Skip to content

ci: add downstream Nix integration builds - #722

Merged
genebean merged 3 commits into
mainfrom
maintenance/dots-integration-ci
Sep 21, 2026
Merged

genebean merged 3 commits into
mainfrom
maintenance/dots-integration-ci

Conversation

@genebean

@genebean genebean commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Adopt the shared genebean/.github Renovate preset and remove the root configuration that was shadowing it.
  • Keep Renovate updates on Thursday and move the full flake.lock refresh to Friday morning.
  • Pass CI_FLAKE_UPDATES to the shared lock-update workflow so its pull requests can trigger normal CI.
  • Add downstream pull-request builds for nixnuc, hetznix01, and Apple Silicon mightymac.
  • Remove Flox completely, including its flake input, host packages, binary-cache configuration, and lock graph.

CI design

  • Read the locked private-flake revision from flake.lock.
  • Check out that exact revision using the read-only CI_PRIVATE_FLAKE_READ token.
  • Override the flake input with the local checkout during evaluation.
  • Accept the repository's checked-in cache configuration.
  • Retain Determinate Nix. Linux jobs use Magic Nix Cache with FlakeHub disabled, while the macOS job uses the configured upstream caches directly because GitHub consistently throttles the Magic Nix Cache backend there.
  • Build darwinConfigurations.mightymac-ci, which preserves the real host configuration but disables its nested Linux-builder VM closure for pull-request validation.

Scope and security

The builds do not decrypt SOPS secrets, activate Homebrew or MAS, or require Apple credentials. The only new repository credential is narrowly scoped read access to private-flake.

The normal darwinConfigurations.mightymac output remains unchanged and still includes its local Linux builder. Expanded Friday-only coverage for that nested VM, hetznix02, bigboy, and the standalone x86_64 Home Manager configuration is intentionally deferred to a follow-up PR.

Verification

The final branch is verified by:

  • formatting, deadnix, statix, and the restic prune singleton check
  • nixnuc
  • hetznix01
  • mightymac-ci on Apple Silicon

@genebean
genebean force-pushed the maintenance/dots-integration-ci branch from d80af43 to 6815df9 Compare September 20, 2026 20:31
- adopt the shared Renovate preset and schedule lock refreshes after Renovate
- build representative NixOS and nix-darwin configurations on pull requests
- use the pinned private flake with read-only access and configured caches

Co-Authored-By: OpenAI Codex <noreply@openai.com>
@genebean
genebean force-pushed the maintenance/dots-integration-ci branch from 6815df9 to 28f168b Compare September 20, 2026 20:48
genebean and others added 2 commits September 20, 2026 17:18
- remove the Flox flake input and its lock graph
- drop Flox from the macOS and NixOS package sets
- remove the unused Flox binary cache configuration

Co-Authored-By: OpenAI Codex <noreply@openai.com>
Add a dedicated mightymac CI configuration that preserves the real host configuration while disabling its nested Linux builder. Build that target directly against the configured upstream caches because GitHub consistently throttles Magic Nix Cache on the macOS runner.

Co-Authored-By: OpenAI Codex <noreply@openai.com>
@genebean
genebean force-pushed the maintenance/dots-integration-ci branch from 4fae66e to 43e0520 Compare September 20, 2026 23:35
@genebean
genebean merged commit 3e8fe17 into main Sep 21, 2026
5 checks passed
@genebean
genebean deleted the maintenance/dots-integration-ci branch September 21, 2026 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant