refactor: rewrite flake.nix for clarity and modularity (#8137)

* refactor: rewrite flake.nix from scratch for clarity and modularity

Rewrite the Nix flake with clean separation of concerns, organized
let-bindings, and 4 purpose-specific devShells instead of a monolithic
default shell with broken package outputs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: add CLI tools to default devShell (gh, aws, playwright, mermaid, asciinema)

Add tools needed for AI agent workflows and dev tooling:
- gh (GitHub CLI)
- awscli2
- asciinema (terminal recording)
- playwright-driver with Nix-managed browsers
- mermaid-cli (diagram generation)

Playwright browsers are provided via nixpkgs' playwright-driver.browsers.
Mermaid/Puppeteer reuses the headless_shell from the same browser set.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: move wm-minio scripts to default devShell

MinIO (local S3) is needed for regular development, not just the full
profile.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: use playwright wrapper + chromium for browser tools

Replace playwright-driver (library, no CLI) with:
- A `playwright` wrapper script that calls the Nix playwright-core CLI
  (version-matched to its own Nix-provided browsers)
- pkgs.chromium for Mermaid/Puppeteer (which respects PUPPETEER_EXECUTABLE_PATH)

This fixes playwright screenshot and mermaid diagram generation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat: auto-load .env.local from main worktree in all devShells

Gitignored files like .env.local don't exist in git worktrees.
Add a shared shellHook that resolves back to the main tree via
git-common-dir and sources .env.local if present. This ensures
AWS credentials and other secrets are available in worktrees.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: replace deprecated pkgs.hostPlatform with stdenv.hostPlatform

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* chore: remove AWS CLI from flake and sandbox images

Pastebin is sufficient for screenshot sharing; AWS credentials
add unnecessary complexity.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address PR review — ruby mismatch, quoting, shell dedup

- Fix pkgs.ruby → pkgs.ruby_3_4 in extraRuntimeVars to match extraRuntimes
- Replace $* with "$@" in all helper scripts (wm, wm-build, wm-caddy,
  wm-bench, wm-cli) to correctly preserve argument boundaries
- Extract coreBuildInputs, browserVars, and playwrightWrapper as shared
  let-bindings to eliminate duplication between default and full shells

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* chore: remove .env.local auto-loading from devShells

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
centdix
2026-02-28 07:51:02 +01:00
committed by GitHub
parent 7d9d16a6a3
commit 7728475fc9
3 changed files with 381 additions and 393 deletions

View File

@@ -195,13 +195,6 @@ RUN bun add -g @playwright/test \
&& chmod -R a+rwX /usr/local/lib/bun/install \
&& rm -rf /var/lib/apt/lists/* /tmp/bunx-*
# ── AWS CLI (for S3-compatible uploads to R2) ─────────────────────────────────
RUN curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o /tmp/awscliv2.zip \
&& unzip -q /tmp/awscliv2.zip -d /tmp \
&& /tmp/aws/install \
&& rm -rf /tmp/aws /tmp/awscliv2.zip
ENV AWS_DEFAULT_REGION=auto
# ── Runtime env for arbitrary UID ─────────────────────────────────────────────
# Mutable state goes to /tmp (writable by any UID). Toolchains stay read-only.

