools/nix/pkgs/service-image/default.nix | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/components/backend/tools/nix/pkgs/service-image/default.nix b/components/backend/tools/nix/pkgs/service-image/default.nix index dbe9d458..822e7a33 100644 --- a/components/backend/tools/nix/pkgs/service-image/default.nix +++ b/components/backend/tools/nix/pkgs/service-image/default.nix @@ -1,6 +1,7 @@ { pkgs, service, + cnLib, ... }: pkgs.dockerTools.buildLayeredImage { @@ -8,22 +9,21 @@ pkgs.dockerTools.buildLayeredImage { tag = service.version; contents = [ + cnLib.image.etcGroupAndPasswd service ]; + # Users come from a static /etc/passwd rather than `shadowSetup`, so the + # build needs no chroot: `enableFakechroot` relies on `proot`, which does + # not work on Darwin. Paths are relative to the image root, which is the + # working directory of the restricted fakeroot environment. fakeRootCommands = '' - ${pkgs.dockerTools.shadowSetup} - # Link API files, to execution folder. - mkdir -p /workspace/data/api + mkdir -p workspace/data/api - groupadd -r non-root -g 1000 - useradd -r -g non-root -u 1000 non-root - chown -R non-root:non-root /workspace - chmod -R u+rw /workspace + chown -R 1000:1000 workspace + chmod -R u+rw workspace ''; - enableFakechroot = true; - config = { Entrypoint = [ "${service}/bin/${service.pname}" ]; WorkingDir = "/workspace"; From 8b1e684c5a4b6e0c6bee344df5b7b1fb322a0d2e Mon Sep 17 00:00:00 2001 From: cmdoret Date: Wed, 16 Sep 2026 11:38:52 +0200 Subject: [PATCH 12/16] doc(chart): explain tls host evaluation --- helm-chart/values.yaml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/helm-chart/values.yaml b/helm-chart/values.yaml index 9c532a2c..fa3f49e8 100644 --- a/helm-chart/values.yaml +++ b/helm-chart/values.yaml @@ -78,7 +78,8 @@ frontend: tls: - secretName: '{{ .Release.Name }}-frontend-tls' hosts: - - '{{ include "hackagon.frontendHost" . }}' + # Evaluates to the first host in frontend.ingress.hosts + - '{{ include "hackagon.frontendHost" . }}' # ============================================================ # Backend From 61a4879e965387d5a68ec3187a52a47153c54543 Mon Sep 17 00:00:00 2001 From: Cyril Matthey-Doret Date: Wed, 16 Sep 2026 11:43:12 +0200 Subject: [PATCH 13/16] fix(chart): update notes Updated Keycloak URL format in NOTES.txt. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- helm-chart/templates/NOTES.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm-chart/templates/NOTES.txt b/helm-chart/templates/NOTES.txt index 85206c5e..7a35c30b 100644 --- a/helm-chart/templates/NOTES.txt +++ b/helm-chart/templates/NOTES.txt @@ -1,7 +1,7 @@ Hackagon has been deployed! Frontend: https://{{ include "hackagon.frontendHost" . }} -Keycloak: https://{{ include "hackagon.keycloakHost" . }} +Keycloak: {{ include "hackagon.keycloakUrl" . }} To get the generated frontend OIDC secrets, run: From e756c88b45598399d40525f363cdd59098b38819 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Wed, 16 Sep 2026 12:15:48 +0200 Subject: [PATCH 14/16] fix(chart): fail on empty host --- helm-chart/templates/_helpers.tpl | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/helm-chart/templates/_helpers.tpl b/helm-chart/templates/_helpers.tpl index 75822932..9976d882 100644 --- a/helm-chart/templates/_helpers.tpl +++ b/helm-chart/templates/_helpers.tpl @@ -69,7 +69,8 @@ Rendered with `tpl`, like every other host value; keep this one free of */}} {{- define "hackagon.frontendHost" -}} {{- $first := first (.Values.frontend.ingress.hosts | default list) | required "frontend.ingress.hosts must name at least one host: it is the app's public name" }} -{{- tpl $first.host . }} +{{- $host := $first.host | required "frontend.ingress.hosts[0].host is required: it is the app's public name" }} +{{- tpl $host . | required "frontend.ingress.hosts[0].host must render to a non-empty hostname" }} {{- end }} {{/* From d37a61a962f5855f147fb79f16c2deba5fda9f64 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Wed, 16 Sep 2026 15:06:39 +0200 Subject: [PATCH 15/16] doc(chart): explain frontend host --- helm-chart/values.yaml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/helm-chart/values.yaml b/helm-chart/values.yaml index fa3f49e8..a8ce1a45 100644 --- a/helm-chart/values.yaml +++ b/helm-chart/values.yaml @@ -69,8 +69,10 @@ frontend: nginx.ingress.kubernetes.io/proxy_busy_buffers_size: 32k nginx.ingress.kubernetes.io/ssl-redirect: "true" # -- Public hostname of the app. The TLS host below and the realm's login - # redirects follow the first entry. + # Redirects follow the first entry. hosts: + # You can overwrite this default to any hard-coded custom domain, + # e.g. host: "hackagon.datascience.ch". - host: "app.{{ .Values.baseDomain }}" paths: - path: / From b8ba9d09db049f2854786fbc2423908e32c580f2 Mon Sep 17 00:00:00 2001 From: cmdoret Date: Wed, 16 Sep 2026 15:10:26 +0200 Subject: [PATCH 16/16] doc(chart): mention issuer is derived --- helm-chart/values.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/helm-chart/values.yaml b/helm-chart/values.yaml index a8ce1a45..ec8728de 100644 --- a/helm-chart/values.yaml +++ b/helm-chart/values.yaml @@ -127,6 +127,7 @@ backend: # -- Where the backend fetches Keycloak's signing keys. # With an external Keycloak (keycloak.enabled: false), # override this with a url the backend pod can actually reach. + # the issuer is derived from the keycloak hostname and injected in configmaps. jwksurl: 'http://{{ include "hackagon.keycloakServiceName" . }}:8080/realms/hackagon/protocol/openid-connect/certs' algorithm: RS256 logging: