feat(work): source ~/.jenkinsenv in all zsh shells
CI / flake (pull_request) Failing after 2m16s

Add programs.zsh.envExtra to the EDaaS work profile so ~/.jenkinsenv is
sourced from ~/.zshenv on every zsh invocation (login, interactive, and
non-interactive), exporting the JENKINS_UCE_/JENKINS_STF_ tokens the Jenkins
MCP servers read via ${JENKINS_*} expansion. Guarded so a missing file does
not break the shell; the file is kept out of the world-readable nix store
because it holds secrets.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Emma Thorpe
2026-07-10 12:31:35 +01:00
co-authored by Claude Opus 4.8
parent 665703fbe6
commit eb89beb97e
+10
View File
@@ -51,6 +51,16 @@
home.shellAliases = { home.shellAliases = {
docker = "/run/current-system/sw/bin/docker"; docker = "/run/current-system/sw/bin/docker";
}; };
# Source the (nix-unmanaged) Jenkins credentials file into every zsh, so the
# JENKINS_UCE_/JENKINS_STF_ tokens are exported for all shells and anything they
# launch -- the Jenkins MCP servers read them via ${JENKINS_*} expansion.
# envExtra lands in ~/.zshenv, which zsh sources for login, interactive, and
# non-interactive shells alike. Guarded so a missing file never breaks a shell;
# the file holds secrets, so it is kept out of the world-readable nix store.
programs.zsh.envExtra = ''
[ -f "$HOME/.jenkinsenv" ] && . "$HOME/.jenkinsenv"
'';
programs.tmux = { programs.tmux = {
# kube context/namespace in the status line. kube-tmux is pinned as a flake # kube context/namespace in the status line. kube-tmux is pinned as a flake
# input (it is not in nixpkgs), so the script is always present in the store. # input (it is not in nixpkgs), so the script is always present in the store.