760
flake.nix
View File

@@ -3,11 +3,11 @@
nixpkgs.url = "nixpkgs/nixos-unstable";
flake-utils.url = "github:numtide/flake-utils";
rust-overlay.url = "github:oxalica/rust-overlay";
nixpkgs-oapi-gen.url =
"nixpkgs/2d068ae5c6516b2d04562de50a58c682540de9bf"; # openapi-generator-cli pin to 7.10.0
# Pin openapi-generator-cli to 7.10.0
nixpkgs-oapi-gen.url = "nixpkgs/2d068ae5c6516b2d04562de50a58c682540de9bf";
};
outputs = { self, nixpkgs, flake-utils, rust-overlay
, nixpkgs-oapi-gen }:
outputs = { self, nixpkgs, flake-utils, rust-overlay, nixpkgs-oapi-gen }:
flake-utils.lib.eachDefaultSystem (system:
let
pkgs = import nixpkgs {
@@ -16,47 +16,180 @@
overlays = [ (import rust-overlay) ];
};
openapi-generator-cli =
(import nixpkgs-oapi-gen { inherit system; }).openapi-generator-cli;
lib = pkgs.lib;
stdenv = pkgs.stdenv;
rust = pkgs.rust-bin.stable.latest.default.override {
extensions = [
"rust-src" # for rust-analyzer
"rust-analyzer"
"rustfmt"
];
};
patchedClang = pkgs.llvmPackages_18.clang.overrideAttrs (oldAttrs: {
postFixup = ''
# Copy the original postFixup logic but skip add-hardening.sh
${oldAttrs.postFixup or ""}
# Remove the line that substitutes add-hardening.sh
sed -i 's/.*source.*add-hardening\.sh.*//' $out/bin/clang
'';
});
buildInputs = with pkgs; [
# ---------------------------------------------------------------
# Rust toolchain
# ---------------------------------------------------------------
rustStable = pkgs.rust-bin.stable.latest.default.override {
extensions = [ "rust-src" "rust-analyzer" "rustfmt" ];
};
# ---------------------------------------------------------------
# Native C/C++ dependencies (required to compile the backend)
# ---------------------------------------------------------------
nativeBuildDeps = with pkgs; [
# Crypto / TLS
openssl
openssl.dev
# XML / SAML (enterprise_saml feature)
libxml2.dev
xmlsec.dev
libxslt.dev
# FFI / codegen
libclang.dev
libffi # deno_ffi on macOS
# Networking / compression
curl.dev
zlib.dev
libffi # For deno_ffi
libtool
nodejs
postgresql
pkg-config
llvmPackages_18.clang
mold
cmake
# Auth (kafka-gssapi, mssql-kerberos)
cyrus_sasl
krb5
# Misc
libtool
postgresql
# Build tooling
pkg-config
llvmPackages_18.clang # linker — pinned to 18 to avoid SIGSEGV with mold + newer clang
mold
cmake # required by rdkafka cmake-build
];
# ---------------------------------------------------------------
# Prebuilt V8 binary (must match version in Cargo.toml)
# ---------------------------------------------------------------
rustyV8Archive = let
version = "130.0.7";
target = stdenv.hostPlatform.rust.rustcTarget;
sha256 = {
x86_64-linux = "sha256-pkdsuU6bAkcIHEZUJOt5PXdzK424CEgTLXjLtQ80t10=";
aarch64-linux = lib.fakeHash;
x86_64-darwin = lib.fakeHash;
aarch64-darwin = lib.fakeHash;
}.${system};
in pkgs.fetchurl {
name = "librusty_v8-${version}";
url = "https://github.com/denoland/rusty_v8/releases/download/v${version}/librusty_v8_release_${target}.a.gz";
inherit sha256;
};
# ---------------------------------------------------------------
# pkg-config search path for native libraries
# ---------------------------------------------------------------
pkgConfigPath = lib.makeSearchPath "lib/pkgconfig"
(with pkgs; [ openssl.dev libxml2.dev xmlsec.dev libxslt.dev cyrus_sasl.dev krb5.dev ]);
# ---------------------------------------------------------------
# RPATH — embed Nix store library paths into compiled binaries
# ---------------------------------------------------------------
rpathLibs = lib.makeLibraryPath (with pkgs; [
openssl libffi cyrus_sasl krb5 libxml2 xmlsec libxslt stdenv.cc.cc.lib
