Skip to content

ci: adopt rainix nix-cachix-setup composite, drop deprecated DeterminateSystems nix installer - #5

Merged
thedavidmeister merged 1 commit into
masterfrom
2026-07-12-issue-4-nix-installer
Jul 12, 2026
Merged

thedavidmeister merged 1 commit into
masterfrom
2026-07-12-issue-4-nix-installer

Conversation

@thedavidmeister

@thedavidmeister thedavidmeister commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Closes #4

What

Replaces the deprecated DeterminateSystems/nix-installer-action (+ magic-nix-cache-action) in .github/workflows/test.yaml with the org-standard shared composite rainlanguage/rainix/.github/actions/nix-cachix-setup@main, which bundles nix-quick-install + Cachix + cache-nix-action and pins every third-party action to an exact SHA (single source of truth — "rainix owns shared CI"). The pre-existing actions/checkout@v4 step is kept, so the composite is called with checkout: 'false'.

This is the same swap already applied and green on the pilot PRs rainlanguage/rain.chainlink#11 and rainlanguage/rain.tier.interface#8.

QA

CI-infrastructure-only change: it touches a single GitHub Actions workflow file and no source or test code, so there is no behavioral code surface to mutation-test — the discriminating oracle is the CI run itself.

  • Discriminating oracle: the Test job must install Nix and run nix develop -c npm run test with the composite in place of the removed installer. A mis-reference (wrong action path or input name) fails the setup step, so the swap is CI-green-discriminating, not a silent no-op.
  • Independent confirmation: the identical composite swap is already green on the pilots rain.chainlink#11 / rain.tier.interface#8; the composite's input contract (checkout, cachix-auth-token) was verified against nix-cachix-setup/action.yml on rainix@main.
  • Equivalence: the composite provides the same capabilities the removed steps did (Nix install + a Nix store cache) plus the org's pinned-SHA hardening. checkout: 'false' preserves the existing actions/checkout@v4 (submodules recursive, fetch-depth 0). An empty CACHIX_AUTH_TOKEN degrades to a read-only Cachix pull (the composite's documented default), so the job stays green whether or not the repo sets that secret.
  • Category check: issue asks to replace the deprecated installer with the org-standard install (preferred: adopt the shared composite) and verify CI stays green — done → Closes CI: replace deprecated DeterminateSystems/nix-installer-action with org-standard nix-quick-install #4.

Co-Authored-By: Claude noreply@anthropic.com

Summary by CodeRabbit

  • Chores
    • Updated the automated workflow’s Nix caching setup to improve build environment configuration.
    • Reused the configured cache authentication securely through repository secrets.

…ateSystems installer

Replaces DeterminateSystems/nix-installer-action + magic-nix-cache-action
with the shared rainlanguage/rainix nix-cachix-setup composite (pinned-SHA
third-party actions, single source of truth). Closes #4.

Co-Authored-By: Claude <noreply@anthropic.com>
@thedavidmeister thedavidmeister self-assigned this Jul 12, 2026
@coderabbitai

coderabbitai Bot commented Jul 12, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

The test workflow replaces separate Nix installer and magic cache actions with the shared Rainix Nix/Cachix setup action, disabling its checkout behavior and passing the repository Cachix authentication token.

Changes

CI Nix setup

Layer / File(s) Summary
Shared Nix and Cachix setup
.github/workflows/test.yaml
The workflow uses rainlanguage/rainix/.github/actions/nix-cachix-setup@main with checkout disabled and authentication sourced from secrets.CACHIX_AUTH_TOKEN.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related issues

  • rainlanguage/rain.webapp#356 — Replaces the same deprecated Nix installer with the shared Rainix setup action.
  • rainlanguage/rain.tier.interface#7 — Replaces the same deprecated Nix installer in CI.
  • rainlanguage/rain.subgraph.docker#12 — Adopts the shared Rainix Nix setup action.
  • rainlanguage/rain.chainlink#10 — Replaces the deprecated installer in CI.
  • rainlanguage/sqlite-web#30 — Adopts the shared Rainix CI setup.
  • rainlanguage/rain.solver#459 — Replaces the deprecated installer with the shared action.
  • rainlanguage/rainlang-codemirror#31 — Adopts the shared Rainix setup action.
  • rainlanguage/rain.local-db.remote#12 — Makes the same shared CI setup change.
  • rainlanguage/rainlang.xyz#8 — Replaces the deprecated installer in another workflow.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the workflow CI change and the migration away from the deprecated Nix installer.
Linked Issues check ✅ Passed The workflow now adopts the shared rainix composite and removes the deprecated installer, matching issue #4's requirements.
Out of Scope Changes check ✅ Passed The only change is the CI workflow Nix setup migration, which stays within the linked issue's scope.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 2026-07-12-issue-4-nix-installer

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/test.yaml:
- Line 16: Update the shared nix-cachix-setup action reference in the workflow
to use its current immutable commit SHA instead of the mutable `@main` ref. Keep
the action path and workflow behavior unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 168dae14-6a24-4e5e-b2f4-e5945849ef4d

📥 Commits

Reviewing files that changed from the base of the PR and between 149ae24 and 0579368.

📒 Files selected for processing (1)
  • .github/workflows/test.yaml

Comment thread .github/workflows/test.yaml
@thedavidmeister thedavidmeister added the ai:ready AI vetter: passes review, ready for human decision label Jul 12, 2026
@thedavidmeister

Copy link
Copy Markdown
Contributor Author

🤖 ai:vetter
Reviewed 0579368: ready — closes #4 — swap deprecated DeterminateSystems nix-installer(+magic-nix-cache) for org-standard rainix nix-cachix-setup composite; Test job green, mirrors green pilots chainlink#11 / tier.interface#8
cost 166 — CI nix-installer→composite swap, green

@thedavidmeister

Copy link
Copy Markdown
Contributor Author

Reviewed 0579368: correct — swaps deprecated DeterminateSystems/nix-installer-action + magic-nix-cache-action for the org-standard rainlanguage/rainix/.github/actions/nix-cachix-setup@main composite. checkout: 'false' preserves the workflow's own submodules: recursive checkout (composite gates its internal checkout on that input, verified). Kills both old-nix-installer and dead-magic-nix-cache. All CI green; @main pin is org convention (rain.flare#123/#52). Ready.

@thedavidmeister
thedavidmeister merged commit d5d67c6 into master Jul 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai:ready AI vetter: passes review, ready for human decision

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: replace deprecated DeterminateSystems/nix-installer-action with org-standard nix-quick-install

1 participant