{ description = "cc-ci-orchestrator — NixOS host for the cc-ci loops runtime (Builder/Adversary/Watchdog)"; inputs = { # Follow the current stable release channel (operator 2026-08-01), was a hard rev pin at # nixpkgs 24.11 (50ab7937, 2025-06-30) kept "the same as the cc-ci server". This host runs # agents/tmux/nginx/docker, not recipe CI, so it does not need to match that server — and a # frozen rev only accrues unpatched CVEs. `nix flake update` now actually moves. nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; # sops-nix follows nixpkgs below, so it no longer needs its own matching pin. sops-nix.url = "github:Mic92/sops-nix"; sops-nix.inputs.nixpkgs.follows = "nixpkgs"; }; outputs = { nixpkgs, sops-nix, ... }: let system = "x86_64-linux"; in { # Hetzner cpx11 host (nixos-infect generated hardware.nix + orchestrator config). # Provision with terraform/ then run Stage 2 per terraform/README.md. nixosConfigurations.cc-ci-orchestrator-hetzner = nixpkgs.lib.nixosSystem { inherit system; modules = [ sops-nix.nixosModules.sops ./nix/hosts/cc-ci-orchestrator-hetzner/hardware.nix ./nix/hosts/cc-ci-orchestrator-hetzner/configuration.nix ]; }; }; }