ci(forgejo): run Nix jobs host-mode on bismuth with a warm store #1

Open
arcuru-bot wants to merge 1 commit from arcuru-bot/eidetica:ci/forgejo-host-mode into main
First-time contributor

What

Converts the Forgejo Nix CI from per-job nixos/nix containers to a host-mode runner on bismuth, so all 7 jobs share one warm /nix/store instead of re-substituting the full closure 7× per push.

Changes:

  • .forgejo/workflows/nix.yml — drop container:, target runs-on: bismuth, remove the per-job nix-env -iA nixpkgs.nodejs step, and install nix-fast-build from the flake (.#nix-fast-build) instead of the unpinned channel.
  • .forgejo/scripts/setup-nix.sh — re-enable the build sandbox, add bismuth's nix-serve (http://bismuth:5000) as the top-priority substituter with its public key.
  • flake.nix — expose nix-fast-build as a package output so CI can pin it.

⚠️ Workflow files

This PR changes .forgejo/workflows/nix.yml and .forgejo/scripts/setup-nix.sh. Merging is the moment they go live.

Not yet verified — needs the host runner

This can't be run until bismuth has a host-mode runner. Before/after merging:

  1. Install Nix natively on bismuth, plus nodejs (for the JS checkout action).
  2. Register a Forgejo runner with the bismuth label — or change the runs-on: line to whatever label you register.
  3. Add a /nix/store GC policy. Persistence is the point of host mode; without a GC policy a home machine fills its disk.

Verification: a green run in host mode, then a second consecutive run showing fewer bytes downloaded / less wall time (store stayed warm).

Note on the substituter key

The bismuth nix-serve public key (bismuth:4o7SV2VpSiWDMTgFsFyAjAGqBjzrreKbTjpooZVghCY=) was not supplied separately — it is already in carbon's nix.conf (carbon trusts bismuth's cache). Reused here rather than guessed.

## What Converts the Forgejo Nix CI from per-job `nixos/nix` containers to a host-mode runner on bismuth, so all 7 jobs share one warm `/nix/store` instead of re-substituting the full closure 7× per push. Changes: - `.forgejo/workflows/nix.yml` — drop `container:`, target `runs-on: bismuth`, remove the per-job `nix-env -iA nixpkgs.nodejs` step, and install `nix-fast-build` from the flake (`.#nix-fast-build`) instead of the unpinned channel. - `.forgejo/scripts/setup-nix.sh` — re-enable the build sandbox, add bismuth's nix-serve (`http://bismuth:5000`) as the top-priority substituter with its public key. - `flake.nix` — expose `nix-fast-build` as a package output so CI can pin it. ## ⚠️ Workflow files This PR changes `.forgejo/workflows/nix.yml` and `.forgejo/scripts/setup-nix.sh`. Merging is the moment they go live. ## Not yet verified — needs the host runner This can't be run until bismuth has a host-mode runner. Before/after merging: 1. Install Nix natively on bismuth, plus nodejs (for the JS checkout action). 2. Register a Forgejo runner with the `bismuth` label — or change the `runs-on:` line to whatever label you register. 3. Add a `/nix/store` GC policy. Persistence is the point of host mode; without a GC policy a home machine fills its disk. Verification: a green run in host mode, then a second consecutive run showing fewer bytes downloaded / less wall time (store stayed warm). ## Note on the substituter key The bismuth nix-serve public key (`bismuth:4o7SV2VpSiWDMTgFsFyAjAGqBjzrreKbTjpooZVghCY=`) was not supplied separately — it is already in carbon's `nix.conf` (carbon trusts bismuth's cache). Reused here rather than guessed.
Drop the per-job nixos/nix container so all seven jobs share the runner's
native /nix/store across pushes instead of re-substituting the closure 7x.

- Target the host-mode runner label on bismuth and stop installing nodejs
  off the unpinned channel (nodejs is host-provided for the checkout action).
- Add bismuth's nix-serve as the top-priority substituter.
- Re-enable the build sandbox now that host mode doesn't need the container
  workaround.
- Pin nix-fast-build via the flake (.#nix-fast-build) instead of the unpinned
  channel.
This pull request has changes conflicting with the target branch.
  • .forgejo/scripts/setup-nix.sh
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u ci/forgejo-host-mode:arcuru-bot-ci/forgejo-host-mode
git switch arcuru-bot-ci/forgejo-host-mode

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff arcuru-bot-ci/forgejo-host-mode
git switch arcuru-bot-ci/forgejo-host-mode
git rebase main
git switch main
git merge --ff-only arcuru-bot-ci/forgejo-host-mode
git switch arcuru-bot-ci/forgejo-host-mode
git rebase main
git switch main
git merge --no-ff arcuru-bot-ci/forgejo-host-mode
git switch main
git merge --squash arcuru-bot-ci/forgejo-host-mode
git switch main
git merge --ff-only arcuru-bot-ci/forgejo-host-mode
git switch main
git merge arcuru-bot-ci/forgejo-host-mode
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
arcuru/eidetica!1
No description provided.