authentik: 2025.6.4 -> 2025.8.3

This commit is contained in:
Fabian Möller
2025-09-18 12:34:06 +02:00
parent 01174307fc
commit 438979abe6
+78 -74
View File
@@ -5,23 +5,23 @@
cacert,
fetchFromGitHub,
buildGoModule,
runCommand,
bash,
chromedriver,
openapi-generator-cli,
nodejs,
nodejs_24,
python312,
makeWrapper,
}:
let
version = "2025.6.4";
nodejs = nodejs_24;
version = "2025.8.3";
src = fetchFromGitHub {
owner = "goauthentik";
repo = "authentik";
rev = "version/${version}";
hash = "sha256-bs/ThY3YixwBObahcS7BrOWj0gsaUXI664ldUQlJul8=";
hash = "sha256-DkvxDwHCfSqEpZ9rRXNR8MP0Mz/y1kHAr38exrHQ39c=";
};
meta = {
@@ -48,10 +48,10 @@ let
outputHash =
{
"aarch64-linux" = "sha256-+UObt/FhHkEzZUR24ND6phSDqvuzaOuUiyoW0dolsiY=";
"x86_64-linux" = "sha256-1qlJf4mVYM5znF3Ifi7CpGMfinUsb/YoXGeM6QLYMis=";
"aarch64-linux" = "sha256-uJe1v43d3baBUESU+CQk6fYBdiNOBiT3Tt0vFIbI/HY=";
"x86_64-linux" = "sha256-jVi+pgcz96Dj25T4e/s+SHqsZfonzXs1WZYe0lCI48Q=";
}
.${stdenvNoCC.hostPlatform.system} or (throw "authentik-website-deps: unsupported hust platform");
.${stdenvNoCC.hostPlatform.system} or (throw "authentik-website-deps: unsupported host platform");
outputHashMode = "recursive";
@@ -66,10 +66,15 @@ let
rm -r ./cache node_modules/.package-lock.json
'';
# dependencies of workspace projects are installed into separate node_modules folders with
# symlinks between them, so we have to copy all of them
installPhase = ''
mv node_modules $out
mkdir $out
echo "Copying node_modules folders:"
find -type d -name node_modules -prune -print -exec mkdir -p $out/{} \; -exec cp -rT {} $out/{} \;
'';
dontCheckForBrokenSymlinks = true;
dontPatchShebangs = true;
};
@@ -79,56 +84,29 @@ let
nativeBuildInputs = [ nodejs ];
postPatch = ''
substituteInPlace package.json --replace-fail 'cross-env ' ""
substituteInPlace ../packages/docusaurus-config/lib/common.js \
--replace-fail 'title: "authentik",' 'title: "authentik", future: { experimental_faster : { rspackBundler: false }},'
'';
sourceRoot = "${src.name}/website";
buildPhase = ''
runHook preBuild
cp -r ${website-deps} node_modules
buildRoot=$PWD
pushd ${website-deps}
find -type d -name node_modules -prune -print -exec cp -rT {} $buildRoot/{} \;
popd
chmod -R +w node_modules
pushd node_modules/.bin
patchShebangs $(readlink docusaurus)
patchShebangs $(readlink docusaurus) $(readlink run-s)
popd
npm run build:schema
npm run build:api
npm run build:docusaurus
runHook postBuild
'';
installPhase = ''
mkdir $out
cp -r build $out/help
'';
};
clientapi = stdenvNoCC.mkDerivation {
pname = "authentik-client-api";
inherit version src meta;
postPatch = ''
rm Makefile
substituteInPlace ./scripts/api-ts-config.yaml \
--replace-fail '/local' "$(pwd)/"
'';
nativeBuildInputs = [ openapi-generator-cli ];
buildPhase = ''
runHook preBuild
openapi-generator-cli generate -i ./schema.yml \
-g typescript-fetch -o $out \
-c ./scripts/api-ts-config.yaml \
--additional-properties=npmVersion="$(${lib.getExe' nodejs "npm"} --version)" \
--git-repo-id authentik --git-user-id goauthentik
runHook postBuild
cp -r api/build $out/help
'';
};
@@ -141,10 +119,10 @@ let
outputHash =
{
"aarch64-linux" = "sha256-e4v7f3+/e++CI9xa9G2/47y8Dga+vluyUtBXGyaWFcI=";
"x86_64-linux" = "sha256-m0vYUevOz6pof8XqiZHXzgPhkQLUUFOdblmfOjHJUJc=";
"aarch64-linux" = "sha256-4JkNwQACS3tiiLuj41cGRWNspljVQxlsJvCM9KE2JrQ=";
"x86_64-linux" = "sha256-LD+zXc8neRbEwq1mx9y7b+08p8hxvo/RW6QzsFQgaUs=";
}
.${stdenvNoCC.hostPlatform.system} or (throw "authentik-webui-deps: unsupported hust platform");
.${stdenvNoCC.hostPlatform.system} or (throw "authentik-webui-deps: unsupported host platform");
outputHashMode = "recursive";
nativeBuildInputs = [
@@ -152,52 +130,35 @@ let
cacert
];
postPatch = ''
substituteInPlace packages/core/version/node.js \
--replace-fail 'import PackageJSON from "../../../../package.json" with { type: "json" };' "" \
