Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions nixos/doc/manual/release-notes/rl-2611.section.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,11 @@

- `boot.vesa` has been removed. It was deprecated in 2020 because Xorg now works better with kernel modesetting. If you still need the legacy VESA 800x600 fallback, set `boot.kernelParams = [ "vga=0x317" "nomodeset" ];` directly.

- `authentik` has been updated to 2026.5.3, which changes the default listen address from `0.0.0.0` to `[::]`.
IPv4-only deployments might need to adjust their listen settings.
Deployments running the server and worker in the same network namespace must also set at least the worker
`AUTHENTIK_LISTEN__HTTP` address so that the server and worker do not bind to the same address.

Comment thread
LisaScheers marked this conversation as resolved.
- Support for the legacy U‐Boot image format has been removed from the initrd generators, as it is deprecated upstream and no longer used by any platform in Nixpkgs.

- Rustical migrates from `settings.http.host` and `settings.http.port` to `settings.http.bind` to support UNIX domain sockets as well as TCP sockets in one setting.
Expand Down
9 changes: 0 additions & 9 deletions pkgs/by-name/au/authentik/client-go-config.patch

This file was deleted.

185 changes: 67 additions & 118 deletions pkgs/by-name/au/authentik/package.nix
Original file line number Diff line number Diff line change
Expand Up @@ -3,14 +3,19 @@
stdenvNoCC,
callPackages,
cacert,
clangStdenv,
cmake,
fetchFromGitHub,
buildGoModule,
buildNpmPackage,
bash,
chromedriver,
nodejs_24,
python3,
python314,
Comment thread
LisaScheers marked this conversation as resolved.
makeWrapper,
openapi-generator-cli,
perl,
rustPlatform,
go,
typescript,
makeSetupHook,
Expand All @@ -20,13 +25,18 @@
let
nodejs = nodejs_24;

version = "2025.12.6";
version = "2026.5.3";

cargoPackageFlags = [
"--package"
"authentik"
];

src = fetchFromGitHub {
owner = "goauthentik";
repo = "authentik";
tag = "version/${version}";
hash = "sha256-uIg47z4LaCawF/5ir4mKE6DpDnEpQ8DuObCNaq6TcYk=";
hash = "sha256-nmAX8nwZpdDcFAPvC9hAEp0x43RnFtGLUTAm7NcvNZo=";
};

meta = {
Expand All @@ -46,24 +56,9 @@ let

client-go = stdenvNoCC.mkDerivation {
pname = "authentik-client-go";
version = "3.${version}";
inherit meta;

src = fetchFromGitHub {
owner = "goauthentik";
repo = "client-go";
tag = "v3.2025.12.4";
hash = "sha256-+/CfOE2HkBU+ZddvdXGenB/z8xNFk8cujpZpMXyh3cY=";
};

patches = [
./client-go-config.patch
];
inherit version src meta;

postPatch = ''
substituteInPlace ./config.yaml \
--replace-fail '/local' "$(pwd)"
'';
sourceRoot = "${src.name}/packages/client-go";

nativeBuildInputs = [
openapi-generator-cli
Expand All @@ -86,10 +81,9 @@ let
installPhase = ''
runHook preInstall

cp go.mod go.sum $out

cd $out
rm -rf test
rm -f go.mod go.sum
rm -f .travis.yml git_push.sh

runHook postInstall
Expand All @@ -101,8 +95,8 @@ let
inherit version src meta;

postPatch = ''
substituteInPlace ./scripts/api/ts-config.yaml \
--replace-fail '/local' "$(pwd)"
substituteInPlace ./packages/client-ts/config.yaml \
--replace-fail '/local' "$(pwd)/packages/client-ts"
'';

nativeBuildInputs = [
Expand All @@ -117,7 +111,7 @@ let
openapi-generator-cli generate \
-i ./schema.yml -o $out \
-g typescript-fetch \
-c ./scripts/api/ts-config.yaml \
-c ./packages/client-ts/config.yaml \
--additional-properties=npmVersion=${version} \
--git-repo-id authentik --git-user-id goauthentik

