Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions projects/onboard/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,8 @@ git clone https://github.com/AmrikSD/code ~/code/AmrikSD/code

Then open a new terminal.

On a network that intercepts TLS and sets `SSL_CERT_FILE`, as some company laptops do, `setup.sh` first builds a certificate store from that file and points Bazel at it in `~/.bazelrc`. Bazel cannot download anything there otherwise.

Before you start, on a Mac: install the 1Password app, sign in, and turn on "Integrate with 1Password CLI" in its Developer settings. The GPG key and the work secrets are read from it. Without it the setup still finishes, and re-running it later picks them up.

## Enjoy
Expand Down
22 changes: 22 additions & 0 deletions projects/onboard/setup.sh
Original file line number Diff line number Diff line change
Expand Up @@ -14,5 +14,27 @@ if ! command -v nix >/dev/null; then
. "$nix_profile"
fi

# Bazel's JVM ignores SSL_CERT_FILE. Where that is set because the network
# intercepts TLS, every Bazel download fails until the JVM is given the same
# certificates as a truststore.
if [ -n "${SSL_CERT_FILE:-}" ] && ! grep -qs 'javax.net.ssl.trustStore=' "$HOME/.bazelrc"; then
store="$HOME/.cache/bazel-truststore.p12"
if [ ! -e "$store" ]; then
echo "Building a certificate store for Bazel from $SSL_CERT_FILE"
mkdir -p "$(dirname "$store")"
certs=$(mktemp -d)
awk -v dir="$certs" '/BEGIN CERTIFICATE/ { if (out) close(out); out = dir "/" ++n ".pem" } out { print > out }' "$SSL_CERT_FILE"
nix shell nixpkgs#jdk --command bash -c '
for cert in "$1"/*.pem; do
keytool -importcert -noprompt -alias "$(basename "$cert" .pem)" -file "$cert" \
-keystore "$2" -storetype PKCS12 -storepass changeit >/dev/null 2>&1
done' truststore "$certs" "$store"
fi
{
echo "startup --host_jvm_args=-Djavax.net.ssl.trustStore=$store"
echo "startup --host_jvm_args=-Djavax.net.ssl.trustStorePassword=changeit"
} >> "$HOME/.bazelrc"
fi

exec nix shell nixpkgs#bazelisk nixpkgs#gh nixpkgs#git --command \
bazelisk run //projects/onboard/cmd/onboard -- "$@"
Loading