Publish Linux nix-cli release caches and the signing public key - #8
Merged
Merged
Conversation
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Releases currently carry only the aarch64-darwin nix-cli closure (built for the macOS .pkg), so Linux consumers (agent sandboxes via monorepo
bin/setup_nix.sh, exa-labs/monorepo#122820) can't substitute the fork from the GitHub release and have to rely on the exa S3 cache.Context
Extends the release workflow so each release is a complete multi-system binary cache:
linux-cachematrix jobs (x86_64-linuxon ubuntu-latest,aarch64-linuxon ubuntu-24.04-arm) build.#nix-cli, runmake-release-cache.sh, rename the closure root file tostore-paths-<system>, and upload the flat cache as a workflow artifact. No FlakeHub cache action in these jobs — they build self-contained.pkgjob renames its darwin root tostore-paths-aarch64-darwin(keeping the legacystore-paths), merges the Linux cache artifacts into the release asset set (skipping already-present content-addressed nar/narinfo names), and publishespublic-key(derived fromNIX_RELEASE_SIGNING_KEYvianix key convert-secret-to-public) so consumers can pin the narinfo signing key.Consumers then substitute per-system:
Link to Devin session: https://app.devin.ai/sessions/e37fd6958cca4b16b5995b723d52a907
Requested by: @ethancedwards8