ci: adopt rainix nix-cachix-setup composite in report-downtime, drop deprecated DeterminateSystems nix installer - #460
Conversation
…deprecated DeterminateSystems nix installer Closes #459 Co-Authored-By: Claude <noreply@anthropic.com>
WalkthroughThe downtime reporting workflow replaces the previous DeterminateSystems Nix installation steps with the shared Rainix Nix/Cachix setup action, disabling checkout and supplying the Cachix authentication secret. ChangesCI Nix setup
Estimated code review effort: 1 (Trivial) | ~2 minutes Possibly related issues
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🤖 ai:producer Producer note: the red |
|
🤖 ai:vetter |
logger/index.test.ts otel timestamp closeTo assertion straddled a 1-second boundary (deltas exactly ~1e9 ns); known pre-existing flake, diff here is workflow-yaml-only. Re-run only. Co-Authored-By: Claude <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/report-downtime.yaml:
- Line 18: Update the workflow’s rainix/cachix setup action reference from the
floating “main” ref to a full commit SHA, keeping the existing action path and
behavior unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: ea9780ce-0758-4190-91e2-457b9b78fab9
📒 Files selected for processing (1)
.github/workflows/report-downtime.yaml
|
🤖 ai:vetter |
Prior retrigger cleared the logger closeTo flake; this run failed on a NEW transient signature: ERR_PNPM_FETCH_404 on @babel/plugin-transform-spread-7.24.1.tgz during pnpm install. The tarball exists (HTTP 200 now), so the 404 was a registry flake. Co-Authored-By: Claude <noreply@anthropic.com>
|
🤖 ai:vetter |
|
@coderabbitai assess this PR size classification for the totality of the PR with the following criterias and report it in your comment: S/M/L PR Classification Guidelines:This guide helps classify merged pull requests by effort and complexity rather than just line count. The goal is to assess the difficulty and scope of changes after they have been completed. Small (S)Characteristics:
Review Effort: Would have taken 5-10 minutes Examples:
Medium (M)Characteristics:
Review Effort: Would have taken 15-30 minutes Examples:
Large (L)Characteristics:
Review Effort: Would have taken 45+ minutes Examples:
Additional Factors to ConsiderWhen deciding between sizes, also consider:
Notes:
|
|
Tip For best results, initiate chat on the files or code changes. SIZE=S |
Closes #459
What
Replaces the deprecated
DeterminateSystems/nix-installer-action@main(+flakehub-cache-action@main) in.github/workflows/report-downtime.yamlwith the org-standard shared compositerainlanguage/rainix/.github/actions/nix-cachix-setup@main, which bundles nix-quick-install + Cachix +cache-nix-actionand pins every third-party action to an exact SHA (single source of truth — "rainix owns shared CI"). The pre-existingactions/checkout@v4(submodules recursive, fetch-depth 0) is kept, so the composite is called withcheckout: 'false'.This also removes the
@mainfloating-ref supply-chain risk the roh-scan signal called out (the composite pins every third-party action to an exact SHA).This is the same swap already applied and green on the pilot PRs rainlanguage/rain.chainlink#11, rainlanguage/rain.tier.interface#8, and rainlanguage/assemblyscript-cbor#5.
QA
CI-infrastructure-only change: it touches a single GitHub Actions workflow file and no source or test code, so there is no behavioral code surface to mutation-test.
report-downtime.yamlis a scheduled workflow (cron, once/7 days), so this PR's own CI does not exercise it — there is no PR-triggered run to observe. The change is validated by equivalence to the established pattern rather than by a PR-CI run, and I flag that explicitly here rather than implying a green run proves it.checkout,cachix-auth-token) matchesnix-cachix-setup/action.ymlonrainix@main.checkout: 'false'preserves the existing checkout (submodules recursive, fetch-depth 0). All downstream steps (prep-sushi.sh,nix develop -c npm install, thenix develop -c npx ts-node scripts/downtime.tsreport step and itsSUBGRAPHS/DURATION/THRESHOLD/TG_*env) are untouched. An emptyCACHIX_AUTH_TOKENdegrades to a read-only Cachix pull (the composite's documented default).report-downtime.yaml:18) with the org-standard install (preferred: adopt the shared composite) — done → Closes CI: replace deprecatedDeterminateSystems/nix-installer-actionwith org-standard nix-quick-install #459.Co-Authored-By: Claude noreply@anthropic.com
Summary by CodeRabbit