This repository has been archived on 2026-07-30. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
nixos/AGENTS.md
beatzaplenty 7e9c0c2a6f
Check NixOS configurations / eval-hosts (pull_request) Canceled after 0s
Rewrite codex-maintenance.sh to scope CI checks to changed files
CI was running a full eval of every host + package on every push/PR,
which was slow enough to routinely time out the Gitea runner. Default
mode now diffs against a base ref and scopes nixpkgs-fmt/statix/eval to
the files that changed and the hosts/packages they can affect; a change
to flake.nix/flake.lock/variables.nix/modules/common/* (or any other
modules/*.nix outside platforms//build-types, whose blast radius isn't
inferable from the path) falls back to evaluating everything. The old
full sweep moves behind --full-check, which CI never passes; --dry-run
adds build-planning on top of whichever scope is active.

Also trims codex-setup.sh's redundant full host eval loop -- that's
what codex-maintenance.sh is for; setup should just install tooling.
2026-07-20 17:25:22 +00:00

1.9 KiB

AGENTS.md

Repo purpose

This repository contains flake-based NixOS configurations for Wayne's LAN servers and workstation.

The flake exposes NixOS configurations named <platform>-<buildtype> (platforms: linode, proxmox, lxc; build types: minimal, nix-cache, server, docker, gui, pxe-boot, tailscale-exit-node, tor-relay), generated from modules/platforms/* and modules/build-types/* by the mkTarget function in flake.nix. Not every combination is built — pxe-boot has no linode variant. See README.md for the full current target list; treat flake.nix as the source of truth since this list can drift.

Do not deploy, switch, reboot, repartition, format disks, or run destructive install commands from this repository unless explicitly asked.

Safety rules

  • Never run nixos-rebuild switch, boot, test, nixos-install, parted, mkfs, mkswap, swapon, mount, or destructive disk commands in Codex.
  • Validation work should be limited to evaluation, linting, formatting checks, and nix build --dry-run --no-link.
  • Do not add secrets, tokens, private keys, password hashes, or live credentials to the repo.
  • Treat flake.nix, Home Manager config, and Nix config files as public.
  • If you find committed tokens or hashes, flag them immediately and recommend rotation/removal.

Expected commands

Use these commands when validating changes:

bash scripts/codex-setup.sh
bash scripts/codex-maintenance.sh

With no flags, codex-maintenance.sh scopes fmt-check/statix/eval to files changed against a base ref — this is what CI runs on every push/PR. For the full sweep (every host, every package — slow; CI never runs this), use bash scripts/codex-maintenance.sh --full-check (add --dry-run for build planning on top of whichever scope is active).

Host evaluation is safe when limited to drvPath checks:

nix eval .#nixosConfigurations.<host>.config.system.build.toplevel.drvPath --raw