diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index b0df63100530..fea2ff44a4f0 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -30,6 +30,11 @@ - `boot.vesa` has been removed. It was deprecated in 2020 because Xorg now works better with kernel modesetting. If you still need the legacy VESA 800x600 fallback, set `boot.kernelParams = [ "vga=0x317" "nomodeset" ];` directly. +- `authentik` has been updated to 2026.5.3, which changes the default listen address from `0.0.0.0` to `[::]`. + IPv4-only deployments might need to adjust their listen settings. + Deployments running the server and worker in the same network namespace must also set at least the worker + `AUTHENTIK_LISTEN__HTTP` address so that the server and worker do not bind to the same address. + - Support for the legacy U‐Boot image format has been removed from the initrd generators, as it is deprecated upstream and no longer used by any platform in Nixpkgs. - Rustical migrates from `settings.http.host` and `settings.http.port` to `settings.http.bind` to support UNIX domain sockets as well as TCP sockets in one setting. diff --git a/pkgs/by-name/au/authentik/client-go-config.patch b/pkgs/by-name/au/authentik/client-go-config.patch deleted file mode 100644 index 8398b16160c7..000000000000 --- a/pkgs/by-name/au/authentik/client-go-config.patch +++ /dev/null @@ -1,9 +0,0 @@ -diff --git a/config.yaml b/config.yaml -index 2f07ea7..0f90432 100644 ---- a/config.yaml -+++ b/config.yaml -@@ -4,3 +4,4 @@ additionalProperties: - packageName: api - enumClassPrefix: true - useOneOfDiscriminatorLookup: true -+ disallowAdditionalPropertiesIfNotPresent: false diff --git a/pkgs/by-name/au/authentik/package.nix b/pkgs/by-name/au/authentik/package.nix index ff63e72475e2..fef159aa3c62 100644 --- a/pkgs/by-name/au/authentik/package.nix +++ b/pkgs/by-name/au/authentik/package.nix @@ -3,14 +3,19 @@ stdenvNoCC, callPackages, cacert, + clangStdenv, + cmake, fetchFromGitHub, buildGoModule, + buildNpmPackage, bash, chromedriver, nodejs_24, - python3, + python314, makeWrapper, openapi-generator-cli, + perl, + rustPlatform, go, typescript, makeSetupHook, @@ -20,13 +25,18 @@ let nodejs = nodejs_24; - version = "2025.12.6"; + version = "2026.5.3"; + + cargoPackageFlags = [ + "--package" + "authentik" + ]; src = fetchFromGitHub { owner = "goauthentik"; repo = "authentik"; tag = "version/${version}"; - hash = "sha256-uIg47z4LaCawF/5ir4mKE6DpDnEpQ8DuObCNaq6TcYk="; + hash = "sha256-nmAX8nwZpdDcFAPvC9hAEp0x43RnFtGLUTAm7NcvNZo="; }; meta = { @@ -46,24 +56,9 @@ let client-go = stdenvNoCC.mkDerivation { pname = "authentik-client-go"; - version = "3.${version}"; - inherit meta; + inherit version src meta; - src = fetchFromGitHub { - owner = "goauthentik"; - repo = "client-go"; - tag = "v3.2025.12.4"; - hash = "sha256-+/CfOE2HkBU+ZddvdXGenB/z8xNFk8cujpZpMXyh3cY="; - }; - - patches = [ - ./client-go-config.patch - ]; - - postPatch = '' - substituteInPlace ./config.yaml \ - --replace-fail '/local' "$(pwd)" - ''; + sourceRoot = "${src.name}/packages/client-go"; nativeBuildInputs = [ openapi-generator-cli @@ -86,10 +81,9 @@ let installPhase = '' runHook preInstall - cp go.mod go.sum $out - cd $out rm -rf test + rm -f go.mod go.sum rm -f .travis.yml git_push.sh runHook postInstall @@ -101,8 +95,8 @@ let inherit version src meta; postPatch = '' - substituteInPlace ./scripts/api/ts-config.yaml \ - --replace-fail '/local' "$(pwd)" + substituteInPlace ./packages/client-ts/config.yaml \ + --replace-fail '/local' "$(pwd)/packages/client-ts" ''; nativeBuildInputs = [ @@ -117,7 +111,7 @@ let openapi-generator-cli generate \ -i ./schema.yml -o $out \ -g typescript-fetch \ - -c ./scripts/api/ts-config.yaml \ + -c ./packages/client-ts/config.yaml \ --additional-properties=npmVersion=${version} \ --git-repo-id authentik --git-user-id goauthentik @@ -128,32 +122,19 @@ let ''; }; - # prefetch-npm-deps does not save all dependencies even though the lockfile is fine - website-deps = stdenvNoCC.mkDerivation { + website-deps = buildNpmPackage { pname = "authentik-website-deps"; inherit src version meta; sourceRoot = "${src.name}/website"; - outputHash = - { - "aarch64-linux" = "sha256-EbLneRDCyLLLBOZ2DUDpf2TbZoTL8QMXP4WlAZEzS90="; - "x86_64-linux" = "sha256-yDjwN/+lX2i9WYDXq4yWwf9o8nA4342iHDDQH4Jt7eQ="; - } - .${stdenvNoCC.hostPlatform.system} or (throw "authentik-website-deps: unsupported host platform"); - - outputHashMode = "recursive"; - - nativeBuildInputs = [ - nodejs - cacert - ]; - - buildPhase = '' - npm ci --cache ./cache - - rm -r ./cache node_modules/.package-lock.json - ''; + inherit nodejs; + npmDepsHash = "sha256-SkIZF+wQPgoZOGJc0YR8Ot07KCsAdA1985SLQaoibfA="; + npmDepsFetcherVersion = 2; + makeCacheWritable = true; + npmInstallFlags = [ "--legacy-peer-deps" ]; + npmRebuildFlags = [ "--ignore-scripts" ]; + dontNpmBuild = true; # dependencies of workspace projects are installed into separate node_modules folders with # symlinks between them, so we have to copy all of them @@ -208,8 +189,8 @@ let outputHash = { - "aarch64-linux" = "sha256-J9wGQe7iMfKznNk3woqi0VNVNA/dE6TGi2f44DOlG1c="; - "x86_64-linux" = "sha256-9Q590Rw0mk3q5osxOKGWU7+XtKwkTyA+CLC2LxAA/3g="; + "aarch64-linux" = "sha256-41xZEfLul92vJATZqyVnd7Pp++NzLL/u8NeJJPHpXrw="; + "x86_64-linux" = "sha256-FpfOl6wNCgXLg86+vbjnYkcOnpaOZBCNxJiFDRT5W3s="; } .${stdenvNoCC.hostPlatform.system} or (throw "authentik-webui-deps: unsupported host platform"); outputHashMode = "recursive"; @@ -220,6 +201,7 @@ let ]; buildPhase = '' + chmod -R +w . ../packages/client-ts npm ci --cache ./cache --ignore-scripts rm -r ./cache node_modules/.package-lock.json @@ -295,7 +277,7 @@ let ]; }; - python = python3.override { + python = python314.override { self = python; packageOverrides = final: prev: { # https://github.com/goauthentik/authentik/pull/16324 @@ -376,62 +358,6 @@ let ]; }; - # Running authentik currently requires a custom version. - # Look in `pyproject.toml` for changes to the rev in the `[tool.uv.sources]` section. - # See https://github.com/goauthentik/authentik/pull/14057 for latest version bump. - djangorestframework = final.buildPythonPackage { - pname = "djangorestframework"; - version = "3.16.0"; - format = "setuptools"; - - src = fetchFromGitHub { - owner = "authentik-community"; - repo = "django-rest-framework"; - rev = "896722bab969fabc74a08b827da59409cf9f1a4e"; - hash = "sha256-YrEDEU3qtw/iyQM3CoB8wYx57zuPNXiJx6ZjrIwnCNU="; - }; - - propagatedBuildInputs = with final; [ - django - pytz - ]; - - nativeCheckInputs = with final; [ - pytest-django - pytest7CheckHook - - # optional tests - coreapi - django-guardian - inflection - pyyaml - uritemplate - ]; - - disabledTests = [ - "test_ignore_validation_for_unchanged_fields" - "test_invalid_inputs" - "test_shell_code_example_rendering" - "test_unique_together_condition" - "test_unique_together_with_source" - ]; - - pythonImportsCheck = [ "rest_framework" ]; - }; - - # authentik is currently not compatible with v1.18 and fails with the following error: - # > AttributeError: 'Namespace' object has no attribute 'worker_fork_timeout'. Did you mean: 'worker_shutdown_timeout'? - dramatiq = prev.dramatiq.overrideAttrs (_: rec { - version = "1.17.1"; - - src = fetchFromGitHub { - owner = "Bogdanp"; - repo = "dramatiq"; - tag = "v${version}"; - hash = "sha256-NeUGhG+H6r+JGd2qnJxRUbQ61G7n+3tsuDugTin3iJ4="; - }; - }); - authentik-django = final.buildPythonPackage { pname = "authentik-django"; inherit version src meta; @@ -548,7 +474,32 @@ let inherit (python.pkgs) authentik-django; - # Provide a setup-hook to configure the Go vendor directory with up-to-date API bindings. + worker = (rustPlatform.buildRustPackage.override { stdenv = clangStdenv; }) { + pname = "authentik-worker"; + inherit version src meta; + + cargoHash = "sha256-KExlNyT9G3R5rnt99beT2pYrWxezMLhGw+Q9T1X2kj4="; + + nativeBuildInputs = [ + cmake + go + perl + ]; + + buildInputs = [ python ]; + + env = { + PYO3_PYTHON = lib.getExe python; + RUSTFLAGS = "--cfg tokio_unstable"; + }; + + cargoBuildFlags = cargoPackageFlags; + + # Upstream currently has no Rust tests in this package. + doCheck = false; + }; + + # Provide a setup-hook to configure the Go source tree with up-to-date API bindings. # This is done to avoid the `vendorHash` depending on anything in the `client-go` build (e.g. # openapi-generator-cli version updates changing the produced content) and invalidating the hash. apiGoVendorHook = @@ -559,9 +510,10 @@ let ( writeShellScript "authentik-api-go-vendor-hook" '' authentikApiGoVendorHook() { - chmod -R +w vendor/goauthentik.io/api - rm -rf vendor/goauthentik.io/api/v3 - cp -r ${client-go} vendor/goauthentik.io/api/v3 + chmod -R +w packages/client-go + rm -rf packages/client-go + cp -r ${client-go} packages/client-go + chmod -R +w packages/client-go echo "Finished authentikApiGoVendorHook" } @@ -593,10 +545,11 @@ let # calculate the vendorHash without other dependencies, so it is only based on the `go.sum` file overrideModAttrs.postPatch = ""; - vendorHash = "sha256-pdQg02f1K4nOhsnadoplQYOhEybqZxn+yDQRN5RNygM="; + vendorHash = "sha256-EVDOZ4USaJoIBDB8mM4ZSBfsSc1d/NOm1Qv/hUJ+8f4="; postInstall = '' - mv $out/bin/server $out/bin/authentik + mv $out/bin/server $out/bin/authentik-server + ln -s authentik-server $out/bin/authentik ''; subPackages = [ "cmd/server" ]; @@ -612,11 +565,6 @@ stdenvNoCC.mkDerivation { postPatch = '' rm Makefile patchShebangs lifecycle/ak - - # This causes issues in systemd services - substituteInPlace lifecycle/ak \ - --replace-fail 'printf' '>&2 printf' \ - --replace-fail '>/dev/stderr' "" ''; installPhase = '' @@ -627,8 +575,9 @@ stdenvNoCC.mkDerivation { wrapProgram $out/bin/ak \ --prefix PATH : ${ lib.makeBinPath [ - (python.withPackages (ps: [ ps.authentik-django ])) + worker proxy + (python.withPackages (ps: [ ps.authentik-django ])) ] } \ --set TMPDIR /dev/shm \ @@ -638,7 +587,7 @@ stdenvNoCC.mkDerivation { ''; passthru = { - inherit proxy apiGoVendorHook; + inherit proxy worker apiGoVendorHook; outposts = callPackages ./outposts.nix { inherit (proxy) vendorHash; inherit apiGoVendorHook;