Commit | Line | Data |
---|---|---|
a7cf4eb6 ML |
1 | ;;; GNU Guix --- Functional package management for GNU |
2 | ;;; Copyright © 2016 Mathieu Lirzin <mthl@gnu.org> | |
6a7c4636 | 3 | ;;; Copyright © 2016, 2017, 2018, 2019, 2020 Ludovic Courtès <ludo@gnu.org> |
189e62fa | 4 | ;;; Copyright © 2017, 2020 Mathieu Othacehe <m.othacehe@gmail.com> |
326f6ef1 | 5 | ;;; Copyright © 2017 Jan Nieuwenhuizen <janneke@gnu.org> |
3e7a62e2 | 6 | ;;; Copyright © 2018, 2019 Ricardo Wurmus <rekado@elephly.net> |
cd62e5d3 | 7 | ;;; Copyright © 2018 Clément Lassieur <clement@lassieur.org> |
a7cf4eb6 ML |
8 | ;;; |
9 | ;;; This file is part of GNU Guix. | |
10 | ;;; | |
6a18183f | 11 | ;;; GNU Guix is free software; you can redistribute it and/or modify |
a7cf4eb6 ML |
12 | ;;; it under the terms of the GNU General Public License as published by |
13 | ;;; the Free Software Foundation, either version 3 of the License, or | |
14 | ;;; (at your option) any later version. | |
15 | ;;; | |
16 | ;;; GNU Guix is distributed in the hope that it will be useful, | |
17 | ;;; but WITHOUT ANY WARRANTY; without even the implied warranty of | |
18 | ;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
19 | ;;; GNU General Public License for more details. | |
20 | ;;; | |
21 | ;;; You should have received a copy of the GNU General Public License | |
22 | ;;; along with GNU Guix. If not, see <http://www.gnu.org/licenses/>. | |
23 | ||
24 | (define-module (gnu services cuirass) | |
e9bf5110 | 25 | #:use-module (guix channels) |
a7cf4eb6 ML |
26 | #:use-module (guix gexp) |
27 | #:use-module (guix records) | |
8d8bbe7c | 28 | #:use-module (guix utils) |
a7cf4eb6 | 29 | #:use-module (gnu packages admin) |
6a7c4636 | 30 | #:use-module (gnu packages ci) |
e9bf5110 | 31 | #:use-module (gnu packages databases) |
6a7c4636 | 32 | #:use-module (gnu packages version-control) |
a7cf4eb6 ML |
33 | #:use-module (gnu services) |
34 | #:use-module (gnu services base) | |
0f01493d | 35 | #:use-module (gnu services databases) |
a7cf4eb6 | 36 | #:use-module (gnu services shepherd) |
d782de17 | 37 | #:use-module (gnu services admin) |
a7cf4eb6 | 38 | #:use-module (gnu system shadow) |
e9bf5110 MO |
39 | #:use-module (srfi srfi-1) |
40 | #:use-module (ice-9 match) | |
189e62fa MO |
41 | #:export (<cuirass-remote-server-configuration> |
42 | cuirass-remote-server-configuration | |
43 | cuirass-remote-server-configuration? | |
44 | ||
45 | <cuirass-configuration> | |
a7cf4eb6 ML |
46 | cuirass-configuration |
47 | cuirass-configuration? | |
189e62fa | 48 | cuirass-service-type |
a7cf4eb6 | 49 | |
189e62fa MO |
50 | <cuirass-remote-worker-configuration> |
51 | cuirass-remote-worker-configuration | |
52 | cuirass-remote-worker-configuration? | |
6c883d0f | 53 | cuirass-remote-worker-service-type)) |
a7cf4eb6 ML |
54 | |
55 | ;;;; Commentary: | |
56 | ;;; | |
57 | ;;; This module implements a service that to run instances of Cuirass, a | |
58 | ;;; continuous integration tool. | |
59 | ;;; | |
60 | ;;;; Code: | |
61 | ||
189e62fa | 62 | (define %cuirass-default-database |
3f3d6637 | 63 | "dbname=cuirass host=/tmp") |
189e62fa MO |
64 | |
65 | (define-record-type* <cuirass-remote-server-configuration> | |
66 | cuirass-remote-server-configuration make-cuirass-remote-server-configuration | |
67 | cuirass-remote-server-configuration? | |
68 | (backend-port cuirass-remote-server-configuration-backend-port ;int | |
3c9a3538 MO |
69 | (default 5555)) |
70 | (log-port cuirass-remote-server-configuration-log-port ;int | |
