2021-11-08 21:43:52 +00:00
|
|
|
{ lib
|
2022-02-04 12:16:47 +00:00
|
|
|
, buildGoModule
|
2021-11-08 21:43:52 +00:00
|
|
|
, rustPlatform
|
|
|
|
, fetchFromGitHub
|
|
|
|
, makeWrapper
|
2022-04-25 17:30:13 +01:00
|
|
|
, symlinkJoin
|
|
|
|
, CoreFoundation
|
2022-10-11 09:55:39 +01:00
|
|
|
, AppKit
|
2022-09-19 05:02:12 +01:00
|
|
|
, libfido2
|
2022-04-25 17:30:13 +01:00
|
|
|
, openssl
|
|
|
|
, pkg-config
|
2021-11-08 21:43:52 +00:00
|
|
|
, protobuf
|
2022-04-25 17:30:13 +01:00
|
|
|
, Security
|
2021-11-08 21:43:52 +00:00
|
|
|
, stdenv
|
|
|
|
, xdg-utils
|
2022-01-08 08:29:19 +00:00
|
|
|
, nixosTests
|
2018-01-14 08:04:08 +00:00
|
|
|
|
2022-04-25 17:30:13 +01:00
|
|
|
, withRdpClient ? true
|
2021-11-08 21:43:52 +00:00
|
|
|
}:
|
|
|
|
let
|
2018-02-01 10:27:07 +00:00
|
|
|
# This repo has a private submodule "e" which fetchgit cannot handle without failing.
|
|
|
|
src = fetchFromGitHub {
|
|
|
|
owner = "gravitational";
|
|
|
|
repo = "teleport";
|
|
|
|
rev = "v${version}";
|
2022-09-07 17:10:10 +01:00
|
|
|
hash = "sha256-F5v3/eKPLhSxW7FImTbE+QMtfn8w5WVTrxMWhgNr3YA=";
|
2021-11-08 21:43:52 +00:00
|
|
|
};
|
2022-09-07 17:10:10 +01:00
|
|
|
version = "10.3.1";
|
2021-11-08 21:43:52 +00:00
|
|
|
|
2022-04-25 17:30:13 +01:00
|
|
|
rdpClient = rustPlatform.buildRustPackage rec {
|
2022-09-07 17:10:10 +01:00
|
|
|
pname = "teleport-rdpclient";
|
|
|
|
cargoHash = "sha256-Xmabjoq1NXxXemeR06Gg8R/HwdSE+rsxxX645pQ3SuI=";
|
2022-04-25 17:30:13 +01:00
|
|
|
inherit version src;
|
|
|
|
|
|
|
|
buildAndTestSubdir = "lib/srv/desktop/rdp/rdpclient";
|
|
|
|
|
|
|
|
buildInputs = [ openssl ]
|
|
|
|
++ lib.optionals stdenv.isDarwin [ CoreFoundation Security ];
|
|
|
|
nativeBuildInputs = [ pkg-config ];
|
|
|
|
|
|
|
|
# https://github.com/NixOS/nixpkgs/issues/161570 ,
|
|
|
|
# buildRustPackage sets strictDeps = true;
|
|
|
|
checkInputs = buildInputs;
|
|
|
|
|
|
|
|
OPENSSL_NO_VENDOR = "1";
|
|
|
|
|
|
|
|
postInstall = ''
|
2022-09-07 17:10:10 +01:00
|
|
|
mkdir -p $out/include
|
|
|
|
cp ${buildAndTestSubdir}/librdprs.h $out/include/
|
2021-11-08 21:43:52 +00:00
|
|
|
'';
|
2018-02-01 10:27:07 +00:00
|
|
|
};
|
|
|
|
|
2021-11-08 21:43:52 +00:00
|
|
|
webassets = fetchFromGitHub {
|
|
|
|
owner = "gravitational";
|
|
|
|
repo = "webassets";
|
2022-09-07 17:10:10 +01:00
|
|
|
# Submodule rev from https://github.com/gravitational/teleport/tree/v10.3.1
|
|
|
|
rev = "6710dcd0dc19ad101bac3259c463ef940f2ab1f3";
|
|
|
|
hash = "sha256-A13FSpgJODmhugAwy4kqiDw4Rihr//DhQX/bjwaeo2A=";
|
2021-11-08 21:43:52 +00:00
|
|
|
};
|
|
|
|
in
|
2022-02-04 12:16:47 +00:00
|
|
|
buildGoModule rec {
|
2021-11-08 21:43:52 +00:00
|
|
|
pname = "teleport";
|
|
|
|
|
|
|
|
inherit src version;
|
2022-09-07 17:10:10 +01:00
|
|
|
vendorHash = "sha256-2Zrd3CbZvxns9lNVtwaaor1mi97IhPc+MRJhj3rU760=";
|
2020-03-18 10:43:09 +00:00
|
|
|
|
2022-04-25 17:06:27 +01:00
|
|
|
subPackages = [ "tool/tbot" "tool/tctl" "tool/teleport" "tool/tsh" ];
|
2022-09-19 05:02:12 +01:00
|
|
|
tags = [ "libfido2" "webassets_embed" ]
|
2022-09-07 17:10:10 +01:00
