Skip to content

Commit 925479d

Browse files
stackptrclaude
andauthored
Enable golink OAuth authentication on spore (#344)
* feat(spore): use apoxy-dev golink fork with OAuth key support Switch golink input from tailscale/golink to the apoxy-dev fork (dilyevsky/tsnet-1.90-upgrade branch) to enable OAuth key authentication, which is not yet available upstream. See: tailscale/golink#210 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * feat(spore): update tailscale auth key to OAuth client secret Replace expiring Tailscale auth key with a non-expiring OAuth client secret for golink authentication. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(spore): override golink vendorHash for apoxy-dev fork The apoxy-dev fork has a stale vendorHash in its flake.nix. Add a local overlay to fix it, and reorder NixOS modules so the golink overlay is applied before ours. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(spore): override golink goModules hash instead of vendorHash vendorHash is consumed by buildGoModule to create a separate fixed-output derivation, so overrideAttrs doesn't reach it. Override goModules.outputHash directly. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(spore): rebuild golink package with correct vendorHash overrideAttrs can't reach vendorHash since it's consumed by buildGoModule before derivation creation. Rebuild the package from scratch using the same source and ldflags. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(spore): set golink package directly to fix vendorHash The golink flake's overlay always overwrites pkgs.golink with its own pre-built package, making overlay-based overrides ineffective. Set services.golink.package directly with the correct vendorHash. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
1 parent 9057b36 commit 925479d

4 files changed

Lines changed: 18 additions & 12 deletions

File tree

‎flake.lock‎

Lines changed: 6 additions & 5 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎flake.nix‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@
3939
inputs.nixpkgs.follows = "nixpkgs";
4040
};
4141
golink = {
42-
url = "github:tailscale/golink";
42+
url = "github:apoxy-dev/golink/dilyevsky/tsnet-1.90-upgrade";
4343
inputs.nixpkgs.follows = "nixpkgs";
4444
inputs.systems.follows = "systems";
4545
};
Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
age-encryption.org/v1
2-
-> ssh-ed25519 2AxgaQ Bml5zq38B3BTWMtQ8jDplWdAb/KRYeHInY+ON6Vr80I
3-
P+uTPP3Xul0eMo5tMu4A6nwhFAhBmoVwoN0k/QnoUxw
4-
-> ssh-ed25519 3EWhnQ qKFgwRZ0Aj8UBm4Ti2qtQqdZku6y4gd29Lqfg9aoLnM
5-
wQ/rJ5aTJBbM+DMHR8eWiLrLXxYRMxMnQVs+yk4UvTI
6-
--- VMe18Za/KOH7wECyAiwcYfvpsyjAE/oo1nCsW7umrvw
7-
g��C��,��I��S�ø���c6� P�ϻ�(�� F<�P���Ň����h��٫n���hFm]>���u�*m�+����TL�W�.�r�����YP
2+
-> ssh-ed25519 2AxgaQ nZxoKnnhBN/Vu5ChV+cvH/+/QtoACBB5EdMeRHfTExY
3+
0//vPZFL/tECbRHROmZ4rLK6ZGKwfmFFBPIpIZdLcOk
4+
-> ssh-ed25519 3EWhnQ 6y7+yYJFVby7SLWf/1ngX7LxIyhASKzqLlo75vVkylc
5+
wcX9MumA4EF9W0dHE/KnHIbDU2b5C4HsdWe9q2sO8+Q
6+
--- r/2H19LwRcmRGfyIVrLDDxGKN2rKFLmkD1BTRyNL3uU
7+
BWL�E$�0og�ƿ��+�j8�FȤ�"�AS�2�IC�I�ƅ�0��p\�����)j��9�@e���ks[�X����H�쬋�ӽ*O��x��

‎hosts/spore/services/default.nix‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,11 @@
3131
services.golink = {
3232
enable = true;
3333
tailscaleAuthKeyFile = config.age.secrets.tailscale-auth-key.path;
34+
package = pkgs.buildGo125Module {
35+
pname = "golink";
36+
inherit (pkgs.golink) version src ldflags;
37+
vendorHash = "sha256-M3Qm25KF6gWtp3K1SigLucgrIJ+5KokMq+Bp7XXaE+o=";
38+
};
3439
};
3540

3641
services.openssh.enable = true;

0 commit comments

Comments
 (0)