How I deploy Haskell Code
alfredodinapoli.com
alfredodinapoli.com
I'd be curious to hear if there's a convenient way to build an entirely statically linked GHC binary. I've searched around some but haven't found an easy answer yet.
https://www.reddit.com/r/haskell/comments/3kjpwe/how_to_easi...
If you smuggle unpackaged code onto a QA or build machine, IMHO you asked for whatever happens to you.
I don't think nixpkgs is a direct solution to this problem though.
(A) Sometimes you're stuck with cabal-install because the rest of the people in the project use it. Nixpkgs includes many different sets of haskell packages, but isn't designed to pull in arbitrary versions of lots of different haskell packages by default.
(B) Even if the rest of the team was using a set of haskell packages compatible with one of the Nixpkgs sets, it still involves extra work to figure out what C libraries the computer you're deploying to has, and then to make sure they're packaged for Nixpkgs and build with them.
I think Nixpkgs and NixOS are _fantastic_ tools, but they aren't a panacea for all haskell deployment solutions.
Towards the second point, nix isn't meant to figure out what C libraries you need; it's meant to let you specify exactly what those are and be confident that those will be respected.
If you can get them to deploy anything you want without them needing to know what is inside of it... your ops team is too trusting, in my opinion.
That's probably specific to your organization.
PenTests and security is a pretty different thing than app dev. And both are different than ops. Only recently have the roles been blurred, but even now, I see truly cross-functional people very rarely.