{ description = "cc-ci-orchestrator — the cc-ci orchestrator (loops, steering session, weekly upgrader) and the NixOS host it shares with the cc-ci CI server"; inputs = { # Stable release channel (operator 2026-08-01). `nix flake update` moves it; the cc-ci input # below FOLLOWS it, so one nixpkgs builds the whole combined host and CVEs get patched once. nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; sops-nix.url = "github:Mic92/sops-nix"; sops-nix.inputs.nixpkgs.follows = "nixpkgs"; # The cc-ci CI server, as a NixOS module (`nixosModules.cc-ci-server`). HTTPS, anonymous read: # nix evaluates every input for every output, so the input must be fetchable without # credentials. The private secrets submodule is deliberately NOT fetched through this input — # the host reads the deployed --recursive checkout's secrets.yaml at activation instead # (`cc-ci.sopsFile`). Both `follows` are REQUIRED: without them cc-ci's own nixpkgs/sops-nix # pins would produce a second sops-nix module tree and a second nixpkgs in one system. cc-ci.url = "git+https://git.autonomic.zone/recipe-maintainers/cc-ci.git"; cc-ci.inputs.nixpkgs.follows = "nixpkgs"; cc-ci.inputs.sops-nix.follows = "sops-nix"; }; outputs = { self, nixpkgs, sops-nix, cc-ci, ... }: let system = "x86_64-linux"; in { nixosModules = { # The orchestrator itself: loops supervisor, steering session, weekly/hourly timers. cc-ci-orchestrator = ./nix/modules/cc-ci.nix; # The host contract those units assume: loops user, claude/opencode CLIs, opencode web # server + tailnet UI, nix-ld, tool set, `ssh cc-ci` config. orchestrator-host = ./nix/modules/orchestrator-host.nix; # Weekly health-gated self-update of the host (busy-gated around CI runs). auto-update = ./nix/modules/auto-update.nix; # Old name of cc-ci-orchestrator, kept while notplants-nix still imports it (2026-09). cc-ci = ./nix/modules/cc-ci.nix; }; nixosConfigurations = { # THE live host: cc-ci CI server + cc-ci orchestrator on one Hetzner cpx32-class box # (195.201.88.249, since 2026-09). README.md is the deploy guide. cc-ci = nixpkgs.lib.nixosSystem { inherit system; modules = [ cc-ci.nixosModules.cc-ci-server self.nixosModules.cc-ci-orchestrator self.nixosModules.orchestrator-host self.nixosModules.auto-update ./nix/hosts/cc-ci/configuration.nix ]; }; }; }; }