From 1814173e3c9bc23d7eab016c7ab3e9d703f838e9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Tue, 10 Mar 2026 22:50:04 -0700 Subject: [PATCH 1/2] feat: add deploy-rs for automated NixOS deployments via GitHub Actions Integrates deploy-rs to enable push-based deployments to glyph, spore, and zeta after CI passes on main. Uses Tailscale for connectivity and Attic cache for pre-built closures. Magic rollback is enabled for safety. Co-Authored-By: Claude Opus 4.6 --- .github/workflows/deploy.yml | 68 ++++++++++++++++++++++++++++++++ flake.lock | 76 +++++++++++++++++++++++++++++++++++- flake.nix | 50 ++++++++++++++++++++++++ lib/deploy.pub | 1 + lib/keys.nix | 1 + modules/nixos/ssh.nix | 1 + 6 files changed, 195 insertions(+), 2 deletions(-) create mode 100644 .github/workflows/deploy.yml create mode 100644 lib/deploy.pub diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml new file mode 100644 index 00000000..6f12d88b --- /dev/null +++ b/.github/workflows/deploy.yml @@ -0,0 +1,68 @@ +name: Deploy + +on: + workflow_run: + workflows: ["CI"] + types: [completed] + branches: [main] + workflow_dispatch: + +jobs: + deploy: + if: >- + github.event_name == 'workflow_dispatch' || + github.event.workflow_run.conclusion == 'success' + strategy: + max-parallel: 1 + matrix: + include: + - host: glyph + system: x86_64-linux + runner: ubuntu-latest + - host: spore + system: x86_64-linux + runner: ubuntu-latest + - host: zeta + system: aarch64-linux + runner: ubuntu-24.04-arm + runs-on: ${{ matrix.runner }} + steps: + - uses: actions/checkout@v4 + + - uses: cachix/install-nix-action@v31 + with: + github_access_token: ${{ secrets.GITHUB_TOKEN }} + extra_nix_config: | + extra-substituters = https://cache.zx.dev/main + extra-trusted-public-keys = main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c= + + - name: Configure Attic cache + run: | + nix profile install --inputs-from . attic#attic-client + attic login rc https://cache.zx.dev ${{ secrets.ATTIC_TOKEN }} + attic use rc:main + + - name: Connect to Tailscale + uses: tailscale/github-action@v3 + with: + oauth-client-id: ${{ secrets.TS_OAUTH_CLIENT_ID }} + oauth-secret: ${{ secrets.TS_OAUTH_SECRET }} + tags: tag:ci + + - name: Configure SSH + run: | + mkdir -p ~/.ssh + echo "${{ secrets.DEPLOY_SSH_KEY }}" > ~/.ssh/deploy_key + chmod 600 ~/.ssh/deploy_key + cat >> ~/.ssh/config < Date: Wed, 11 Mar 2026 08:41:57 -0700 Subject: [PATCH 2/2] fix: remove nix flake check from CI nix flake check evaluates all flake outputs across all systems, causing cross-platform build failures (e.g. aarch64-linux derivations on x86_64-linux runners). The per-host build step already validates each configuration. Co-Authored-By: Claude Opus 4.6 --- .github/workflows/ci.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 7043af25..fcc53c17 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -37,7 +37,6 @@ jobs: nix profile install --inputs-from . attic#attic-client attic login rc https://cache.zx.dev ${{ secrets.ATTIC_TOKEN }} attic use rc:main - - run: nix flake check - name: Build system configuration run: | if [ "${{ matrix.system }}" = "aarch64-darwin" ]; then