Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 6 additions & 2 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -86,12 +86,16 @@ jobs:
runs-on: ubuntu-latest
needs: [check_if_version_upgraded, create_github_release]
if: needs.check_if_version_upgraded.outputs.is_pre_release != 'true'
permissions:
contents: write
steps:
# Pushing to main requires a bypass of the pull-request rule.
# If the NIX_PINS_DEPLOY_KEY secret is set (a write-enabled deploy
# key, with "Deploy keys" on the ruleset bypass list), the push
# goes over SSH; when unset, checkout falls back to GITHUB_TOKEN,
# which needs the workflow/bot allowed through the ruleset instead.
- uses: actions/checkout@v4
with:
ref: main
ssh-key: ${{ secrets.NIX_PINS_DEPLOY_KEY }}
- uses: actions/setup-node@v4
- name: Re-pin docs/deployment-nixos.md to the new release
run: node scripts/update-nixos-plugin-pins.mjs --tag v${{ needs.check_if_version_upgraded.outputs.to_version }}
Expand Down
1 change: 1 addition & 0 deletions .storybook/preview.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
import type { Preview } from '@storybook/react-vite'
import React from 'react'
import '@helpwave/hightide/style/globals.css'
import '../src/fonts.css'
import '../src/index.css'
import { HightideProvider } from '@helpwave/hightide'

Expand Down
5 changes: 4 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -242,7 +242,10 @@ Cutting and consuming a release is a single repeatable motion:
`themeVersion` / `spiVersion` / `sha256` pins in
[docs/deployment-nixos.md](docs/deployment-nixos.md) from the release assets' digests
and commits the result to `main` — the checked-in NixOS snippet always matches the
latest release.
latest release. Because `main` only accepts pull requests, the pushing identity needs
a ruleset bypass: either allow the workflow's `GITHUB_TOKEN` through, or set the
Actions secret `NIX_PINS_DEPLOY_KEY` to a write-enabled deploy key and put
**Deploy keys** on the bypass list — the job pushes over SSH when the secret is set.
4. **Deploy**: copy the refreshed pin block into your NixOS config and
`nixos-rebuild switch`.

Expand Down
31 changes: 30 additions & 1 deletion docs/deployment-nixos.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,36 @@ All four jars go into Keycloak's `providers/` directory —
The pins below are **kept up to date automatically**: after every release, CI recomputes
the versions and sha256 hashes from the release assets and commits them back to this file
(see [§6 Updating](#6-updating)). Whatever is checked in here always matches the latest
release — copy it as-is.
release — copy it as-is into your module's `let` bindings:

```nix
themeVersion = "0.6.1";
spiVersion = "0.3.0";

release =
ver: file: sha:
pkgs.fetchurl {
name = file;
url = "https://github.com/helpwave/id.helpwave.de/releases/download/v${ver}/${file}";
sha256 = sha;
};

themePlugin =
release themeVersion "keycloak-theme-for-kc-26.2-and-above.jar"
"sha256-nhAyu69jEyf3F0W0qph94iGnVdNU69yGEAUzN3IaJOY=";

captchaSPI =
release themeVersion "helpwave-captcha-${spiVersion}.jar"
"sha256-RSzFG775YXjNLxYlxvCMxxjoRRLYOCUNq2mutrUOaRM=";

pictureSPI =
release themeVersion "helpwave-picture-${spiVersion}.jar"
"sha256-aReO2U4AVyKMQydMqvZ2vIhl3TfM6MWpS7/rZQWerXg=";

policySPI =
release themeVersion "helpwave-policy-acceptance-${spiVersion}.jar"
"sha256-+FZ7skQGOEFD5AmZtIiRAO0xbUwn9bqcZU4Q6SejxBg=";
```

To re-pin manually (e.g. against an older release):

Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "id.helpwave.de",
"version": "0.6.1",
"version": "0.6.2",
"repository": {
"type": "git",
"url": "git://github.com/helpwave/id.helpwave.de.git"
Expand Down
24 changes: 14 additions & 10 deletions scripts/update-nixos-plugin-pins.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -102,16 +102,20 @@ function findAsset(release, predicate, description) {
return asset
}

/** Replaces exactly one occurrence; fails loudly if the doc anchor shape changed. */
function replaceOnce(content, pattern, replacement, description) {
const matches = content.match(new RegExp(pattern, 'g')) ?? []
if (matches.length !== 1) {
/**
* Replaces every occurrence (the pins appear both in the copyable block and in
* the full module example); fails loudly if the doc anchor shape changed.
*/
function replacePins(content, pattern, replacement, description) {
const global = new RegExp(pattern, 'g')
const matches = content.match(global) ?? []
if (matches.length === 0) {
fail(
`Expected exactly 1 match for ${description} in ${path.relative(process.cwd(), DOC_PATH)}, ` +
`found ${matches.length}. Did the pin block in the doc change shape?`
`Found no match for ${description} in ${path.relative(process.cwd(), DOC_PATH)}. ` +
'Did the pin block in the doc change shape?'
)
}
return content.replace(pattern, replacement)
return content.replace(global, replacement)
}

async function main() {
Expand Down Expand Up @@ -149,13 +153,13 @@ async function main() {
const original = fs.readFileSync(DOC_PATH, 'utf8')
let content = original

content = replaceOnce(
content = replacePins(
content,
/themeVersion = "[^"]+";/,
`themeVersion = "${themeVersion}";`,
'themeVersion pin'
)
content = replaceOnce(
content = replacePins(
content,
/spiVersion = "[^"]+";/,
`spiVersion = "${spiVersion}";`,
Expand All @@ -172,7 +176,7 @@ async function main() {
}
for (const [binding, fileAnchor] of Object.entries(bindingAnchors)) {
const escapedAnchor = fileAnchor.replace(/[.*+?^${}()|[\]\\]/g, '\\$&')
content = replaceOnce(
content = replacePins(
content,
new RegExp(`(release themeVersion "${escapedAnchor}"\\s*\\n\\s*")sha256-[A-Za-z0-9+/=]+(")`),
`$1${hashes[binding]}$2`,
Expand Down
2 changes: 1 addition & 1 deletion src/login/components/Branding.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ export function Branding({ animate = 'loading' }: BrandingProps) {
return (
<div className="flex flex-col items-center">
<HelpwaveLogo animate={effectiveAnimate} height={96} width={96} animationDuration={5} />
<div className="font-space text-4xl -translate-y-8 font-[900]">
<div className="font-space text-4xl -translate-y-8 font-bold">
helpwave id
</div>
</div>
Expand Down
Loading