nix: expose overlay and NixOS module for infrastructure deployment

- Fix default.nix to build from workspace (imphnen-backend/Cargo.toml)
- Add overlays.default adding pkgs.imphnen-backend
- Add nixosModules.backend via nixos-module.nix
- NixOS module defines systemd service on port 8081 with environmentFile

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
maulanasdqn
2026-04-02 13:44:23 +07:00
co-authored by Claude Sonnet 4.6
parent e432a1a743
commit 30128a8fe2
3 changed files with 111 additions and 56 deletions
+14 -13
View File
@@ -1,15 +1,16 @@
{pkgs ? import <nixpkgs> {}}: let
manifest = (pkgs.lib.importTOML ./Cargo.toml).package;
rustDeps = pkgs.callPackage ./Cargo.nix {};
packageEntry = rustDeps.workspaceMembers.${manifest.name};
deps = packageEntry.build.cargoDeps or null;
in
pkgs.rustPlatform.buildRustPackage {
pname = manifest.name;
version = manifest.version;
cargoDeps = deps;
{ pkgs ? import <nixpkgs> { } }:
pkgs.rustPlatform.buildRustPackage {
pname = "imphnen-backend";
version = (pkgs.lib.importTOML ./imphnen-backend/Cargo.toml).package.version;
src = pkgs.lib.cleanSource ./.;
cargoLock.lockFile = ./Cargo.lock;
nativeBuildInputs = [pkgs.openssl pkgs.pkg-config];
buildInputs = [pkgs.openssl];
}
cargoBuildFlags = [
"--package"
"imphnen-backend"
"--bin"
"api"
];
nativeBuildInputs = [ pkgs.pkg-config ];
buildInputs = [ pkgs.openssl ];
doCheck = false;
}
+9 -3
View File
@@ -21,9 +21,7 @@
system:
import nixpkgs {
inherit system;
config = {
allowUnfree = true;
};
config.allowUnfree = true;
};
forAllSystems = nixpkgs.lib.genAttrs supportedSystems;
in
@@ -31,9 +29,17 @@
packages = forAllSystems (system: {
default = (pkgsFor system).callPackage ./default.nix { };
});
overlays.default = final: _prev: {
imphnen-backend = final.callPackage ./default.nix { };
};
nixosModules.backend = ./nixos-module.nix;
devShells = forAllSystems (system: {
default = (pkgsFor system).callPackage ./shell.nix { };
});
dockerImages = forAllSystems (system: {
tryOutApi = (pkgsFor system).callPackage ./docker.nix { };
});
+48
View File
@@ -0,0 +1,48 @@
{ config, lib, pkgs, ... }:
let
cfg = config.services.imphnen-backend;
in
{
options.services.imphnen-backend = {
enable = lib.mkEnableOption "IMPHNEN backend service";
port = lib.mkOption {
type = lib.types.port;
default = 8081;
description = "Port the backend HTTP server listens on.";
};
environmentFile = lib.mkOption {
type = lib.types.path;
description = "Path to environment file with secrets (DATABASE_URL, JWT keys, etc).";
};
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
};
};
config = lib.mkIf cfg.enable {
systemd.services.imphnen-backend = {
description = "IMPHNEN Backend Service";
wantedBy = [ "multi-user.target" ];
after = [
"network.target"
"postgresql.service"
];
serviceConfig = {
ExecStart = "${pkgs.imphnen-backend}/bin/api";
EnvironmentFile = cfg.environmentFile;
Environment = [ "PORT=${toString cfg.port}" ];
DynamicUser = true;
Restart = "on-failure";
RestartSec = "5s";
StandardOutput = "journal";
StandardError = "journal";
};
};
networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [ cfg.port ];
};
}