|
|
|
++ lib.optional withRdpClient "desktop_access_rdp";
|
2020-03-18 10:43:09 +00:00
|
|
|
|
2022-09-19 05:02:12 +01:00
|
|
|
buildInputs = [ openssl libfido2 ]
|
2022-10-11 09:55:39 +01:00
|
|
|
++ lib.optionals (stdenv.isDarwin && withRdpClient) [ CoreFoundation Security AppKit ];
|
2022-09-19 05:02:12 +01:00
|
|
|
nativeBuildInputs = [ makeWrapper pkg-config ];
|
2020-03-18 10:43:09 +00:00
|
|
|
|
2021-08-04 13:00:16 +01:00
|
|
|
patches = [
|
|
|
|
# https://github.com/NixOS/nixpkgs/issues/120738
|
|
|
|
./tsh.patch
|
|
|
|
# https://github.com/NixOS/nixpkgs/issues/132652
|
|
|
|
./test.patch
|
2022-03-28 12:27:12 +01:00
|
|
|
./0001-fix-add-nix-path-to-exec-env.patch
|
2022-04-25 17:30:13 +01:00
|
|
|
./rdpclient.patch
|
2021-08-04 13:00:16 +01:00
|
|
|
];
|
2021-04-26 13:45:28 +01:00
|
|
|
|
2021-08-11 13:58:40 +01:00
|
|
|
# Reduce closure size for client machines
|
|
|
|
outputs = [ "out" "client" ];
|
|
|
|
|
2022-09-07 17:10:10 +01:00
|
|
|
preBuild = ''
|
|
|
|
mkdir -p build
|
|
|
|
echo "making webassets"
|
|
|
|
cp -r ${webassets}/* webassets/
|
|
|
|
make -j$NIX_BUILD_CORES lib/web/build/webassets
|
|
|
|
'' + lib.optionalString withRdpClient ''
|
|
|
|
ln -s ${rdpClient}/lib/* lib/
|
|
|
|
ln -s ${rdpClient}/include/* lib/srv/desktop/rdp/rdpclient/
|
|
|
|
'';
|
2018-01-14 08:04:08 +00:00
|
|
|
|
2022-04-25 17:06:27 +01:00
|
|
|
# Multiple tests fail in the build sandbox
|
|
|
|
# due to trying to spawn nixbld's shell (/noshell), etc.
|
|
|
|
doCheck = false;
|
2021-04-22 16:32:55 +01:00
|
|
|
|
2021-01-05 12:50:58 +00:00
|
|
|
postInstall = ''
|
2022-09-07 17:10:10 +01:00
|
|
|
mkdir -p $client/bin
|
|
|
|
mv {$out,$client}/bin/tsh
|
2022-07-12 00:23:52 +01:00
|
|
|
# make xdg-open overrideable at runtime
|
|
|
|
wrapProgram $client/bin/tsh --suffix PATH : ${lib.makeBinPath [ xdg-utils ]}
|
2022-09-07 17:10:10 +01:00
|
|
|
ln -s {$client,$out}/bin/tsh
|
2021-01-05 12:50:58 +00:00
|
|
|
'';
|
2018-01-14 08:04:08 +00:00
|
|
|
|
2021-02-01 14:45:17 +00:00
|
|
|
doInstallCheck = true;
|
|
|
|
|
|
|
|
installCheckPhase = ''
|
|
|
|
$out/bin/tsh version | grep ${version} > /dev/null
|
2021-01-05 12:50:58 +00:00
|
|
|
$client/bin/tsh version | grep ${version} > /dev/null
|
2022-04-25 17:06:27 +01:00
|
|
|
$out/bin/tbot version | grep ${version} > /dev/null
|
2021-02-01 14:45:17 +00:00
|
|
|
$out/bin/tctl version | grep ${version} > /dev/null
|
|
|
|
$out/bin/teleport version | grep ${version} > /dev/null
|
|
|
|
'';
|
|
|
|
|
2022-01-08 08:29:19 +00:00
|
|
|
passthru.tests = nixosTests.teleport;
|
|
|
|
|
2021-01-05 12:50:58 +00:00
|
|
|
meta = with lib; {
|
2021-11-08 21:43:52 +00:00
|
|
|
description = "Certificate authority and access plane for SSH, Kubernetes, web applications, and databases";
|
2021-04-22 16:32:55 +01:00
|
|
|
homepage = "https://goteleport.com/";
|
2021-01-05 12:50:58 +00:00
|
|
|
license = licenses.asl20;
|
|
|
|
maintainers = with maintainers; [ sigma tomberek freezeboy ];
|
|
|
|
platforms = platforms.unix;
|
2018-01-14 08:04:08 +00:00
|
|
|
};
|
|
|
|
}
|