]);
# ---------------------------------------------------------------
# Bindgen configuration
# Bindgen uses libclang directly (not $CC), so we must explicitly
# provide all Nix header search paths.
# See: https://web.archive.org/web/20220523141208/https://hoverbear.org/blog/rust-bindgen-in-nix/
# ---------------------------------------------------------------
bindgenClangArgs = builtins.concatStringsSep " " ([
"-nostdinc"
(builtins.readFile "${stdenv.cc}/nix-support/libc-crt1-cflags")
(builtins.readFile "${stdenv.cc}/nix-support/libc-cflags")
(builtins.readFile "${stdenv.cc}/nix-support/cc-cflags")
(builtins.readFile "${stdenv.cc}/nix-support/libcxx-cxxflags")
"-idirafter ${pkgs.libiconv}/include"
] ++ lib.optionals stdenv.cc.isClang [
"-idirafter ${stdenv.cc.cc}/lib/clang/${lib.getVersion stdenv.cc.cc}/include"
] ++ lib.optionals stdenv.cc.isGNU [
"-isystem ${stdenv.cc.cc}/include/c++/${lib.getVersion stdenv.cc.cc}"
"-isystem ${stdenv.cc.cc}/include/c++/${lib.getVersion stdenv.cc.cc}/${stdenv.hostPlatform.config}"
"-idirafter ${stdenv.cc.cc}/lib/gcc/${stdenv.hostPlatform.config}/${lib.getVersion stdenv.cc.cc}/include"
]);
# ---------------------------------------------------------------
# Build environment variables (shared by all shells that compile Rust)
# ---------------------------------------------------------------
buildEnvVars = {
PKG_CONFIG_PATH = pkgConfigPath;
RUSTY_V8_ARCHIVE = rustyV8Archive;
LIBCLANG_PATH = "${pkgs.llvmPackages.libclang.lib}/lib";
BINDGEN_EXTRA_CLANG_ARGS = bindgenClangArgs;
# Force clang 18 as cargo linker (stdenv may bring a newer clang that causes SIGSEGV with mold)
CARGO_TARGET_X86_64_UNKNOWN_LINUX_GNU_LINKER = "${pkgs.llvmPackages_18.clang}/bin/clang";
CARGO_TARGET_AARCH64_UNKNOWN_LINUX_GNU_LINKER = "${pkgs.llvmPackages_18.clang}/bin/clang";
# Embed rpath so binaries find Nix store .so files at runtime
CARGO_TARGET_X86_64_UNKNOWN_LINUX_GNU_RUSTFLAGS = "-C link-arg=-fuse-ld=mold -C link-arg=-Wl,-rpath,${rpathLibs}";
CARGO_TARGET_AARCH64_UNKNOWN_LINUX_GNU_RUSTFLAGS = "-C link-arg=-fuse-ld=mold -C link-arg=-Wl,-rpath,${rpathLibs}";
CARGO_HOST_RUSTFLAGS = "-C link-arg=-Wl,-rpath,${rpathLibs}";
# https://github.com/NixOS/nixpkgs/issues/370494 — jemalloc build fix
CFLAGS = "-Wno-error=int-conversion";
LD_LIBRARY_PATH = lib.makeLibraryPath [ pkgs.zlib ];
};
# ---------------------------------------------------------------
# OpenAPI generator (pinned)
# ---------------------------------------------------------------
openapi-generator-cli =
(import nixpkgs-oapi-gen { inherit system; }).openapi-generator-cli;
# ---------------------------------------------------------------
# Common worker runtimes (languages the worker executes)
# ---------------------------------------------------------------
commonRuntimes = with pkgs; [
deno
python3
python3Packages.pip
uv
go
bun
nushell
typescript
flock
];
# ---------------------------------------------------------------
# Runtime PATH env vars — tells the worker where to find interpreters
# ---------------------------------------------------------------
commonRuntimeVars = {
DENO_PATH = "${pkgs.deno}/bin/deno";
GO_PATH = "${pkgs.go}/bin/go";
BUN_PATH = "${pkgs.bun}/bin/bun";
NODE_PATH = "${pkgs.nodejs}/bin/node";
NODE_BIN_PATH = "${pkgs.nodejs}/bin/node";
UV_PATH = "${pkgs.uv}/bin/uv";
NU_PATH = "${pkgs.nushell}/bin/nu";
FLOCK_PATH = "${pkgs.flock}/bin/flock";
CARGO_PATH = "${rustStable}/bin/cargo";
BASH_PATH = "bash";
GIT_PATH = "${pkgs.git}/bin/git";
};