--replace-fail '(PackageJSON.version);' '"${version}";'
'';
buildPhase = ''
npm ci --cache ./cache
rm -r node_modules/chromedriver node_modules/.bin/chromedriver
npm ci --cache ./cache --ignore-scripts
rm -r ./cache node_modules/.package-lock.json
rm node_modules/@goauthentik/{core,web-sfe,esbuild-plugin-live-reload}
cp -r packages/core node_modules/@goauthentik/
cp -r packages/sfe node_modules/@goauthentik/web-sfe
'';
# dependencies of workspace projects are installed into separate node_modules folders with
# symlinks between them, so we have to copy all of them
installPhase = ''
mv node_modules $out
mkdir $out
echo "Copying node_modules folders:"
find -type d -name node_modules -prune -print -exec mkdir -p $out/{} \; -exec cp -rT {} $out/{} \;
'';
dontCheckForBrokenSymlinks = true;
dontPatchShebangs = true;
};
webui = stdenvNoCC.mkDerivation {
pname = "authentik-webui";
inherit version meta;
inherit src version meta;
src = runCommand "authentik-webui-source" { } ''
mkdir $out
cp -r ${src}/web $out/
ln -s ${src}/package.json $out/
chmod -R +w $out/web
ln -s ${src}/website $out/web/
cp -r ${webui-deps} $out/web/node_modules
chmod -R +w $out/web/node_modules
ln -s ${clientapi} $out/web/node_modules/@goauthentik/api
'';
sourceRoot = "${src.name}/web";
nativeBuildInputs = [
nodejs
];
postPatch = ''
cd web
substituteInPlace packages/core/version/node.js \
--replace-fail 'import PackageJSON from "../../../../package.json" with { type: "json" };' "" \
--replace-fail '(PackageJSON.version);' '"${version}";'
@@ -206,6 +167,11 @@ let
buildPhase = ''
runHook preBuild
buildRoot=$PWD
pushd ${webui-deps}
find -type d -name node_modules -prune -print -exec cp -rT {} $buildRoot/{} \;
popd
pushd node_modules/.bin
patchShebangs $(readlink rollup)
patchShebangs $(readlink wireit)
@@ -242,6 +208,28 @@ let
# https://github.com/goauthentik/authentik/pull/14709
django = final.django_5_1;
django-dramatiq-postgres = prev.buildPythonPackage {
pname = "django-dramatiq-postgres";
inherit version src meta;
pyproject = true;
sourceRoot = "${src.name}/packages/django-dramatiq-postgres";
build-system = with final; [ hatchling ];
propagatedBuildInputs =
with final;
[
cron-converter
django
django-pgtrigger
dramatiq
structlog
tenacity
]
++ dramatiq.optional-dependencies.watch;
};
# Running authentik currently requires a custom version.
# Look in `pyproject.toml` for changes to the rev in the `[tool.uv.sources]` section.
# See https://github.com/goauthentik/authentik/pull/14057 for latest version bump.
@@ -285,6 +273,19 @@ let
pythonImportsCheck = [ "rest_framework" ];
};
# authentik is currently not compatible with v1.18 and fails with the following error:
# > AttributeError: 'Namespace' object has no attribute 'worker_fork_timeout'. Did you mean: 'worker_shutdown_timeout'?
dramatiq = prev.dramatiq.overrideAttrs (_: rec {
version = "1.17.1";
src = fetchFromGitHub {
owner = "Bogdanp";
repo = "dramatiq";
tag = "v${version}";
hash = "sha256-NeUGhG+H6r+JGd2qnJxRUbQ61G7n+3tsuDugTin3iJ4=";
};
});
tenant-schemas-celery = prev.tenant-schemas-celery.overrideAttrs (_: rec {
version = "3.0.0";
@@ -292,7 +293,7 @@ let
owner = "maciej-gol";
repo = "tenant-schemas-celery";
tag = version;
hash = "sha256-rGLrP8rE9SACMDVpNeBU85U/Sb2lNhsgEgHJhAsdKNM=";
hash = "sha256-3ZUXSAOBMtj72sk/VwPV24ysQK+E4l1HdwKa78xrDtg=";
};
});
@@ -335,14 +336,17 @@ let
django
django-countries
django-cte
django-dramatiq-postgres
django-filter
django-guardian
django-model-utils
django-pglock
django-pgtrigger
django-prometheus
django-redis
django-storages
django-tenants
djangoql
djangorestframework
djangorestframework-guardian
docker
@@ -427,7 +431,7 @@ let
env.CGO_ENABLED = 0;
vendorHash = "sha256-7oX7e7Ni5I6zblEQIeXjYOt4+QNSjH4Rpn7B5Cr5LMc=";
vendorHash = "sha256-wTTEDBRYCW1UFaeX49ufLT0c17sacJzcCaW/8cPNYR4=";
postInstall = ''
mv $out/bin/server $out/bin/authentik