Skip to content

ci: adopt rainix nix-cachix-setup composite in report-downtime, drop deprecated DeterminateSystems nix installer - #460

Merged
thedavidmeister merged 3 commits into
masterfrom
ci-adopt-nix-cachix-setup-downtime
Jul 14, 2026
Merged

thedavidmeister merged 3 commits into
masterfrom
ci-adopt-nix-cachix-setup-downtime

Conversation

@thedavidmeister

@thedavidmeister thedavidmeister commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Closes #459

What

Replaces the deprecated DeterminateSystems/nix-installer-action@main (+ flakehub-cache-action@main) in .github/workflows/report-downtime.yaml with the org-standard shared composite rainlanguage/rainix/.github/actions/nix-cachix-setup@main, which bundles nix-quick-install + Cachix + cache-nix-action and pins every third-party action to an exact SHA (single source of truth — "rainix owns shared CI"). The pre-existing actions/checkout@v4 (submodules recursive, fetch-depth 0) is kept, so the composite is called with checkout: 'false'.

This also removes the @main floating-ref supply-chain risk the roh-scan signal called out (the composite pins every third-party action to an exact SHA).

This is the same swap already applied and green on the pilot PRs rainlanguage/rain.chainlink#11, rainlanguage/rain.tier.interface#8, and rainlanguage/assemblyscript-cbor#5.

QA

CI-infrastructure-only change: it touches a single GitHub Actions workflow file and no source or test code, so there is no behavioral code surface to mutation-test.

  • Scope honesty: report-downtime.yaml is a scheduled workflow (cron, once/7 days), so this PR's own CI does not exercise it — there is no PR-triggered run to observe. The change is validated by equivalence to the established pattern rather than by a PR-CI run, and I flag that explicitly here rather than implying a green run proves it.
  • Independent confirmation: the identical installer → composite swap is already green on the pilots rain.chainlink#11 / rain.tier.interface#8 / assemblyscript-cbor#5; the composite's input contract (checkout, cachix-auth-token) matches nix-cachix-setup/action.yml on rainix@main.
  • Equivalence: the composite provides the same capabilities the two removed steps did (Nix install + a flake/store cache) plus the org's pinned-SHA hardening. checkout: 'false' preserves the existing checkout (submodules recursive, fetch-depth 0). All downstream steps (prep-sushi.sh, nix develop -c npm install, the nix develop -c npx ts-node scripts/downtime.ts report step and its SUBGRAPHS/DURATION/THRESHOLD/TG_* env) are untouched. An empty CACHIX_AUTH_TOKEN degrades to a read-only Cachix pull (the composite's documented default).
  • Category check: issue asks to replace the deprecated installer (report-downtime.yaml:18) with the org-standard install (preferred: adopt the shared composite) — done → Closes CI: replace deprecated DeterminateSystems/nix-installer-action with org-standard nix-quick-install #459.

Co-Authored-By: Claude noreply@anthropic.com

Summary by CodeRabbit

  • Chores
    • Updated the downtime reporting workflow’s Nix setup and caching configuration.
    • Streamlined environment preparation for more consistent automated runs.

…deprecated DeterminateSystems nix installer

Closes #459

Co-Authored-By: Claude <noreply@anthropic.com>
@thedavidmeister thedavidmeister self-assigned this Jul 12, 2026
@coderabbitai

coderabbitai Bot commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

The downtime reporting workflow replaces the previous DeterminateSystems Nix installation steps with the shared Rainix Nix/Cachix setup action, disabling checkout and supplying the Cachix authentication secret.

Changes

CI Nix setup

Layer / File(s) Summary
Replace Nix installer
.github/workflows/report-downtime.yaml
Uses the shared Rainix setup action with checkout: 'false' and the configured Cachix authentication token.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related issues

  • rainlanguage/assemblyscript-cbor#4 — Replaces the deprecated Nix installer with the shared Rainix setup action.
  • rainlanguage/rain.chainlink#10 — Replaces deprecated Nix installer usage with the shared Rainix composite.
  • rainlanguage/rain.local-db.remote#12 — Adopts the shared Rainix Nix setup in GitHub Actions.
  • rainlanguage/rain.subgraph.docker#12 — Replaces the deprecated installer with the shared composite.
  • rainlanguage/rainlang-codemirror#31 — Uses the shared Rainix Nix setup action.
  • rainlanguage/rainlang.xyz#8 — Replaces deprecated Nix setup with the shared Rainix composite.
  • rainlanguage/rain.subgraph.cli#12 — Adopts the shared Rainix Nix setup action.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly states the workflow now uses the rainix Nix/Cachix composite instead of the deprecated DeterminateSystems installer.
Linked Issues check ✅ Passed The workflow change matches #459 by replacing the deprecated installer with the rainix shared setup and preserving checkout behavior.
Out of Scope Changes check ✅ Passed The only change is the Nix setup swap in the targeted workflow, with no unrelated code or workflow edits.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci-adopt-nix-cachix-setup-downtime

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thedavidmeister

Copy link
Copy Markdown
Contributor Author

🤖 ai:producer

Producer note: the red unit tests check is pre-existing and unrelated to this PR. This diff changes only .github/workflows/report-downtime.yaml, a schedule:-triggered (cron) workflow that is not run by this PR at all — it cannot affect the unit tests job. The failure is in src/logger/index.test.ts (a duration assertion: expected 10000000 to be close to 1009999990… +/- 1000), a time-dependent logger test failing independently on the base branch. This installer-modernization PR is inert on PR CI; the logger-test red needs to be resolved separately (it is not a regression from this change).