Expand All @@ -128,32 +122,19 @@ let
'';
};

# prefetch-npm-deps does not save all dependencies even though the lockfile is fine
website-deps = stdenvNoCC.mkDerivation {
website-deps = buildNpmPackage {
pname = "authentik-website-deps";
inherit src version meta;

sourceRoot = "${src.name}/website";

outputHash =
{
"aarch64-linux" = "sha256-EbLneRDCyLLLBOZ2DUDpf2TbZoTL8QMXP4WlAZEzS90=";
"x86_64-linux" = "sha256-yDjwN/+lX2i9WYDXq4yWwf9o8nA4342iHDDQH4Jt7eQ=";
}
.${stdenvNoCC.hostPlatform.system} or (throw "authentik-website-deps: unsupported host platform");

outputHashMode = "recursive";

nativeBuildInputs = [
nodejs
cacert
];

buildPhase = ''
npm ci --cache ./cache

rm -r ./cache node_modules/.package-lock.json
'';
inherit nodejs;
npmDepsHash = "sha256-SkIZF+wQPgoZOGJc0YR8Ot07KCsAdA1985SLQaoibfA=";
npmDepsFetcherVersion = 2;
makeCacheWritable = true;
npmInstallFlags = [ "--legacy-peer-deps" ];
npmRebuildFlags = [ "--ignore-scripts" ];
dontNpmBuild = true;

# dependencies of workspace projects are installed into separate node_modules folders with
# symlinks between them, so we have to copy all of them
Expand Down Expand Up @@ -208,8 +189,8 @@ let

outputHash =
{
"aarch64-linux" = "sha256-J9wGQe7iMfKznNk3woqi0VNVNA/dE6TGi2f44DOlG1c=";
"x86_64-linux" = "sha256-9Q590Rw0mk3q5osxOKGWU7+XtKwkTyA+CLC2LxAA/3g=";
"aarch64-linux" = "sha256-41xZEfLul92vJATZqyVnd7Pp++NzLL/u8NeJJPHpXrw=";
"x86_64-linux" = "sha256-FpfOl6wNCgXLg86+vbjnYkcOnpaOZBCNxJiFDRT5W3s=";
}
.${stdenvNoCC.hostPlatform.system} or (throw "authentik-webui-deps: unsupported host platform");
outputHashMode = "recursive";
Expand All @@ -220,6 +201,7 @@ let
];

buildPhase = ''
chmod -R +w . ../packages/client-ts
npm ci --cache ./cache --ignore-scripts

rm -r ./cache node_modules/.package-lock.json
Expand Down Expand Up @@ -295,7 +277,7 @@ let
];
};

python = python3.override {
python = python314.override {
self = python;
packageOverrides = final: prev: {
# https://github.com/goauthentik/authentik/pull/16324
Expand Down Expand Up @@ -376,62 +358,6 @@ let
];
};

# Running authentik currently requires a custom version.
# Look in `pyproject.toml` for changes to the rev in the `[tool.uv.sources]` section.
# See https://github.com/goauthentik/authentik/pull/14057 for latest version bump.
djangorestframework = final.buildPythonPackage {
pname = "djangorestframework";
version = "3.16.0";
format = "setuptools";

src = fetchFromGitHub {
owner = "authentik-community";
repo = "django-rest-framework";
rev = "896722bab969fabc74a08b827da59409cf9f1a4e";
hash = "sha256-YrEDEU3qtw/iyQM3CoB8wYx57zuPNXiJx6ZjrIwnCNU=";
};

propagatedBuildInputs = with final; [
django
pytz
];

nativeCheckInputs = with final; [
pytest-django
pytest7CheckHook

# optional tests
coreapi
django-guardian
inflection
pyyaml
uritemplate
];

disabledTests = [
"test_ignore_validation_for_unchanged_fields"
"test_invalid_inputs"
"test_shell_code_example_rendering"
"test_unique_together_condition"
"test_unique_together_with_source"
];

pythonImportsCheck = [ "rest_framework" ];
};

