From e1d9fce7e455363d1e27c7c5a643291fc4626d17 Mon Sep 17 00:00:00 2001 From: AmrikSD Date: Mon, 5 Oct 2026 18:50:08 +0100 Subject: [PATCH] feat(onboard): make setup work on networks that intercept TLS --- projects/onboard/README.md | 2 ++ projects/onboard/setup.sh | 22 ++++++++++++++++++++++ 2 files changed, 24 insertions(+) diff --git a/projects/onboard/README.md b/projects/onboard/README.md index 41067208..b3196c7e 100644 --- a/projects/onboard/README.md +++ b/projects/onboard/README.md @@ -17,6 +17,8 @@ git clone https://github.com/AmrikSD/code ~/code/AmrikSD/code Then open a new terminal. +On a network that intercepts TLS and sets `SSL_CERT_FILE`, as some company laptops do, `setup.sh` first builds a certificate store from that file and points Bazel at it in `~/.bazelrc`. Bazel cannot download anything there otherwise. + Before you start, on a Mac: install the 1Password app, sign in, and turn on "Integrate with 1Password CLI" in its Developer settings. The GPG key and the work secrets are read from it. Without it the setup still finishes, and re-running it later picks them up. ## Enjoy diff --git a/projects/onboard/setup.sh b/projects/onboard/setup.sh index 62478585..c5e12294 100755 --- a/projects/onboard/setup.sh +++ b/projects/onboard/setup.sh @@ -14,5 +14,27 @@ if ! command -v nix >/dev/null; then . "$nix_profile" fi +# Bazel's JVM ignores SSL_CERT_FILE. Where that is set because the network +# intercepts TLS, every Bazel download fails until the JVM is given the same +# certificates as a truststore. +if [ -n "${SSL_CERT_FILE:-}" ] && ! grep -qs 'javax.net.ssl.trustStore=' "$HOME/.bazelrc"; then + store="$HOME/.cache/bazel-truststore.p12" + if [ ! -e "$store" ]; then + echo "Building a certificate store for Bazel from $SSL_CERT_FILE" + mkdir -p "$(dirname "$store")" + certs=$(mktemp -d) + awk -v dir="$certs" '/BEGIN CERTIFICATE/ { if (out) close(out); out = dir "/" ++n ".pem" } out { print > out }' "$SSL_CERT_FILE" + nix shell nixpkgs#jdk --command bash -c ' + for cert in "$1"/*.pem; do + keytool -importcert -noprompt -alias "$(basename "$cert" .pem)" -file "$cert" \ + -keystore "$2" -storetype PKCS12 -storepass changeit >/dev/null 2>&1 + done' truststore "$certs" "$store" + fi + { + echo "startup --host_jvm_args=-Djavax.net.ssl.trustStore=$store" + echo "startup --host_jvm_args=-Djavax.net.ssl.trustStorePassword=changeit" + } >> "$HOME/.bazelrc" +fi + exec nix shell nixpkgs#bazelisk nixpkgs#gh nixpkgs#git --command \ bazelisk run //projects/onboard/cmd/onboard -- "$@"