# ---------------------------------------------------------------
# Extra language runtimes (full shell only)
# ---------------------------------------------------------------
coursier = pkgs.fetchFromGitHub {
owner = "coursier";
repo = "launchers";
@@ -64,67 +197,245 @@
hash = "sha256-8E0WtDFc7RcqmftDigMyy1xXUkjgL4X4kpf7h1GdE48=";
};
PKG_CONFIG_PATH = pkgs.lib.makeSearchPath "lib/pkgconfig"
(with pkgs; [ openssl.dev libxml2.dev xmlsec.dev libxslt.dev cyrus_sasl.dev krb5.dev ]);
RUSTY_V8_ARCHIVE = let
# NOTE: needs to be same as in Cargo.toml
version = "130.0.7";
target = pkgs.hostPlatform.rust.rustcTarget;
sha256 = {
x86_64-linux =
"sha256-pkdsuU6bAkcIHEZUJOt5PXdzK424CEgTLXjLtQ80t10=";
aarch64-linux = pkgs.lib.fakeHash;
x86_64-darwin = pkgs.lib.fakeHash;
aarch64-darwin = pkgs.lib.fakeHash;
}.${system};
in pkgs.fetchurl {
name = "librusty_v8-${version}";
url =
"https://github.com/denoland/rusty_v8/releases/download/v${version}/librusty_v8_release_${target}.a.gz";
inherit sha256;
extraRuntimes = with pkgs; [
dotnet-sdk_9
php
php84Packages.composer
ruby_3_4
jdk21
ansible
oracle-instantclient
];
extraRuntimeVars = {
JAVA_PATH = "${pkgs.jdk21}/bin/java";
JAVAC_PATH = "${pkgs.jdk21}/bin/javac";
COURSIER_PATH = "${coursier}/coursier";
DOTNET_PATH = "${pkgs.dotnet-sdk_9}/bin/dotnet";
DOTNET_ROOT = "${pkgs.dotnet-sdk_9}/share/dotnet";
PHP_PATH = "${pkgs.php}/bin/php";
COMPOSER_PATH = "${pkgs.php84Packages.composer}/bin/composer";
RUBY_PATH = "${pkgs.ruby_3_4}/bin/ruby";
RUBY_BUNDLE_PATH = "${pkgs.ruby_3_4}/bin/bundle";
RUBY_GEM_PATH = "${pkgs.ruby_3_4}/bin/gem";
ORACLE_LIB_DIR = "${pkgs.oracle-instantclient.lib}/lib";
ANSIBLE_PLAYBOOK_PATH = "${pkgs.ansible}/bin/ansible-playbook";
ANSIBLE_GALAXY_PATH = "${pkgs.ansible}/bin/ansible-galaxy";
CARGO_SWEEP_PATH = "${pkgs.cargo-sweep}/bin/cargo-sweep";
};
# ---------------------------------------------------------------
# General dev environment variables
# ---------------------------------------------------------------
devEnvVars = {
DATABASE_URL = "postgres://postgres:changeme@127.0.0.1:5432/windmill?sslmode=disable";
REMOTE = "http://127.0.0.1:8000";
REMOTE_LSP = "http://127.0.0.1:3001";
NODE_ENV = "development";
NODE_OPTIONS = "--max-old-space-size=16384";
};
# ---------------------------------------------------------------
# Helper scripts — base set (default + full)
# ---------------------------------------------------------------
helperScriptsBase = [
(pkgs.writeScriptBin "wm" ''
cd ./frontend
npm install
npm run ${if stdenv.isDarwin then "generate-backend-client-mac" else "generate-backend-client"}
npm run dev "$@"
'')
(pkgs.writeScriptBin "wm-build" ''
cd ./frontend
npm install
npm run ${if stdenv.isDarwin then "generate-backend-client-mac" else "generate-backend-client"}
npm run build "$@"
'')
(pkgs.writeScriptBin "wm-migrate" ''
cd ./backend
sqlx migrate run
'')
(pkgs.writeScriptBin "wm-reset" ''
sqlx database drop -f
sqlx database create
wm-migrate
'')
(pkgs.writeScriptBin "wm-minio" ''
set -e
cd ./backend
mkdir -p .minio-data/wmill
${pkgs.minio}/bin/minio server ./.minio-data --console-address ":9001"
'')
(pkgs.writeScriptBin "wm-minio-keys" ''
set -e
cd ./backend
${pkgs.minio-client}/bin/mc alias set 'wmill-minio-dev' 'http://localhost:9000' 'minioadmin' 'minioadmin'
if [[ -f .minio-data/secrets.txt ]] && [[ -s .minio-data/secrets.txt ]]; then
echo "Access keys already exist:"
cat .minio-data/secrets.txt
echo ""
echo "Keys loaded from: ./backend/.minio-data/secrets.txt"
else
echo "Creating new access keys..."
mkdir -p .minio-data
