diff --git a/ansible/tasks/stage2-setup-postgres.yml b/ansible/tasks/stage2-setup-postgres.yml index 1a2bd9d9e..4e8176f64 100644 --- a/ansible/tasks/stage2-setup-postgres.yml +++ b/ansible/tasks/stage2-setup-postgres.yml @@ -57,17 +57,20 @@ when: stage2 become: true block: - - name: Install packages from nix binary cache + - name: Resolve postgres env store path ansible.builtin.shell: | - sudo -u postgres bash -c ". /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && nix profile install github:supabase/postgres/{{ git_commit_sha }}#{{ nix_item }}" - loop: - - "{{ psql_version }}/bin" - - pg_prove - - supabase-groonga - - "{{ postgresql_version }}_debug" - - "{{ postgresql_version }}_src" - loop_control: - loop_var: 'nix_item' + sudo -u postgres bash -c " + . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && + nix build --no-link --print-out-paths github:supabase/postgres/{{ git_commit_sha }}#postgres-env-{{ postgresql_major_version }} + " + register: postgres_env_path + + - name: Install postgres env from nix binary cache + ansible.builtin.shell: | + sudo -u postgres bash -c " + . /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && + nix-env --set {{ postgres_env_path.stdout }} + " - name: Install supascan for baseline validation ansible.builtin.shell: | @@ -127,11 +130,6 @@ - name: Install gatekeeper if not pg15 when: stage2 and not is_psql_15 block: - - name: Install gatekeeper from nix binary cache - become: yes - shell: | - sudo -u postgres bash -c ". /nix/var/nix/profiles/default/etc/profile.d/nix-daemon.sh && nix profile install github:supabase/postgres/{{ git_commit_sha }}#gatekeeper" - - name: Create symbolic link for linux-pam to find pam_jit_pg.so become: yes shell: | diff --git a/ansible/vars.yml b/ansible/vars.yml index 43cac8c07..c46b9d666 100644 --- a/ansible/vars.yml +++ b/ansible/vars.yml @@ -11,9 +11,9 @@ postgres_major: # This is the source of truth for Postgres versions used in the Dockerfiles, and # is used to derive image tags and base images in the release matrix. postgres_release: - postgresorioledb-17: "17.9.0.011-orioledb" - postgres17: "17.6.1.158" - postgres15: "15.14.1.158" + postgresorioledb-17: "17.9.0.15799999-orioledb" + postgres17: "17.6.1.15799999" + postgres15: "15.14.1.15799999" # Docker release matrix — base images built first, layered images built on top. # tag and base_tag are derived at build time from postgres_release via release_key. # tag_suffix is appended to the release version to form the final image tag. diff --git a/nix/packages/default.nix b/nix/packages/default.nix index c3b1ae012..c3bbea579 100644 --- a/nix/packages/default.nix +++ b/nix/packages/default.nix @@ -1,6 +1,9 @@ { self, inputs, ... }: { - imports = [ ./postgres.nix ]; + imports = [ + ./postgres.nix + ./postgres-env.nix + ]; perSystem = { inputs', diff --git a/nix/packages/postgres-env.nix b/nix/packages/postgres-env.nix new file mode 100644 index 000000000..022944021 --- /dev/null +++ b/nix/packages/postgres-env.nix @@ -0,0 +1,33 @@ +{ + perSystem = + { + lib, + pkgs, + self', + ... + }: + let + # Bundles everything the AMI build installs into the postgres user's nix + # profile (via `nix-env --set`) into a single derivation. + makePostgresEnv = + version: + pkgs.symlinkJoin { + name = "postgres-env-${version}"; + paths = [ + self'.packages."psql_${version}/bin" + self'.packages.pg_prove + self'.packages.supabase-groonga + self'.packages."postgresql_${version}_src" + ] + ++ lib.optionals pkgs.stdenv.isLinux [ self'.packages."postgresql_${version}_debug" ] + ++ lib.optionals (pkgs.stdenv.isLinux && version != "15") [ self'.packages.gatekeeper ]; + }; + in + { + packages = { + postgres-env-15 = makePostgresEnv "15"; + postgres-env-17 = makePostgresEnv "17"; + postgres-env-orioledb-17 = makePostgresEnv "orioledb-17"; + }; + }; +}