babashka 2026-09-25

Workshops aren't streamed/recorded, right?

Hey! Nope, workshops aren't streamed or recorded. Only the AI showcase will be recorded and uploaded afterward.

👍 2

@borkdude with the new bb deps resolution in place, what's the current trick to make it like corporate certs?

✅ 1

set -gx CLJ_JVM_OPTS -Djavax.net.ssl.trustStoreType=KeychainStore
set -gx JAVA_TOOL_OPTIONS -Djavax.net.ssl.trustStoreType=KeychainStore
is what I have been using

it might be pebkac

have you tried passing those to bb itself?

not yet, but will try

possible pebkac, the bb command that fails due to this is executed by the zed editor for clojure-lsp or something similar

hmm no it doens't work from the shell either

you can put stuff in BABASHKA_PRELOADS like settings these properties, perhaps that helps?

oh if it doesn't work from the shell, then that won't help either

perhaps you can write an issue about this and how I might test a possible solution? meanwhile you can use BABASHKA_DEPS_RESOLVER=jvm

I'm not sure how you'd test a possible solution if you aren't on a corp machine that is involved in tls spying via internal certs 😕

LLM suggestion. Worth a shot maybe,..

#!/usr/bin/env bb
(require '[babashka.process :as p]
         '[babashka.fs :as fs])

(def out (str (fs/path (fs/home) ".keychain.p12")))
(def password (char-array "changeit"))

(def pem
  (:out (p/shell {:out :bytes} "security" "find-certificate" "-a" "-p"
                 "/Library/Keychains/System.keychain"
                 "/System/Library/Keychains/SystemRootCertificates.keychain"
                 (str (fs/path (fs/home) "Library/Keychains/login.keychain-db")))))

(def certs
  (.generateCertificates (java.security.cert.CertificateFactory/getInstance "X.509")
                         (java.io.ByteArrayInputStream. pem)))

(def ks (doto (java.security.KeyStore/getInstance "PKCS12")
          (.load nil nil)))

(doseq [[i cert] (map-indexed vector certs)]
  (.setCertificateEntry ks (str "cert-" i) cert))

(with-open [os (java.io.FileOutputStream. out)]
  (.store ks os password))

(println "Wrote" (count certs) "certificates to" out)

Then set this in the shell:

export BABASHKA_PRELOADS='(System/setProperty "javax.net.ssl.trustStore" (str (System/getProperty "user.home") "/.keychain.p12")) (System/setProperty "javax.net.ssl.trustStorePassword" "changeit")'

👍 1

what's the new dep resolver btw?

is it running in the graal process?

(btw switching to the jvm resolver worked in the terminal)

the new dep resolver is running tools.deps from source (interpreted)

in the graal process, yes

I can try picking up on CLJ_JVM_OPTS and JAVA_TOOLS_OPTS and see if I can get something working for your machine that doesn't need any workarounds

I think you had mentioned earlier that this is not trivial with graal because it bakes certs in too early or something?

ah yes I think I found the thread, at the end of which I created https://github.com/babashka/babashka/wiki/Using-custom-certificates

can you try if bb -.ssl.trustStore=$JAVA_HOME/lib/security/cacerts works?

if that works, then I can make that work with BABASHKA_PRELOADS (the order is currently wrong: the deps resolving happens before running the preloads)

everything's cached now

let me see what I need to delete to make it break again

bb -Sforce print-deps --format classpath is what I'm trying to make fail

rm -rf .cpcache/ didn't help

-Sdeps '{:mvn/local-repo "/tmp/dude"}'

bb -.ssl.trustStore=$JAVA_HOME/lib/security/cacerts works!

I'll try fixing it by reading from CLJ_JVM_OPTS

so you don't have to work around anymore

BB_JVM_OPTS perhaps? Not sure which one would be better

probably the BB one

well, deps.clj in bb already respected CLJ_JVM_OPTS when doing the mvn dance via java...

yeah but for clj tools I set CLJ_JVM_OPTS -.ssl.trustStoreType=KeychainStore which doesn't work with BB even with bb -D...

but yeah maybe it would be safer for bb

so I'll need to use a differet one for bb

maybe babashka preloads would still be the right thing then

but it needs to be executed earlier

I kinda like the BB_JVM_OPTS idea. Here are the opts I always want to pass to bb. But I guess a 0-th step preloads is more powerful

the CLJ_JVM_OPTS variable is a fragment that is inserted "as is" when clj start a new JVM bb would have to parse it and set those at runtime which may have a slightly different effect. E.g. I don't know if you can change -Xmx at runtime

what does bb -.ssl.trustStore=$JAVA_HOME/lib/security/cacerts do then?

those options are parsed by the native-image itself

I see so that's before babashka starts, right?

before my code starts, basically

have you built bb locally before?

I'm wondering if there is something like NATIVE_IMAGE_JVM_OPTS that native image picks up

I haven't built it locally no

hmmm that would be the answer to our problems ;)

I think the only way to get that is to wrap bb in another launcher shell script

so BABASHKA_PRELOADS is the most honest option I think

let me link to you a CI binary where you can test this change

when it's done

sure thing, but no rush

looks like there isn't such an env var right now for native image https://github.com/oracle/graal/issues/9504

you are on mac m-series right?

have bb installed via borkdude/brew

follow this build: https://github.com/babashka/babashka/actions/runs/36146042922/job/108107354071?pr=2173 when it's done, download the artifact and try setting the option in BABASHKA_PRELOADS

of course run bb via that download, not your global one :)

seems like it's working:

BABASHKA_PRELOADS='(System/setProperty "javax.net.ssl.trustStore" (str (System/getenv "JAVA_HOME") "/lib/security/cacerts"))' ~/Downloads/bb -Sdeps '{:mvn/local-repo "/tmp/dude2"}' -Sforce print-deps --format classpath
Downloading: org/clojure/clojure/1.12.5/clojure-1.12.5.pom from central
Downloading: org/clojure/spec.alpha/0.5.238/spec.alpha-0.5.238.pom from central
Downloading: org/clojure/core.specs.alpha/0.4.74/core.specs.alpha-0.4.74.pom from central
...

What's BABASHKA_PRELOADS_HOME btw? I saw it mentioned in the pr but it isn't on http://book.babashka.org

it's used in the tests but I'll change that

ah so it isn't for users, right?

So the wiki solution works then, with the new resolver, no changes needed there I guess documentation wise

that's my observation, yes

merged it. if you want you can install the dev build, but perhaps I'll make a new minor release this wee... oh it's already Friday :) well maybe soon

Not urgent, I can wait for it. Thank you!

it's funny that you wrote that page!

didn't realize it until now

you asked me to 🙂

it's a problem I keep facing again and again lol

Is anyone here using BABASHKA_PRELOADS and if so, what are you doing in it? I might change the order when this is executed, before deps fetching. Not sure if that bites anyone, but it lets us set the right JVM properties for certificates etc.

👎 2

@jeroenvandijk @marcobiscaro2112 👎 means "don't do this", or "no, I'm not using it"?

means not using it

👍 1

nice :)

🙏 1
🙌 1