Skip to content

ci: adopt rainix nix-cachix-setup composite, drop deprecated DeterminateSystems nix installer - #13

Merged
thedavidmeister merged 1 commit into
mainfrom
ci-adopt-nix-cachix-setup
Jul 14, 2026
Merged

thedavidmeister merged 1 commit into
mainfrom
ci-adopt-nix-cachix-setup

Conversation

@thedavidmeister

@thedavidmeister thedavidmeister commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Closes #12

What

Replaces the deprecated DeterminateSystems/nix-installer-action@v4 in .github/workflows/build.yaml with the org-standard shared composite rainlanguage/rainix/.github/actions/nix-cachix-setup@main, which bundles nix-quick-install + Cachix + cache-nix-action and pins every third-party action to an exact SHA (single source of truth — "rainix owns shared CI"). The pre-existing actions/checkout@v3 step is kept, so the composite is called with checkout: 'false'.

build.yaml is the only workflow flagged by roh-scan's old-nix-installer signal here; test.yaml installs no Nix (cargo test runs on the runner toolchain), so it is untouched.

This is the same swap already applied and green on the pilot PRs rainlanguage/rain.chainlink#11, rainlanguage/rain.tier.interface#8, and rainlanguage/assemblyscript-cbor#5.

QA

CI-infrastructure-only change: it touches a single GitHub Actions workflow file and no source or test code, so there is no behavioral code surface to mutation-test — the discriminating oracle is the CI run itself.

  • Discriminating oracle: build.yaml runs on pull_request, so this PR's own CI exercises the swap on the ubuntu-latest/macos-latest matrix: the Build job must install Nix via the composite and run nix build . --print-build-logs. A mis-reference (wrong action path or input name) fails the setup step, so the swap is CI-green-discriminating, not a silent no-op.
  • Independent confirmation: the identical composite swap is already green on the pilots rain.chainlink#11 / rain.tier.interface#8 / assemblyscript-cbor#5; the composite's input contract (checkout, cachix-auth-token) matches nix-cachix-setup/action.yml on rainix@main.
  • Equivalence: the composite provides the same capability the removed step did (Nix install) plus the org's pinned-SHA hardening and a Nix store cache. checkout: 'false' preserves the existing actions/checkout@v3. An empty CACHIX_AUTH_TOKEN degrades to a read-only Cachix pull (the composite's documented default), so the job stays green whether or not the repo sets that secret.
  • Category check: issue asks to replace the deprecated installer with the org-standard install (preferred: adopt the shared composite) and verify CI stays green — done → Closes CI: replace deprecated DeterminateSystems/nix-installer-action with org-standard nix-quick-install #12.

Co-Authored-By: Claude noreply@anthropic.com

Summary by CodeRabbit

  • Chores
    • Updated the build workflow’s Nix setup and caching configuration.
    • Improved access to cached build artifacts during automated builds.

…ateSystems nix installer

Closes #12

Co-Authored-By: Claude <noreply@anthropic.com>
@thedavidmeister thedavidmeister self-assigned this Jul 12, 2026
@coderabbitai

coderabbitai Bot commented Jul 12, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

The build workflow replaces DeterminateSystems/nix-installer-action@v4 with the shared Rainix Nix/Cachix setup action, disables its checkout behavior, and passes the repository’s Cachix authentication secret.

Changes

CI setup modernization

Layer / File(s) Summary
Shared Nix and Cachix setup
.github/workflows/build.yaml
The Install Nix step now uses rainlanguage/rainix/.github/actions/nix-cachix-setup@main, skips checkout, and receives secrets.CACHIX_AUTH_TOKEN.

Estimated code review effort: 2 (Simple) | ~5 minutes

Possibly related issues

  • rainlanguage/rain.chainlink#10 — Replaces the deprecated Nix installer with the shared Rainix Nix/Cachix setup.
  • rainlanguage/rain.webapp#356 — Replaces the deprecated Nix installer with the shared Rainix action in CI.
  • rainlanguage/rain.tier.interface#7 — Adopts the shared Rainix Nix/Cachix setup in CI workflows.
  • rainlanguage/assemblyscript-cbor#4 — Replaces the deprecated Nix installer with the shared Rainix action.
  • rainlanguage/sqlite-web#30 — Adopts the shared Rainix Nix/Cachix setup in GitHub workflows.
  • rainlanguage/rainlang-codemirror#31 — Replaces the deprecated Nix installer with the shared Rainix action.
  • rainlanguage/rain.subgraph.docker#12 — Replaces the deprecated Nix installer with the shared Rainix action.
  • rainlanguage/rain.solver#459 — Replaces the deprecated Nix installer with the shared Rainix setup.
  • rainlanguage/rainlang.xyz#8 — Replaces the deprecated Nix installer with the shared Rainix action.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is specific and accurately describes the Nix installer replacement in CI.
Linked Issues check ✅ Passed The workflow now uses the shared rainix nix-cachix-setup composite instead of the deprecated installer, matching #12.
Out of Scope Changes check ✅ Passed The changes stay focused on the build workflow Nix setup and do not ցույց unrelated scope.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci-adopt-nix-cachix-setup

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/build.yaml:
- Around line 16-19: Update the shared action reference in the workflow step
using rainlanguage/rainix/.github/actions/nix-cachix-setup so it is pinned to a
specific immutable commit SHA instead of the mutable `@main` ref, while preserving
the existing checkout and cachix-auth-token inputs.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: a33d1298-ba61-4afc-ba3b-0e5cffc43971

📥 Commits

Reviewing files that changed from the base of the PR and between 9f2a89a and 3d9b78f.

📒 Files selected for processing (1)
  • .github/workflows/build.yaml

Comment thread .github/workflows/build.yaml
@thedavidmeister thedavidmeister added the ai:ready AI vetter: passes review, ready for human decision label Jul 12, 2026
@thedavidmeister

Copy link
Copy Markdown
Contributor Author

🤖 ai:vetter
Reviewed 3d9b78f: ready — closes #12 — swaps deprecated DeterminateSystems installer for org nix-cachix-setup composite in build.yaml; checkout:false + cachix-auth-token match the composite's real input contract; sole roh-scan-flagged file (test.yaml installs no Nix)
cost 141 — CI installer→composite swap, single file

@thedavidmeister
thedavidmeister merged commit 55394b1 into main Jul 14, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai:ready AI vetter: passes review, ready for human decision

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: replace deprecated DeterminateSystems/nix-installer-action with org-standard nix-quick-install

1 participant