${pkgs.minio-client}/bin/mc admin accesskey create 'wmill-minio-dev' | tee .minio-data/secrets.txt
echo ""
echo 'New keys saved to: ./backend/.minio-data/secrets.txt'
fi
echo "bucket: wmill"
echo "endpoint: http://localhost:9000"
'')
];
# ---------------------------------------------------------------
# Helper scripts — extra (full shell only)
# ---------------------------------------------------------------
helperScriptsFull = [
(pkgs.writeScriptBin "wm-caddy" ''
cd ./frontend
xcaddy build "$@" \
--with github.com/mholt/caddy-l4@145ec36251a44286f05a10d231d8bfb3a8192e09 \
--with github.com/RussellLuo/caddy-ext/layer4@ab1e18cfe426012af351a68463937ae2e934a2a1
'')
(pkgs.writeScriptBin "wm-setup" ''
sqlx database create
wm-build
wm-caddy
wm-migrate
'')
(pkgs.writeScriptBin "wm-bench" ''
deno run -A benchmarks/main.ts -e admin@windmill.dev -p changeme "$@"
'')
];
# ---------------------------------------------------------------
# Shared inputs and settings for default + full shells
# ---------------------------------------------------------------
coreBuildInputs = nativeBuildDeps ++ commonRuntimes ++ [
rustStable
openapi-generator-cli
] ++ (with pkgs; [
nodejs
git
sqlx-cli
cargo-watch
jq
gnused
# CLI tools (for AI agents and dev workflow)
gh
asciinema
mermaid-cli
]);
# Playwright: use Nix-provided browsers (version-matched to playwright-driver)
# Mermaid/Puppeteer: point at Nix chromium (Puppeteer respects this env var)
browserVars = {
PLAYWRIGHT_BROWSERS_PATH = "${pkgs.playwright-driver.browsers}";
PUPPETEER_EXECUTABLE_PATH = "${pkgs.chromium}/bin/chromium";
PUPPETEER_SKIP_DOWNLOAD = "true";
};
# Wrapper for the Nix-provided playwright CLI (version-matched to its browsers)
playwrightWrapper = pkgs.writeShellScriptBin "playwright" ''
exec ${pkgs.nodejs}/bin/node ${pkgs.playwright-driver}/cli.js "$@"
'';
in {
# Enter by `nix develop .#wasm`
devShells."wasm" = pkgs.mkShell {
# Explicitly set paths for headers and linker
shellHook = ''
export CC=${patchedClang}/bin/clang
'';
buildInputs = buildInputs ++ (with pkgs; [
# =============================================================
# default — daily driver for backend + frontend development
# Usage: nix develop
# =============================================================
devShells.default = pkgs.mkShell (buildEnvVars // commonRuntimeVars // devEnvVars // browserVars // {
buildInputs = coreBuildInputs;
packages = helperScriptsBase ++ [ playwrightWrapper ];
});
# =============================================================
# full — all language runtimes, k8s tooling, specialized scripts
# Usage: nix develop .#full
# =============================================================
devShells.full = pkgs.mkShell (buildEnvVars // commonRuntimeVars // extraRuntimeVars // devEnvVars // browserVars // {
buildInputs = coreBuildInputs ++ extraRuntimes ++ (with pkgs; [
# Python extras
poetry
pyright
openapi-python-client
# LSP / editor
svelte-language-server
taplo
# Extra dev tools
cargo-sweep
# Kubernetes
minikube
kubectl
kubernetes-helm
conntrack-tools
cri-tools
# Extra
xcaddy
nsjail
]);
packages = helperScriptsBase ++ helperScriptsFull ++ [ playwrightWrapper ];
});
# =============================================================
# wasm — WASM target compilation (nightly Rust)
# Usage: nix develop .#wasm
# =============================================================
devShells.wasm = pkgs.mkShell (buildEnvVars // {
hardeningDisable = [ "all" ];
buildInputs = nativeBuildDeps ++ (with pkgs; [
(rust-bin.nightly.latest.default.override {
extensions = [
"rust-src" # for rust-analyzer
"rust-analyzer"
];
targets =
