diff --git a/ansible/tasks/stage2-setup-postgres.yml b/ansible/tasks/stage2-setup-postgres.yml index 3019fa829..d4823238a 100644 --- a/ansible/tasks/stage2-setup-postgres.yml +++ b/ansible/tasks/stage2-setup-postgres.yml @@ -62,17 +62,20 @@ when: stage2 become: true block: - - name: Install packages from nix binary cache + - name: Resolve postgres env store path ansible.builtin.shell: | - sudo -u postgres bash -c ". /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && nix profile install github:supabase/postgres/{{ git_commit_sha }}#{{ nix_item }}" - loop: - - "{{ psql_version }}/bin" - - pg_prove - - supabase-groonga - - "{{ postgresql_version }}_debug" - - "{{ postgresql_version }}_src" - loop_control: - loop_var: 'nix_item' + sudo -u postgres bash -c " + . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && + nix build --no-link --print-out-paths github:supabase/postgres/{{ git_commit_sha }}#postgres-env-{{ postgresql_major_version }} + " + register: postgres_env_path + + - name: Install postgres env from nix binary cache + ansible.builtin.shell: | + sudo -u postgres bash -c " + . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && + nix-env --set {{ postgres_env_path.stdout }} + " - name: Install supascan for baseline validation ansible.builtin.shell: | @@ -132,11 +135,6 @@ - name: Install gatekeeper if not pg15 when: stage2 and not is_psql_15 block: - - name: Install gatekeeper from nix binary cache - become: yes - shell: | - sudo -u postgres bash -c ". /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && nix profile install github:supabase/postgres/{{ git_commit_sha }}#gatekeeper" - - name: Create symbolic link for linux-pam to find pam_jit_pg.so become: yes shell: | diff --git a/nix/packages/default.nix b/nix/packages/default.nix index dc6268b3a..a7f70338b 100644 --- a/nix/packages/default.nix +++ b/nix/packages/default.nix @@ -2,6 +2,7 @@ { imports = [ ./postgres.nix + ./postgres-env.nix ./site-env.nix ]; diff --git a/nix/packages/postgres-env.nix b/nix/packages/postgres-env.nix new file mode 100644 index 000000000..7c4153f2b --- /dev/null +++ b/nix/packages/postgres-env.nix @@ -0,0 +1,33 @@ +{ + perSystem = + { + lib, + pkgs, + self', + ... + }: + let + # Make a bundle of packages, as a single derivation, to be installed into the + # postgres user's nix profile, during image provisioning or instance update. + makePostgresEnv = + version: + pkgs.symlinkJoin { + name = "postgres-env-${version}"; + paths = [ + self'.packages."psql_${version}/bin" + self'.packages.pg_prove + self'.packages.supabase-groonga + self'.packages."postgresql_${version}_src" + ] + ++ lib.optionals pkgs.stdenv.isLinux [ self'.packages."postgresql_${version}_debug" ] + ++ lib.optionals (pkgs.stdenv.isLinux && version != "15") [ self'.packages.gatekeeper ]; + }; + in + { + packages = { + postgres-env-15 = makePostgresEnv "15"; + postgres-env-17 = makePostgresEnv "17"; + postgres-env-orioledb-17 = makePostgresEnv "orioledb-17"; + }; + }; +}