postjevsql.git / flake.nix
1{
2  # The toolchain is mise's (mise.toml); anyone can use it without nix. This
3  # flake packages the extension and the sidecar, and its devShell only wraps
4  # mise. buck2 owns the target graph.
5  description = "postjevsql: a Rust Postgres extension for TypeSafe's Jev";
6
7  inputs = {
8    nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
9    # The estate package set (buck2, see below); nixpkgs follows ours.
10    nix-pkgs.url = "git+ssh://git@github.com/deizel/nix-pkgs";
11    nix-pkgs.inputs.nixpkgs.follows = "nixpkgs";
12    # third-party/jevcrates is a git submodule; without this the flake's
13    # source omits it and the sandbox build cannot find the jev crates.
14    self.submodules = true;
15  };
16
17  outputs =
18    {
19      self,
20      nixpkgs,
21      nix-pkgs,
22    }:
23    let
24      system = "x86_64-linux";
25      pkgs = nixpkgs.legacyPackages.${system};
26      inherit (nixpkgs) lib;
27      # The supported majors (PG_MAJORS in build/defs.bzl).
28      majors = import ./nix/majors.nix { inherit lib; };
29      # buck2 2026-08-22 drops its own gRPC connections under bursts of
30      # tiny messages (h2's small-DATA-frame budget; tests/CLAUDE.md):
31      # the forkserver exits and every later local action fails. Fixed in
32      # facebook/buck2 1cc3e05f85, first released in 2026-09-15. nix-pkgs
33      # carries that release for the whole estate, and its package throws
34      # once nixpkgs catches up (header there has the full account).
35      buck2 = nix-pkgs.packages.${system}.buck2;
36    in
37    {
38      # The extension per supported major (contract §3, nix/package.nix),
39      # as nixpkgs names its sets: postgresqlNNPackages.postjevsql.
40      legacyPackages.${system} = lib.listToAttrs (
41        map (major: {
42          name = "postgresql${major}Packages";
43          value.postjevsql = pkgs."postgresql_${major}".pkgs.callPackage ./nix/package.nix { inherit buck2; };
44        }) majors.all
45      );
46      packages.${system} = {
47        default = self.legacyPackages.${system}."postgresql${majors.default}Packages".postjevsql;
48        # The sidecar CLI (nix/sidecar-cli.nix), the one engine behind
49        # every sidecar launcher.
50        postjevsql-sidecar = pkgs.callPackage ./nix/sidecar-cli.nix {
51          postjevsql = self.packages.${system}.default;
52        };
53        # The sidecar as a `docker load`-able image (nix/sidecar-image.nix).
54        postjevsql-sidecar-image = pkgs.callPackage ./nix/sidecar-image.nix {
55          extension = ps: ps.callPackage ./nix/package.nix { inherit buck2; };
56          cli = self.packages.${system}.postjevsql-sidecar;
57        };
58      };
59
60      # Sidecar mode (CLAUDE.md *Deployment*); nix/sidecar.nix. The
61      # flake's module builds the extension with the pinned buck2.
62      nixosModules.sidecar =
63        { lib, ... }:
64        {
65          imports = [ ./nix/sidecar.nix ];
66          services.postjevsql-sidecar.extension = lib.mkDefault (
67            ps: ps.callPackage ./nix/package.nix { inherit buck2; }
68          );
69        };
70
71      # The module booted against a loopback target (nix/sidecar-test.nix).
72      checks.${system} = {
73        sidecar = import ./nix/sidecar-test.nix {
74          inherit pkgs;
75          sidecar = self.nixosModules.sidecar;
76        };
77        # The image booted in docker against the same target (nix/sidecar-image-test.nix).
78        sidecar-image = import ./nix/sidecar-image-test.nix {
79          inherit pkgs;
80          image = self.packages.${system}.postjevsql-sidecar-image;
81        };
82      };
83
84      devShells.${system} = {
85        # The toolchain is mise's, written in mise.toml (rustc, buck2, python, a server of every Postgres
86        # major, clang, libclang, hk, fnox); anyone can use it without nix: see README.md. This shell only
87        # wraps it: mise itself, git, curl and the certificates. Entering it puts what `mise install` has
88        # already installed on PATH (it installs nothing itself: the first install is large).
89        # Downloaded programs are ordinary dynamically linked binaries: NixOS with nix-ld runs them as
90        # they are; elsewhere use `nix develop .#fhs`.
91        default = pkgs.mkShell {
92          packages = [
93            pkgs.mise
94            pkgs.git
95            pkgs.curl
96            pkgs.cacert
97          ];
98          shellHook = ''
99            root="$(git rev-parse --show-toplevel 2>/dev/null || pwd)"
100            if [ -f "$root/mise.toml" ]; then
101              export MISE_TRUSTED_CONFIG_PATHS="$root''${MISE_TRUSTED_CONFIG_PATHS:+:$MISE_TRUSTED_CONFIG_PATHS}"
102              eval "$(mise env -s bash 2>/dev/null)" || true
103            fi
104          '';
105        };
106
107        # The same, inside an FHS root (bubblewrap), for a machine without nix-ld.
108        fhs =
109          (pkgs.buildFHSEnv {
110            name = "postjevsql-fhs";
111            targetPkgs = p: [
112              p.mise
113              p.git
114              p.curl
115              p.cacert
116              p.zlib
117              p.stdenv.cc.cc.lib
118            ];
119            runScript = "bash";
120          }).env;
121      };
122    };
123}