Skip to content

Latest commit

 

History

7 Commits

Folders and files

Repository files navigation

psibase-nix

NixOS module and runtime package for psibase. NixOS, x86_64-linux only.

This is the operator surface. The contributor nix develop shell stays in the psibase repo.

  • packages.psibase — psinode / psibase / psitest plus share/psibase, patchelf’d from the published Ubuntu 24.04 psidk tarball. Does not build from source.
  • nixosModules.psibase — services.psibase, a hardened systemd unit.

NixOS module

# flake.nix (your NixOS host, e.g. psinix)
{
  inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
  inputs.psibase-nix.url = "github:gofractally/psibase-nix";
  inputs.psibase-nix.inputs.nixpkgs.follows = "nixpkgs";

  outputs = { nixpkgs, psibase-nix, ... }: {
    nixosConfigurations.myhost = nixpkgs.lib.nixosSystem {
      system = "x86_64-linux";
      modules = [
        psibase-nix.nixosModules.psibase
        {
          services.psibase = {
            enable = true;
            host = "psibase.example.com";
            listen = 8090;
            producer = "prod"; # omit for a non-producing node
            p2p = true;
            databaseCacheSize = "2GiB";
          };
        }
      ];
    };
  };
}
sudo nixos-rebuild switch --flake .#myhost

Service runs psinode as user psibase under /var/lib/psibase/db. Boot a new chain once the service is up:

psibase boot -a http://HOST:PORT -p prod

-a/--api is a subcommand argument, not a global one. It defaults to http://psibase.localhost:8080/ and also reads PSINODE_URL.

Not handled by this module

TLS and reverse proxy are yours. For a full NixOS host that puts Caddy in front of psinode, see velua/psinix. psinode listens on 127.0.0.1 by default. If a remote proxy connects directly to psinode:

services.psibase = {
  listenAddress = "0.0.0.0";
  openFirewall = true;
};

SoftHSM / block production

With softHsm.enable = true the module writes a SoftHSM config pointing at a persistent token directory, runs a oneshot that initializes the token once from pinFile, and starts psinode with --pkcs11-module=…/libsofthsm2.so.

pinFile must be a runtime path string (e.g. sops), not a Nix path literal:

({ config, ... }: {
  services.psibase.softHsm = {
    enable = true;
    pinFile = config.sops.secrets.softhsm_pin.path;
  };
})

After every psinode restart, unlock the HSM in x-admin before the node can sign blocks.

Package

nix build .#psibase

Layout contract: $out/{bin,share/psibase}. Any derivation producing that layout can be substituted via services.psibase.package.

Pinning a psibase release (follows)

The runtime bits come from flake input psibase (the GitHub release tarball; the asset is named psidk-*.tar.gz). This repo’s lock is only a default. A host flake such as psinix should follow its own pin so a new psibase cut does not require a psibase-nix commit:

{
  inputs.psibase-nix.url = "github:gofractally/psibase-nix";
  inputs.psibase-nix.inputs.nixpkgs.follows = "nixpkgs";

  inputs.psibase = {
    url = "https://github.com/gofractally/psibase/releases/download/v0.27.0-pre/psidk-ubuntu-2404.tar.gz";
    flake = false;
  };
  inputs.psibase-nix.inputs.psibase.follows = "psibase";
}

nix flake lock records the tarball hash. To move to a new release, change the psibase URL in the host flake and run nix flake update psibase.

nixpkgs.follows is the same idea for nixpkgs: one copy, the host’s pin, no extra lock fight.

Tests

nix build .#checks.x86_64-linux.module-eval    # module + assertions (seconds)
nix build .#checks.x86_64-linux.overlay-eval   # overlay resolves against nixpkgs
nix build .#checks.x86_64-linux.vm             # boots a node with SoftHSM (minutes)
nix flake check                                # all of the above

vm boots SoftHSM + an unsigned ProdDefault chain under the systemd sandbox. Not covered: signed/production boot, HSM unlock/signing, real p2p peers.

nix fmt

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages