Sign inSign up

johnwalkerx/nix-remote-builder-plugin

By johnwalkerx

•Updated over 1 year ago

A Woodpecker CI plugin which uses the store of a remote system to build our given Nix flake paths.

Image
0

444

johnwalkerx/nix-remote-builder-plugin repository overview

⁠nix-remote-builder-plugin

status-badge Docker Image Version (latest semver) ⁠

A Woodpecker CI⁠ plugin which uses the store of a remote system to build our given Nix flake paths.

The usecase is that the remote system acts as a builder and Nix binarycache. So we build our nixOS systems on the remote system and keep the output in the nix store of the remote system.

Our benefits:

  • For each build we use the persistent store of the remote system and get much faster builds because we use already build artefacts.
  • The result will stay in the Nix store of the remote machine. So we can serve this store as binary cache.

⁠Plugin-Parameters

  • sshkey: SSH key for SSH authentification on remote system. This should be applied from a CI secret.
  • username: Username on remote system
  • hostname: Hostname of remote system
  • sshport: SSH Port to connect on remote system
  • flakepaths: List of flakepaths to build separated by ,

⁠Example CI config

steps:
  remote-build:
    image: johnwalkerx/nix-remote-builder-plugin:latest
    pull: true
    settings:
      hostname: binarycache.example.com
      sshport: 22
      username: uploaduser
      sshkey:
        from_secret: sshkey
      flakepaths: >-
        .#nixosConfigurations.machine1.config.system.build.toplevel,
        .#nixosConfigurations.machine2.config.system.build.toplevel

NOTE: Make sure to restrict usage of the secret to this specific docker image and select that only plugins can use this secrets.

Tag summary

Content type

Image

Digest

sha256:981edeebd…

Size

198.4 MB

Last updated

over 1 year ago

docker pull johnwalkerx/nix-remote-builder-plugin