[ "wasm32-unknown-unknown" "wasm32-unknown-emscripten" ];
extensions = [ "rust-src" "rust-analyzer" ];
targets = [ "wasm32-unknown-unknown" "wasm32-unknown-emscripten" ];
})
wasm-pack
deno
emscripten
nushell
# Needed for extra dependencies
glibc_multi
]);
};
devShells."cli" = pkgs.mkShell {
});
# =============================================================
# cli — lightweight Bun-based CLI development
# Usage: nix develop .#cli
# =============================================================
devShells.cli = pkgs.mkShell {
shellHook = ''
if command -v git >/dev/null 2>&1 && git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
export FLAKE_ROOT="$(git rev-parse --show-toplevel)"
else
# Fallback to PWD if not in a git repository
export FLAKE_ROOT="$PWD"
fi
wm-cli-deps
'';
buildInputs = buildInputs ++ [ pkgs.deno ];
buildInputs = with pkgs; [ bun nodejs git ];
packages = [
(pkgs.writeScriptBin "wm-cli" ''
deno run -A --no-check $FLAKE_ROOT/cli/src/main.ts $*
bun run $FLAKE_ROOT/cli/src/main.ts "$@"
'')
(pkgs.writeScriptBin "wm-cli-deps" ''
pushd $FLAKE_ROOT/cli/
${if pkgs.stdenv.isDarwin then
${if stdenv.isDarwin then
"./gen_wm_client_mac.sh && ./windmill-utils-internal/gen_wm_client_mac.sh"
else
"./gen_wm_client.sh && ./windmill-utils-internal/gen_wm_client.sh"}
@@ -132,314 +443,5 @@
'')
];
};
devShells.default = pkgs.mkShell {
buildInputs = buildInputs ++ [
# To update run: `nix flake update nixpkgs-oapi-gen`
openapi-generator-cli
] ++ (with pkgs; [
# Essentials
rust
git
sqlx-cli
# Build/helper scripts
jq
gnused # other implementations are inconsistent on osx
# Python
flock
python3
python3Packages.pip
uv
poetry
pyright
openapi-python-client
# Other languages
deno
typescript
nushell
go
bun
dotnet-sdk_9
oracle-instantclient
ansible
ruby_3_4
cargo-sweep # We use it for rust
# LSP/Local dev
svelte-language-server
taplo
# Orchestration/Kubernetes
minikube
kubectl
kubernetes-helm
conntrack-tools # To run minikube without driver (--driver=none)
cri-tools
# Extra
xcaddy
cargo-watch
nsjail
sccache
]);
packages = [
(pkgs.writeScriptBin "wm-caddy" ''
cd ./frontend
xcaddy build $* \
--with github.com/mholt/caddy-l4@145ec36251a44286f05a10d231d8bfb3a8192e09 \
--with github.com/RussellLuo/caddy-ext/layer4@ab1e18cfe426012af351a68463937ae2e934a2a1
'')
(pkgs.writeScriptBin "wm-build" ''
cd ./frontend
npm install
npm run ${
if pkgs.stdenv.isDarwin then
"generate-backend-client-mac"
else
"generate-backend-client"
}
npm run build $*
'')
(pkgs.writeScriptBin "wm-migrate" ''
cd ./backend
sqlx migrate run
'')
(pkgs.writeScriptBin "wm-setup" ''
sqlx database create
wm-build
wm-caddy
wm-migrate
'')
(pkgs.writeScriptBin "wm-reset" ''
sqlx database drop -f
sqlx database create
wm-migrate
'')
(pkgs.writeScriptBin "wm-bench" ''
deno run -A benchmarks/main.ts -e admin@windmill.dev -p changeme $*
'')
(pkgs.writeScriptBin "wm" ''
cd ./frontend
npm install
npm run generate-backend-client
npm run dev $*
'')
(pkgs.writeScriptBin "wm-minio" ''
set -e
cd ./backend
mkdir -p .minio-data/wmill
${pkgs.minio}/bin/minio server ./.minio-data --console-address ":9001"
'')
# Generate keys
# TODO: Do not set new keys if ran multiple times
(pkgs.writeScriptBin "wm-minio-keys" ''
set -e
cd ./backend
# Set up MinIO alias
${pkgs.minio-client}/bin/mc alias set 'wmill-minio-dev' 'http://localhost:9000' 'minioadmin' 'minioadmin'
# Check if secrets file exists and contains valid keys
if [[ -f .minio-data/secrets.txt ]] && [[ -s .minio-data/secrets.txt ]]; then
echo "Access keys already exist:"
cat .minio-data/secrets.txt
echo ""
