Files
cc-ci/nix/modules/default.nix
T
notplantsandClaude Fable 5.1 9b99f81f5f
continuous-integration/drone/push Build is failing
nix: export the CI server as nixosModules.cc-ci-server
The whole server (every service module, the harness tooling, sops wiring,
acme-dns) becomes one reusable module, nix/modules/default.nix, so another
flake can run cc-ci on a host it defines. First consumer: the
cc-ci-orchestrator repo's `#cc-ci` host, which runs the CI server and the
orchestrator together on one Hetzner machine.

Two things the modules hard-coded become options (nix/modules/options.nix):
- cc-ci.publicIPv4 — acme-dns's listen address and ns-acme glue record.
- cc-ci.sopsFile — the secrets.yaml path; defaults to the secrets/ submodule,
  but a consumer that imports cc-ci as a plain input (no private submodule)
  points it at the deployed --recursive checkout and sops-nix reads it at
  activation (validateSopsFiles off for that case).

The standalone host (nix/hosts/cc-ci-hetzner) now only carries hardware,
networking and identity and imports the module via the flake. Verified: the
`#cc-ci` system derivation is byte-identical before and after
(/nix/store/ckp1244bz86fz3qbx81n5kx60c1lak3m-…531670d.drv on both).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-07 19:56:58 +00:00

45 lines
1.6 KiB
Nix

# The cc-ci CI server as ONE reusable NixOS module — exported from flake.nix as
# `nixosModules.cc-ci-server`. Everything a host needs to BE cc-ci, except what is physical or
# identity and therefore belongs to the host that imports it: hardware, networking, the tailscale
# node, root SSH keys, `system.stateVersion`. A host sets `cc-ci.publicIPv4` (and, when it is not
# built from a --recursive clone, `cc-ci.sopsFile`) and imports this.
#
# Consumers: nix/hosts/cc-ci-hetzner (the canonical standalone host) and
# recipe-maintainers/cc-ci-orchestrator's `#cc-ci` host, which runs the CI server and the
# orchestrator together (2026-09).
{ pkgs, ... }:
{
imports = [
./options.nix
./packages.nix
./secrets.nix
./acme-dns.nix
./swarm.nix
./docker-prune.nix
./abra.nix
./proxy.nix
./drone.nix
./drone-runner.nix
./bridge.nix
./dashboard.nix
./reports.nix
./backupbot.nix
./harness.nix
./warm-keycloak.nix
./nightly-sweep.nix
];
# Recipes bind-mount /etc/localtime and /etc/timezone; the harness compares timestamps across
# host and containers, so the host is UTC like every container.
time.timeZone = "UTC";
environment.etc."timezone".text = "UTC\n";
# Phase `nixenv`: the Drone exec runner resolves recipe shell-outs from this host PATH
# (/run/current-system/sw/bin). Install the SINGLE shared harness tool set (pkgs.ccciRuntimeTools,
# defined in packages.nix) so the Drone path and the harness env (cc-ci-run / sweep) can never
# diverge.
environment.systemPackages = pkgs.ccciRuntimeTools;
nix.settings.experimental-features = [ "nix-command" "flakes" ];
}