71 | (default 5556)) | |
189e62fa | 72 | (publish-port cuirass-remote-server-configuration-publish-port ;int |
3c9a3538 | 73 | (default 5557)) |
189e62fa MO |
74 | (log-file cuirass-remote-server-log-file ;string |
75 | (default "/var/log/cuirass-remote-server.log")) | |
76 | (cache cuirass-remote-server-configuration-cache ;string | |
77 | (default "/var/cache/cuirass/remote/")) | |
78 | (trigger-url cuirass-remote-server-trigger-url ;string | |
79 | (default #f)) | |
80 | (public-key cuirass-remote-server-configuration-public-key ;string | |
81 | (default #f)) | |
82 | (private-key cuirass-remote-server-configuration-private-key ;string | |
83 | (default #f))) | |
84 | ||
a7cf4eb6 ML |
85 | (define-record-type* <cuirass-configuration> |
86 | cuirass-configuration make-cuirass-configuration | |
87 | cuirass-configuration? | |
379b6ba5 LC |
88 | (cuirass cuirass-configuration-cuirass ;package |
89 | (default cuirass)) | |
b17e326f LC |
90 | (log-file cuirass-configuration-log-file ;string |
91 | (default "/var/log/cuirass.log")) | |
3e7a62e2 RW |
92 | (web-log-file cuirass-configuration-web-log-file ;string |
93 | (default "/var/log/cuirass-web.log")) | |
a7cf4eb6 | 94 | (cache-directory cuirass-configuration-cache-directory ;string (dir-name) |
463995da | 95 | (default "/var/cache/cuirass")) |
a7cf4eb6 ML |
96 | (user cuirass-configuration-user ;string |
97 | (default "cuirass")) | |
98 | (group cuirass-configuration-group ;string | |
99 | (default "cuirass")) | |
100 | (interval cuirass-configuration-interval ;integer (seconds) | |
101 | (default 60)) | |
1443e2dd MO |
102 | (parameters cuirass-configuration-parameters ;string |
103 | (default #f)) | |
189e62fa MO |
104 | (remote-server cuirass-configuration-remote-server |
105 | (default #f)) | |
0f01493d | 106 | (database cuirass-configuration-database ;string |
189e62fa | 107 | (default %cuirass-default-database)) |
11b7717d | 108 | (port cuirass-configuration-port ;integer (port) |
1c05aab4 | 109 | (default 8081)) |
326f6ef1 JN |
110 | (host cuirass-configuration-host ;string |
111 | (default "localhost")) | |
231eddc8 LC |
112 | (specifications cuirass-configuration-specifications) |
113 | ;gexp that evaluates to specification-alist | |
a7cf4eb6 ML |
114 | (use-substitutes? cuirass-configuration-use-substitutes? ;boolean |
115 | (default #f)) | |
116 | (one-shot? cuirass-configuration-one-shot? ;boolean | |
eb122280 | 117 | (default #f)) |
c800fd56 | 118 | (fallback? cuirass-configuration-fallback? ;boolean |
af96c1e0 CB |
119 | (default #f)) |
120 | (extra-options cuirass-configuration-extra-options | |
121 | (default '()))) | |
a7cf4eb6 ML |
122 | |
123 | (define (cuirass-shepherd-service config) | |
124 | "Return a <shepherd-service> for the Cuirass service with CONFIG." | |
46e552cb LC |
125 | (let ((cuirass (cuirass-configuration-cuirass config)) |
126 | (cache-directory (cuirass-configuration-cache-directory config)) | |
127 | (web-log-file (cuirass-configuration-web-log-file config)) | |
128 | (log-file (cuirass-configuration-log-file config)) | |
129 | (user (cuirass-configuration-user config)) | |
130 | (group (cuirass-configuration-group config)) | |
131 | (interval (cuirass-configuration-interval config)) | |
1443e2dd | 132 | (parameters (cuirass-configuration-parameters config)) |
189e62fa | 133 | (remote-server (cuirass-configuration-remote-server config)) |
46e552cb | 134 | (database (cuirass-configuration-database config)) |
46e552cb LC |
