name: Publish Nix cache on: push: branches: - main workflow_dispatch: permissions: contents: write packages: write concurrency: group: publish-nixcache-${{ github.ref }} cancel-in-progress: false jobs: publish: name: Build and publish uncached paths runs-on: ubuntu-latest timeout-minutes: 180 steps: - name: Checkout repository uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: persist-credentials: true - name: Install Nix uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0 with: extra_nix_config: | experimental-features = nix-command flakes accept-flake-config = true access-tokens = github.com=${{ github.token }} - name: Configure cache signing env: NIX_SIGNING_KEY: ${{ secrets.NIX_SIGNING_KEY }} run: | set -euo pipefail test -n "$NIX_SIGNING_KEY" || { echo "NIX_SIGNING_KEY is required; refusing to publish unsigned cache paths." >&2 exit 1 } signing_key="$RUNNER_TEMP/nixcache-signing-key" umask 077 printf '%s' "$NIX_SIGNING_KEY" > "$signing_key" nix key convert-secret-to-public < "$signing_key" > nixcache-public-key.txt echo "NIXCACHE_SIGNING_KEY_FILE=$signing_key" >> "$GITHUB_ENV" - name: Commit cache public key run: | set -euo pipefail if git diff --quiet -- nixcache-public-key.txt; then exit 0 fi git config user.name "github-actions[bot]" git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git add nixcache-public-key.txt git commit -m "chore: publish Nix cache signing key" git push - name: Build and publish uncached store paths env: GITHUB_TOKEN: ${{ github.token }} NIXCACHE_REPO: ${{ github.repository }} NIXCACHE_CONFIG_DIR: . run: | set -euo pipefail nixcache_source="$(nix flake archive --json --no-write-lock-file github:cmspam/nixcache-oci/fb6006b5575da494dbbfc582e841d976ec06be6e | jq -r .path)" source "$nixcache_source/lib/cache-builder.sh" full_pipeline