# authentik is currently not compatible with v1.18 and fails with the following error:
# > AttributeError: 'Namespace' object has no attribute 'worker_fork_timeout'. Did you mean: 'worker_shutdown_timeout'?
dramatiq = prev.dramatiq.overrideAttrs (_: rec {
version = "1.17.1";

src = fetchFromGitHub {
owner = "Bogdanp";
repo = "dramatiq";
tag = "v${version}";
hash = "sha256-NeUGhG+H6r+JGd2qnJxRUbQ61G7n+3tsuDugTin3iJ4=";
};
});

authentik-django = final.buildPythonPackage {
pname = "authentik-django";
inherit version src meta;
Expand Down Expand Up @@ -548,7 +474,32 @@ let

inherit (python.pkgs) authentik-django;

# Provide a setup-hook to configure the Go vendor directory with up-to-date API bindings.
worker = (rustPlatform.buildRustPackage.override { stdenv = clangStdenv; }) {
pname = "authentik-worker";
inherit version src meta;

cargoHash = "sha256-KExlNyT9G3R5rnt99beT2pYrWxezMLhGw+Q9T1X2kj4=";

nativeBuildInputs = [
cmake
go
perl
];

buildInputs = [ python ];

env = {
PYO3_PYTHON = lib.getExe python;
RUSTFLAGS = "--cfg tokio_unstable";
};

cargoBuildFlags = cargoPackageFlags;

# Upstream currently has no Rust tests in this package.
doCheck = false;
};

# Provide a setup-hook to configure the Go source tree with up-to-date API bindings.
# This is done to avoid the `vendorHash` depending on anything in the `client-go` build (e.g.
# openapi-generator-cli version updates changing the produced content) and invalidating the hash.
apiGoVendorHook =
Expand All @@ -559,9 +510,10 @@ let
(
writeShellScript "authentik-api-go-vendor-hook" ''
authentikApiGoVendorHook() {
chmod -R +w vendor/goauthentik.io/api
rm -rf vendor/goauthentik.io/api/v3
cp -r ${client-go} vendor/goauthentik.io/api/v3
chmod -R +w packages/client-go
rm -rf packages/client-go
cp -r ${client-go} packages/client-go
Comment thread
LisaScheers marked this conversation as resolved.
chmod -R +w packages/client-go

echo "Finished authentikApiGoVendorHook"
}
Expand Down Expand Up @@ -593,10 +545,11 @@ let
# calculate the vendorHash without other dependencies, so it is only based on the `go.sum` file
overrideModAttrs.postPatch = "";

vendorHash = "sha256-pdQg02f1K4nOhsnadoplQYOhEybqZxn+yDQRN5RNygM=";
vendorHash = "sha256-EVDOZ4USaJoIBDB8mM4ZSBfsSc1d/NOm1Qv/hUJ+8f4=";

postInstall = ''
mv $out/bin/server $out/bin/authentik
mv $out/bin/server $out/bin/authentik-server
Comment thread
LisaScheers marked this conversation as resolved.
ln -s authentik-server $out/bin/authentik
'';

subPackages = [ "cmd/server" ];
Expand All @@ -612,11 +565,6 @@ stdenvNoCC.mkDerivation {
postPatch = ''
rm Makefile
patchShebangs lifecycle/ak

# This causes issues in systemd services
substituteInPlace lifecycle/ak \
--replace-fail 'printf' '>&2 printf' \
--replace-fail '>/dev/stderr' ""
'';

installPhase = ''
Expand All @@ -627,8 +575,9 @@ stdenvNoCC.mkDerivation {
wrapProgram $out/bin/ak \
--prefix PATH : ${
lib.makeBinPath [
(python.withPackages (ps: [ ps.authentik-django ]))
worker
proxy
(python.withPackages (ps: [ ps.authentik-django ]))
]
} \
--set TMPDIR /dev/shm \
Expand All @@ -638,7 +587,7 @@ stdenvNoCC.mkDerivation {
'';

passthru = {
inherit proxy apiGoVendorHook;
inherit proxy worker apiGoVendorHook;
outposts = callPackages ./outposts.nix {
inherit (proxy) vendorHash;
inherit apiGoVendorHook;
Expand Down
Loading