135 | (port (cuirass-configuration-port config)) |
136 | (host (cuirass-configuration-host config)) | |
137 | (specs (cuirass-configuration-specifications config)) | |
138 | (use-substitutes? (cuirass-configuration-use-substitutes? config)) | |
139 | (one-shot? (cuirass-configuration-one-shot? config)) | |
af96c1e0 CB |
140 | (fallback? (cuirass-configuration-fallback? config)) |
141 | (extra-options (cuirass-configuration-extra-options config))) | |
189e62fa MO |
142 | `(,(shepherd-service |
143 | (documentation "Run Cuirass.") | |
144 | (provision '(cuirass)) | |
f2b10e1b | 145 | (requirement '(guix-daemon postgres postgres-roles networking)) |
189e62fa MO |
146 | (start #~(make-forkexec-constructor |
147 | (list (string-append #$cuirass "/bin/cuirass") | |
eda735fb | 148 | "register" |
189e62fa MO |
149 | "--cache-directory" #$cache-directory |
150 | "--specifications" | |
151 | #$(scheme-file "cuirass-specs.scm" specs) | |
152 | "--database" #$database | |
153 | "--interval" #$(number->string interval) | |
1443e2dd MO |
154 | #$@(if parameters |
155 | (list (string-append | |
156 | "--parameters=" | |
157 | parameters)) | |
158 | '()) | |
189e62fa MO |
159 | #$@(if remote-server '("--build-remote") '()) |
160 | #$@(if use-substitutes? '("--use-substitutes") '()) | |
161 | #$@(if one-shot? '("--one-shot") '()) | |
162 | #$@(if fallback? '("--fallback") '()) | |
163 | #$@extra-options) | |
164 | ||
165 | #:environment-variables | |
166 | (list "GIT_SSL_CAINFO=/etc/ssl/certs/ca-certificates.crt" | |
167 | (string-append "GIT_EXEC_PATH=" #$git | |
168 | "/libexec/git-core")) | |
169 | ||
170 | #:user #$user | |
171 | #:group #$group | |
172 | #:log-file #$log-file)) | |
173 | (stop #~(make-kill-destructor))) | |
174 | ,(shepherd-service | |
175 | (documentation "Run Cuirass web interface.") | |
176 | (provision '(cuirass-web)) | |
f2b10e1b | 177 | (requirement '(cuirass)) |
189e62fa MO |
178 | (start #~(make-forkexec-constructor |
179 | (list (string-append #$cuirass "/bin/cuirass") | |
eda735fb | 180 | "web" |
189e62fa | 181 | "--database" #$database |
189e62fa | 182 | "--listen" #$host |
eda735fb | 183 | "--port" #$(number->string port) |
1443e2dd | 184 | #$@(if parameters |
91911b93 | 185 | (list (string-append |
1443e2dd MO |
186 | "--parameters=" |
187 | parameters)) | |
91911b93 | 188 | '()) |
189e62fa MO |
189 | #$@extra-options) |
190 | ||
191 | #:user #$user | |
192 | #:group #$group | |
193 | #:log-file #$web-log-file)) | |
194 | (stop #~(make-kill-destructor))) | |
195 | ,@(if remote-server | |
196 | (match-record remote-server <cuirass-remote-server-configuration> | |
197 | (backend-port publish-port log-file cache trigger-url | |
198 | public-key private-key) | |
199 | (list | |
200 | (shepherd-service | |
201 | (documentation "Run Cuirass remote build server.") | |
202 | (provision '(cuirass-remote-server)) | |
f2b10e1b | 203 | (requirement '(avahi-daemon cuirass)) |
189e62fa | 204 | (start #~(make-forkexec-constructor |
eda735fb MO |
205 | (list (string-append #$cuirass "/bin/cuirass") |
206 | "remote-server" | |
189e62fa MO |
207 | (string-append "--database=" #$database) |
208 | (string-append "--cache=" #$cache) | |
209 | (string-append "--user=" #$user) | |
210 | #$@(if backend-port | |
211 | (list (string-append | |
212 | "--backend-port=" | |
213 | (number->string backend-port))) | |
214 | '()) | |
215 | #$@(if publish-port | |
216 | (list (string-append | |
217 | "--publish-port=" | |
218 | (number->string publish-port))) | |