@thedavidmeister thedavidmeister added the ai:ready AI vetter: passes review, ready for human decision label Jul 12, 2026
@thedavidmeister

Copy link
Copy Markdown
Contributor Author

🤖 ai:vetter
Reviewed d3c9430: ready — closes #459 — swaps deprecated DeterminateSystems installer for org nix-cachix-setup composite in report-downtime.yaml; checkout:false + cachix-auth-token match the composite's real input contract, downstream prep-sushi/ts-node steps untouched; sole roh-scan-flagged file
cost 149 — CI installer→composite swap, scheduled wf

logger/index.test.ts otel timestamp closeTo assertion straddled a 1-second
boundary (deltas exactly ~1e9 ns); known pre-existing flake, diff here is
workflow-yaml-only. Re-run only.

Co-Authored-By: Claude <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/report-downtime.yaml:
- Line 18: Update the workflow’s rainix/cachix setup action reference from the
floating “main” ref to a full commit SHA, keeping the existing action path and
behavior unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: ea9780ce-0758-4190-91e2-457b9b78fab9

📥 Commits

Reviewing files that changed from the base of the PR and between 9031984 and b3de99b.

📒 Files selected for processing (1)
  • .github/workflows/report-downtime.yaml

Comment thread .github/workflows/report-downtime.yaml
@thedavidmeister

Copy link
Copy Markdown
Contributor Author

🤖 ai:vetter
Reviewed b3de99b: ready — re-vet at moved head b3de99b: closes #459 — deprecated DeterminateSystems installer swapped for rainix nix-cachix-setup composite; usage matches composite contract (checkout:'false' keeps submodules checkout, token degrades read-only); issue's single named site fully covered; red unit-tests job external to this YAML-only diff
cost 142 — one-file CI swap, org-standard composite

Prior retrigger cleared the logger closeTo flake; this run failed on a
NEW transient signature: ERR_PNPM_FETCH_404 on
@babel/plugin-transform-spread-7.24.1.tgz during pnpm install. The
tarball exists (HTTP 200 now), so the 404 was a registry flake.

Co-Authored-By: Claude <noreply@anthropic.com>
@thedavidmeister

Copy link
Copy Markdown
Contributor Author

🤖 ai:vetter
Reviewed 740b5e5: ready — closes #459 — re-vet at moved head 740b5e5: only empty CI-retrigger commits since vetted b3de99b, diff identical; deprecated DeterminateSystems installer swapped for rainix nix-cachix-setup composite (checkout:'false' preserves submodule checkout, token degrades read-only); all checks green
cost 144 — one-file CI swap, retrigger-only head move

@thedavidmeister
thedavidmeister merged commit 8626ba9 into master Jul 14, 2026
12 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

@coderabbitai assess this PR size classification for the totality of the PR with the following criterias and report it in your comment:

S/M/L PR Classification Guidelines:

This guide helps classify merged pull requests by effort and complexity rather than just line count. The goal is to assess the difficulty and scope of changes after they have been completed.

Small (S)

Characteristics:

  • Simple bug fixes, typos, or minor refactoring
  • Single-purpose changes affecting 1-2 files
  • Documentation updates
  • Configuration tweaks
  • Changes that require minimal context to review

Review Effort: Would have taken 5-10 minutes

Examples:

  • Fix typo in variable name
  • Update README with new instructions
  • Adjust configuration values
  • Simple one-line bug fixes
  • Import statement cleanup

Medium (M)

Characteristics:

  • Feature additions or enhancements
  • Refactoring that touches multiple files but maintains existing behavior
  • Breaking changes with backward compatibility
  • Changes requiring some domain knowledge to review

Review Effort: Would have taken 15-30 minutes

Examples:

  • Add new feature or component
  • Refactor common utility functions
  • Update dependencies with minor breaking changes
  • Add new component with tests
  • Performance optimizations
  • More complex bug fixes

Large (L)

Characteristics:

  • Major feature implementations
  • Breaking changes or API redesigns
  • Complex refactoring across multiple modules
  • New architectural patterns or significant design changes
  • Changes requiring deep context and multiple review rounds

Review Effort: Would have taken 45+ minutes

Examples:

  • Complete new feature with frontend/backend changes
  • Protocol upgrades or breaking changes
  • Major architectural refactoring
  • Framework or technology upgrades

Additional Factors to Consider

When deciding between sizes, also consider:

  • Test coverage impact: More comprehensive test changes lean toward larger classification
  • Risk level: Changes to critical systems bump up a size category
  • Team familiarity: Novel patterns or technologies increase complexity

Notes:

  • the assessment must be for the totality of the PR, that means comparing the base branch to the last commit of the PR
  • the assessment output must be exactly one of: S, M or L (single-line comment) in format of: SIZE={S/M/L}
  • do not include any additional text, only the size classification
  • your assessment comment must not include tips or additional sections
  • do NOT tag me or anyone else on your comment

@coderabbitai

coderabbitai Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

SIZE=S

This branch was successfully deployed

1 active deployment
preview — 740b5e55 Deployed Jul 12, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai:ready AI vetter: passes review, ready for human decision

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: replace deprecated DeterminateSystems/nix-installer-action with org-standard nix-quick-install

1 participant