From 930708194b6f1aff52c30f336f70db4b33d38f83 Mon Sep 17 00:00:00 2001 From: Xe Iaso Date: Fri, 27 Oct 2023 09:48:08 -0400 Subject: try this Signed-off-by: Xe Iaso --- .vscode/extensions.json | 12 ++++ lume/src/blog/notes/_data.yml | 1 + .../blog/notes/nix-flakes-terraform-unfree-fix.mdx | 82 ++++++++++++++++++++++ static/img/asg2023-diagram.svg | 1 - 4 files changed, 95 insertions(+), 1 deletion(-) create mode 100644 .vscode/extensions.json create mode 100644 lume/src/blog/notes/_data.yml create mode 100644 lume/src/blog/notes/nix-flakes-terraform-unfree-fix.mdx delete mode 100644 static/img/asg2023-diagram.svg diff --git a/.vscode/extensions.json b/.vscode/extensions.json new file mode 100644 index 0000000..8739ced --- /dev/null +++ b/.vscode/extensions.json @@ -0,0 +1,12 @@ +{ + "recommendations": [ + "unifiedjs.vscode-mdx", + "golang.go", + "bbenoist.nix", + "jnoortheen.nix-ide", + "dhall.dhall-lang", + "denoland.vscode-deno", + "bradlc.vscode-tailwindcss", + "ronnidc.nunjucks" + ] +} \ No newline at end of file diff --git a/lume/src/blog/notes/_data.yml b/lume/src/blog/notes/_data.yml new file mode 100644 index 0000000..25ffedb --- /dev/null +++ b/lume/src/blog/notes/_data.yml @@ -0,0 +1 @@ +is_note: true \ No newline at end of file diff --git a/lume/src/blog/notes/nix-flakes-terraform-unfree-fix.mdx b/lume/src/blog/notes/nix-flakes-terraform-unfree-fix.mdx new file mode 100644 index 0000000..5433191 --- /dev/null +++ b/lume/src/blog/notes/nix-flakes-terraform-unfree-fix.mdx @@ -0,0 +1,82 @@ +--- +title: "How to fix terraform and nix flakes" +date: 2023-10-27 +tags: + - nix + - terraform + - enshittification +hero: + ai: Furryrock + file: coffee-birb + prompt: A pink haired avali wearing a sweater and sweatpants drinking coffee indoors. +--- + +Recently Terraform [changed licenses](https://www.theregister.com/2023/08/11/hashicorp_bsl_licence/) to the Business Source License. This is a non-free license in the eyes of Nix, so now whenever you update your project flakes, you get greeted by this lovely error: + +``` +error: Package ‘terraform-1.6.2’ in /nix/store/z1nvpjx9vd4151vx2krxzmx2p1a36pf9-source/pkgs/applications/networking/cluster/terraform/default.nix:52 has an unfree license (‘bsl11’), refusing to evaluate. + +a) To temporarily allow unfree packages, you can use an environment variable + for a single invocation of the nix tools. + + $ export NIXPKGS_ALLOW_UNFREE=1 + + Note: For `nix shell`, `nix build`, `nix develop` or any other Nix 2.4+ + (Flake) command, `--impure` must be passed in order to read this + environment variable. + +b) For `nixos-rebuild` you can set + { nixpkgs.config.allowUnfree = true; } + in configuration.nix to override this. + +Alternatively you can configure a predicate to allow specific packages: + { + nixpkgs.config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) [ + "terraform" + ]; + } + +c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add + { allowUnfree = true; } +to ~/.config/nixpkgs/config.nix. +``` + +The extra fun part is that when you're using a flake with a per-project version of nixpkgs, none of those workarounds work. Here's what you have to do instead: + +In your flake you'll usually have an import of nixpkgs like this: + +```nix +let + pkgs = import nixpkgs { inherit system; }; +in + crimes_etc +``` + +Or like this: + +```nix +let + pkgs = nixpkgs.legacyPackages.${system}; +in + different_crimes_etc +``` + +You'll want to change that to this: + +```nix +let + pkgs = import nixpkgs { inherit system; config.allowUnfree = true; }; +in + working_crimes_etc +``` + +This allows you to bypass the license check for all packages in nixpkgs so that things Just Work™. If you want to only do this for terraform, you can make a separate instance of nixpkgs to pull out only terraform, but I think that overall it's probably easier to just eliminate the problem entirely. + +I hope this helps you out! + + + Don't you love the intersection of computers and capitalism? It's the best. + + + Tell me about it. + \ No newline at end of file diff --git a/static/img/asg2023-diagram.svg b/static/img/asg2023-diagram.svg deleted file mode 100644 index 1c0932f..0000000 --- a/static/img/asg2023-diagram.svg +++ /dev/null @@ -1 +0,0 @@ -
Via VS Code/Tailscale SSH
CONTROL
CONTROL
WireGuard
HTTPS
Laptop
VM
Tailscale
Funnel
Audience
\ No newline at end of file -- cgit v1.2.3