echo "Keys loaded from: ./backend/.minio-data/secrets.txt"
else
echo "Creating new access keys..."
mkdir -p .minio-data
${pkgs.minio-client}/bin/mc admin accesskey create 'wmill-minio-dev' | tee .minio-data/secrets.txt
echo ""
echo 'New keys saved to: ./backend/.minio-data/secrets.txt'
fi
echo "bucket: wmill"
echo "endpoint: http://localhost:9000"
'')
];
inherit PKG_CONFIG_PATH RUSTY_V8_ARCHIVE;
GIT_PATH = "${pkgs.git}/bin/git";
NODE_ENV = "development";
NODE_OPTIONS = "--max-old-space-size=16384";
# DATABASE_URL = "postgres://postgres:changeme@127.0.0.1:5432/";
DATABASE_URL =
"postgres://postgres:changeme@127.0.0.1:5432/windmill?sslmode=disable";
REMOTE = "http://127.0.0.1:8000";
REMOTE_LSP = "http://127.0.0.1:3001";
# RUSTC_WRAPPER = "${pkgs.sccache}/bin/sccache";
DENO_PATH = "${pkgs.deno}/bin/deno";
GO_PATH = "${pkgs.go}/bin/go";
PHP_PATH = "${pkgs.php}/bin/php";
COMPOSER_PATH = "${pkgs.php84Packages.composer}/bin/composer";
BUN_PATH = "${pkgs.bun}/bin/bun";
NODE_PATH = "${pkgs.nodejs}/bin/node";
NODE_BIN_PATH = "${pkgs.nodejs}/bin/node";
UV_PATH = "${pkgs.uv}/bin/uv";
NU_PATH = "${pkgs.nushell}/bin/nu";
JAVA_PATH = "${pkgs.jdk21}/bin/java";
JAVAC_PATH = "${pkgs.jdk21}/bin/javac";
COURSIER_PATH = "${coursier}/coursier";
BASH_PATH = "bash";
RUBY_PATH = "${pkgs.ruby}/bin/ruby";
RUBY_BUNDLE_PATH = "${pkgs.ruby}/bin/bundle";
RUBY_GEM_PATH = "${pkgs.ruby}/bin/gem";
# for related places search: ADD_NEW_LANG
FLOCK_PATH = "${pkgs.flock}/bin/flock";
CARGO_PATH = "${rust}/bin/cargo";
CARGO_SWEEP_PATH = "${pkgs.cargo-sweep}/bin/cargo-sweep";
DOTNET_PATH = "${pkgs.dotnet-sdk_9}/bin/dotnet";
DOTNET_ROOT = "${pkgs.dotnet-sdk_9}/share/dotnet";
ORACLE_LIB_DIR = "${pkgs.oracle-instantclient.lib}/lib";
ANSIBLE_PLAYBOOK_PATH = "${pkgs.ansible}/bin/ansible-playbook";
ANSIBLE_GALAXY_PATH = "${pkgs.ansible}/bin/ansible-galaxy";
# RUST_LOG = "debug";
# RUST_LOG = "kube=debug";
# Override cargo linker to use clang 18 (stdenv brings clang 21 which causes SIGSEGV with mold)
CARGO_TARGET_X86_64_UNKNOWN_LINUX_GNU_LINKER = "${pkgs.llvmPackages_18.clang}/bin/clang";
CARGO_TARGET_AARCH64_UNKNOWN_LINUX_GNU_LINKER = "${pkgs.llvmPackages_18.clang}/bin/clang";
CARGO_TARGET_X86_64_UNKNOWN_LINUX_GNU_RUSTFLAGS = "-C link-arg=-fuse-ld=mold -C link-arg=-Wl,-rpath,${pkgs.lib.makeLibraryPath [ pkgs.openssl pkgs.libffi pkgs.cyrus_sasl pkgs.krb5 pkgs.libxml2 pkgs.xmlsec pkgs.libxslt stdenv.cc.cc.lib ]}";
CARGO_TARGET_AARCH64_UNKNOWN_LINUX_GNU_RUSTFLAGS = "-C link-arg=-fuse-ld=mold -C link-arg=-Wl,-rpath,${pkgs.lib.makeLibraryPath [ pkgs.openssl pkgs.libffi pkgs.cyrus_sasl pkgs.krb5 pkgs.libxml2 pkgs.xmlsec pkgs.libxslt stdenv.cc.cc.lib ]}";
# rpath for build scripts and proc macros (host compilation)
CARGO_HOST_RUSTFLAGS = "-C link-arg=-Wl,-rpath,${pkgs.lib.makeLibraryPath [ pkgs.openssl pkgs.libffi pkgs.cyrus_sasl pkgs.krb5 pkgs.libxml2 pkgs.xmlsec pkgs.libxslt stdenv.cc.cc.lib ]}";
# See this issue: https://github.com/NixOS/nixpkgs/issues/370494
# Allows to build jemalloc on nixos
CFLAGS = "-Wno-error=int-conversion";
# Need to tell bindgen where to find libclang
LIBCLANG_PATH = "${pkgs.llvmPackages.libclang.lib}/lib";
# LD_LIBRARY_PATH set in shellHook with a wrapper to avoid leaking into git/ssh
# LD_LIBRARY_PATH = "${pkgs.gcc.lib}/lib";
LD_LIBRARY_PATH = pkgs.lib.makeLibraryPath [
pkgs.zlib
];
# Set C flags for Rust's bindgen program. Unlike ordinary C
# compilation, bindgen does not invoke $CC directly. Instead it
# uses LLVM's libclang. To make sure all necessary flags are
# included we need to look in a few places.
# See https://web.archive.org/web/20220523141208/https://hoverbear.org/blog/rust-bindgen-in-nix/
BINDGEN_EXTRA_CLANG_ARGS =
