fix(nix): pass NODE_EXTRA_CA_CERTS through to bun in node_modules build#18405
Open
HacknBashe wants to merge 2 commits intoanomalyco:devfrom
Open
fix(nix): pass NODE_EXTRA_CA_CERTS through to bun in node_modules build#18405HacknBashe wants to merge 2 commits intoanomalyco:devfrom
HacknBashe wants to merge 2 commits intoanomalyco:devfrom
Conversation
Contributor
|
Thanks for your contribution! This PR doesn't have a linked issue. All PRs must reference an existing issue. Please:
See CONTRIBUTING.md for details. |
Contributor
|
Thanks for updating your PR! It now meets our contributing guidelines. 👍 |
86855e4 to
c16b605
Compare
Corporate environments with TLS inspection proxies cause bun to fail with SELF_SIGNED_CERT_IN_CHAIN during the node_modules build. NIX_SSL_CERT_FILE is already passed through via proxyImpureEnvVars, but bun only reads NODE_EXTRA_CA_CERTS. This bridges the two in the build phase so no external daemon configuration is needed.
Remove comments about bridging NIX_SSL_CERT_FILE to NODE_EXTRA_CA_CERTS.
3e74a90 to
3f8a32d
Compare
Author
|
I think my opencode agent requested this review? Not sure why you were pinged adam, sorry |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue for this PR
Closes #18407
Type of change
What does this PR do?
Adds
NODE_EXTRA_CA_CERTStoimpureEnvVarsin the node_modules fixed-output derivationCorporate environments with TLS inspection proxies inject their own CA certificates into the chain. This causes bun to fail with
SELF_SIGNED_CERT_IN_CHAINwhen fetching GitHub tarballs (e.g.ghostty-web) during the nix build.lib.fetchers.proxyImpureEnvVarsalready includesNIX_SSL_CERT_FILE, but bun ignores that and only readsNODE_EXTRA_CA_CERTS. Without it inimpureEnvVars, there's no way to pass a custom CA bundle through to bun in the sandboxed build.How did you verify your code works?
No longer see self signed cert error when building my nix flake against my local opencode repo with this change.
Screenshots / recordings
old error that is gone
===
Checklist
If you do not follow this template your PR will be automatically rejected.