219 | '()) | |
1443e2dd MO |
220 | #$@(if parameters |
221 | (list (string-append | |
222 | "--parameters=" | |
223 | parameters)) | |
224 | '()) | |
189e62fa MO |
225 | #$@(if trigger-url |
226 | (list | |
227 | (string-append | |
228 | "--trigger-substitute-url=" | |
229 | trigger-url)) | |
230 | '()) | |
231 | #$@(if public-key | |
232 | (list | |
233 | (string-append "--public-key=" | |
234 | public-key)) | |
235 | '()) | |
236 | #$@(if private-key | |
237 | (list | |
238 | (string-append "--private-key=" | |
239 | private-key)) | |
240 | '())) | |
241 | #:log-file #$log-file)) | |
242 | (stop #~(make-kill-destructor))))) | |
243 | '())))) | |
a7cf4eb6 ML |
244 | |
245 | (define (cuirass-account config) | |
246 | "Return the user accounts and user groups for CONFIG." | |
247 | (let ((cuirass-user (cuirass-configuration-user config)) | |
248 | (cuirass-group (cuirass-configuration-group config))) | |
249 | (list (user-group | |
250 | (name cuirass-group) | |
251 | (system? #t)) | |
252 | (user-account | |
253 | (name cuirass-user) | |
254 | (group cuirass-group) | |
255 | (system? #t) | |
256 | (comment "Cuirass privilege separation user") | |
8d4805ba | 257 | (home-directory (string-append "/var/lib/" cuirass-user)) |
56a93cb9 | 258 | (shell (file-append shadow "/sbin/nologin")))))) |
a7cf4eb6 | 259 | |
0f01493d MO |
260 | (define (cuirass-postgresql-role config) |
261 | (let ((user (cuirass-configuration-user config))) | |
262 | (list (postgresql-role | |
263 | (name user) | |
264 | (create-database? #t))))) | |
265 | ||
463995da LC |
266 | (define (cuirass-activation config) |
267 | "Return the activation code for CONFIG." | |
5ba7e828 MO |
268 | (let* ((cache (cuirass-configuration-cache-directory config)) |
269 | (remote-server (cuirass-configuration-remote-server config)) | |
270 | (remote-cache (and remote-server | |
271 | (cuirass-remote-server-configuration-cache | |
272 | remote-server))) | |
5ba7e828 MO |
273 | (user (cuirass-configuration-user config)) |
274 | (log "/var/log/cuirass") | |
275 | (group (cuirass-configuration-group config))) | |
463995da LC |
276 | (with-imported-modules '((guix build utils)) |
277 | #~(begin | |
278 | (use-modules (guix build utils)) | |
279 | ||
280 | (mkdir-p #$cache) | |
b40f4a59 | 281 | (mkdir-p #$log) |
463995da | 282 | |
5ba7e828 MO |
283 | (when #$remote-cache |
284 | (mkdir-p #$remote-cache)) | |
285 | ||
463995da LC |
286 | (let ((uid (passwd:uid (getpw #$user))) |
287 | (gid (group:gid (getgr #$group)))) | |
137f8df6 | 288 | (chown #$cache uid gid) |
5ba7e828 MO |
289 | (chown #$log uid gid) |
290 | ||
291 | (when #$remote-cache | |
292 | (chown #$remote-cache uid gid))))))) | |
463995da | 293 | |
d782de17 LC |
294 | (define (cuirass-log-rotations config) |
295 | "Return the list of log rotations that corresponds to CONFIG." | |
0f01493d MO |
296 | (list (log-rotation |
297 | (files (list (cuirass-configuration-log-file config))) | |
298 | (frequency 'weekly) | |
299 | (options '("rotate 40"))))) ;worth keeping | |
d782de17 | 300 | |
a7cf4eb6 ML |
301 | (define cuirass-service-type |
302 | (service-type | |
303 | (name 'cuirass) | |
304 | (extensions | |
305 | (list | |
38d6aa05 LC |
306 | (service-extension profile-service-type ;for 'info cuirass' |
307 | (compose list cuirass-configuration-cuirass)) | |
d782de17 | 308 | (service-extension rottlog-service-type cuirass-log-rotations) |
463995da | 309 | (service-extension activation-service-type cuirass-activation) |