# Prevent clang from using system headers - only use Nix headers
"-nostdinc ${
builtins.readFile "${stdenv.cc}/nix-support/libc-crt1-cflags"
} ${builtins.readFile "${stdenv.cc}/nix-support/libc-cflags"} ${
builtins.readFile "${stdenv.cc}/nix-support/cc-cflags"
} ${
builtins.readFile "${stdenv.cc}/nix-support/libcxx-cxxflags"
} -idirafter ${pkgs.libiconv}/include ${
lib.optionalString stdenv.cc.isClang
"-idirafter ${stdenv.cc.cc}/lib/clang/${
lib.getVersion stdenv.cc.cc
}/include"
}${
lib.optionalString stdenv.cc.isGNU
"-isystem ${stdenv.cc.cc}/include/c++/${
lib.getVersion stdenv.cc.cc
} -isystem ${stdenv.cc.cc}/include/c++/${
lib.getVersion stdenv.cc.cc
}/${stdenv.hostPlatform.config} -idirafter ${stdenv.cc.cc}/lib/gcc/${stdenv.hostPlatform.config}/${
lib.getVersion stdenv.cc.cc
}/include"
}";
};
packages.default = self.packages.${system}.windmill;
packages.windmill-client = pkgs.buildNpmPackage {
name = "windmill-client";
version = (pkgs.lib.strings.trim (builtins.readFile ./version.txt));
src = pkgs.nix-gitignore.gitignoreSource [ ] ./frontend;
nativeBuildInputs = with pkgs; [ pkg-config ];
buildInputs = with pkgs; [ nodejs pixman cairo pango ];
doCheck = false;
npmDepsHash = "sha256-NXk9mnf74+/k0i3goqU8Zi/jr5b/bmW+HWRLJCI2CX8=";
npmBuild = "npm run build";
postUnpack = ''
mkdir -p ./backend/windmill-api/
cp ${
./backend/windmill-api/openapi.yaml
} ./backend/windmill-api/openapi.yaml
cp ${./openflow.openapi.yaml} ./openflow.openapi.yaml
'';
preBuild = ''
npm run ${
if pkgs.stdenv.isDarwin then
"generate-backend-client-mac"
else
"generate-backend-client"
}
'';
installPhase = ''
mkdir -p $out/build
cp -r build $out
'';
NODE_OPTIONS = "--max-old-space-size=8192";
};
packages.windmill = pkgs.rustPlatform.buildRustPackage {
pname = "windmill";
version = (pkgs.lib.strings.trim (builtins.readFile ./version.txt));
src = ./backend;
nativeBuildInputs = buildInputs
++ [ self.packages.${system}.windmill-client pkgs.perl ]
++ pkgs.lib.optionals pkgs.stdenv.isDarwin [
# Additional darwin specific inputs can be set here
pkgs.libiconv
pkgs.darwin.apple_sdk.frameworks.SystemConfiguration
];
cargoLock = {
lockFile = ./backend/Cargo.lock;
outputHashes = {
"php-parser-rs-0.1.3" =
"sha256-ZeI3KgUPmtjlRfq6eAYveqt8Ay35gwj6B9iOQRjQa9A=";
"progenitor-0.3.0" =
"sha256-F6XRZFVIN6/HfcM8yI/PyNke45FL7jbcznIiqj22eIQ=";
"tinyvector-0.1.0" =
"sha256-NYGhofU4rh+2IAM+zwe04YQdXY8Aa4gTmn2V2HtzRfI=";
};
};
buildFeatures = [
"enterprise"
"enterprise_saml"
"stripe"
"embedding"
"parquet"
"prometheus"
"openidconnect"
"cloud"
"jemalloc"
"tantivy"
"license"
"http_trigger"
"zip"
"oauth2"
"kafka"
"otel"
"dind"
"websocket"
"smtp"
"static_frontend"
"all_languages"
];
doCheck = false;
inherit PKG_CONFIG_PATH RUSTY_V8_ARCHIVE;
SQLX_OFFLINE = true;
FRONTEND_BUILD_DIR =
"${self.packages.${system}.windmill-client}/build";
};
});
}

View File

@@ -42,13 +42,6 @@ RUN bun add -g @playwright/test \
&& bunx playwright install chromium --with-deps \
&& rm -rf /var/lib/apt/lists/* /tmp/bunx-*
# ── AWS CLI ───────────────────────────────────────────────────────────────────
RUN curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o /tmp/awscliv2.zip \
&& unzip -q /tmp/awscliv2.zip -d /tmp \
&& /tmp/aws/install \
&& rm -rf /tmp/aws /tmp/awscliv2.zip
ENV AWS_DEFAULT_REGION=auto
# ── Claude Code ───────────────────────────────────────────────────────────────
RUN curl -fsSL https://claude.ai/install.sh | bash
ENV PATH="/root/.local/bin:$PATH"