a7cf4eb6 | 310 | (service-extension shepherd-root-service-type cuirass-shepherd-service) |
0f01493d | 311 | (service-extension account-service-type cuirass-account) |
3bcfd416 MO |
312 | ;; Make sure postgresql and postgresql-role are instantiated. |
313 | (service-extension postgresql-service-type (const #t)) | |
0f01493d MO |
314 | (service-extension postgresql-role-service-type |
315 | cuirass-postgresql-role))) | |
a64160d2 RW |
316 | (description |
317 | "Run the Cuirass continuous integration service."))) | |
189e62fa MO |
318 | |
319 | (define-record-type* <cuirass-remote-worker-configuration> | |
320 | cuirass-remote-worker-configuration make-cuirass-remote-worker-configuration | |
321 | cuirass-remote-worker-configuration? | |
322 | (cuirass cuirass-remote-worker-configuration-cuirass ;package | |
323 | (default cuirass)) | |
324 | (workers cuirass-remote-worker-workers ;int | |
325 | (default 1)) | |
66c31d50 MO |
326 | (server cuirass-remote-worker-server ;string |
327 | (default #f)) | |
a19b6889 | 328 | (systems cuirass-remote-worker-systems ;list |
8d8bbe7c | 329 | (default (list (%current-system)))) |
189e62fa MO |
330 | (log-file cuirass-remote-worker-log-file ;string |
331 | (default "/var/log/cuirass-remote-worker.log")) | |
332 | (publish-port cuirass-remote-worker-configuration-publish-port ;int | |
3c9a3538 | 333 | (default 5558)) |
189e62fa MO |
334 | (public-key cuirass-remote-worker-configuration-public-key ;string |
335 | (default #f)) | |
336 | (private-key cuirass-remote-worker-configuration-private-key ;string | |
337 | (default #f))) | |
338 | ||
339 | (define (cuirass-remote-worker-shepherd-service config) | |
340 | "Return a <shepherd-service> for the Cuirass remote worker service with | |
341 | CONFIG." | |
342 | (match-record config <cuirass-remote-worker-configuration> | |
66c31d50 MO |
343 | (cuirass workers server systems log-file publish-port |
344 | public-key private-key) | |
189e62fa MO |
345 | (list (shepherd-service |
346 | (documentation "Run Cuirass remote build worker.") | |
347 | (provision '(cuirass-remote-worker)) | |
348 | (requirement '(avahi-daemon guix-daemon networking)) | |
349 | (start #~(make-forkexec-constructor | |
eda735fb MO |
350 | (list (string-append #$cuirass "/bin/cuirass") |
351 | "remote-worker" | |
eb9adede MO |
352 | (string-append "--workers=" |
353 | #$(number->string workers)) | |
66c31d50 MO |
354 | #$@(if server |
355 | (list (string-append "--server=" server)) | |
356 | '()) | |
a19b6889 MO |
357 | #$@(if systems |
358 | (list (string-append | |
359 | "--systems=" | |
360 | (string-join systems ","))) | |
361 | '()) | |
189e62fa MO |
362 | #$@(if publish-port |
363 | (list (string-append | |
364 | "--publish-port=" | |
365 | (number->string publish-port))) | |
366 | '()) | |
367 | #$@(if public-key | |
368 | (list | |
369 | (string-append "--public-key=" | |
370 | public-key)) | |
371 | '()) | |
372 | #$@(if private-key | |
373 | (list | |
374 | (string-append "--private-key=" | |
375 | private-key)) | |
eff80711 MO |
376 | '())) |
377 | #:log-file #$log-file)) | |
189e62fa MO |
378 | (stop #~(make-kill-destructor)))))) |
379 | ||
380 | (define cuirass-remote-worker-service-type | |
381 | (service-type | |
382 | (name 'cuirass-remote-worker) | |
383 | (extensions | |
384 | (list | |
385 | (service-extension shepherd-root-service-type | |
386 | cuirass-remote-worker-shepherd-service))) | |
387 | (description | |
388 | "Run the Cuirass remote build worker service."))) |