# Flake CI. Formatting (treefmt) runs on *every* PR; the heavier Nix work # (deadnix/statix/pre-commit lints + per-host evaluation) runs only when the # change can affect it. name: CI # Deliberately no `paths:` filter. This job is a required status check on main, # and a path-filtered workflow is *skipped* (never runs) for PRs that touch no # matching file -- which leaves the required check pending forever and blocks the # merge (e.g. a .renovaterc.json-only change). So the workflow always runs and # always reports. # # Two tiers of checks: # * Formatting always runs. treefmt covers Markdown, YAML, and JSON as well as # Nix and shell, so a docs- or config-only PR must be format-checked too. It # is cheap (no host evaluation). # * The heavy steps (full `nix flake check` + host evals) run only when a .nix # file, flake.lock, or this workflow changed; otherwise they skip and the job # still passes, keeping the required check green-reportable. on: push: branches: [main] pull_request: jobs: flake: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7 with: # Full history so the detect step can diff the PR against its base. fetch-depth: 0 # Decide whether the *heavy* Nix steps need to run. On a pull_request, diff # against the base for files that can affect them: any .nix, the lockfile, # or this workflow. On any other event (push to main) always run. The # formatting step below is unaffected -- it always runs. - name: Detect Nix-relevant changes id: detect run: | set -euo pipefail if [ "${{ github.event_name }}" != "pull_request" ]; then echo "Event ${{ github.event_name }}: running full checks." echo "run=true" >> "$GITHUB_OUTPUT" exit 0 fi base='${{ github.event.pull_request.base.sha }}' head='${{ github.event.pull_request.head.sha }}' changed=$(git diff --name-only "$base...$head") echo "Changed files:" echo "$changed" if echo "$changed" | grep -Eq '(\.nix$|^flake\.lock$|^\.gitea/workflows/ci\.yaml$)'; then echo "Nix-relevant changes found: running heavy checks." echo "run=true" >> "$GITHUB_OUTPUT" else echo "No Nix-relevant changes: heavy checks skip (formatting still runs)." echo "run=false" >> "$GITHUB_OUTPUT" fi # Nix drives the formatting check, so install it unconditionally. - name: Install Nix uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31 with: extra_nix_config: | experimental-features = nix-command flakes accept-flake-config = true substituters = https://cache.nixos.org https://nix-community.cachix.org trusted-public-keys = cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY= nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs= # Always run: treefmt formats Markdown/YAML/JSON (docs + config) as well as # Nix and shell, so documentation-only PRs are format-checked too. This is # the cheap gate (no host evaluation) and pre-builds the `formatting` # derivation that the flake check below reuses from cache. - name: Formatting check run: nix build --print-build-logs '.#checks.x86_64-linux.formatting' # Runs every flake check: treefmt formatting, deadnix, statix, and the # pre-commit hooks (so a --no-verify commit can't ship unlinted). - name: Flake check if: steps.detect.outputs.run == 'true' run: nix flake check --print-build-logs # Evaluate (not build) each host's toplevel so eval errors fail CI cheaply. # aarch64 / darwin hosts evaluate fine on an x86_64 runner; only building # would need emulation, which we deliberately avoid here. # # Host lists are discovered from the flake (attrNames of # nixos/darwinConfigurations) rather than hard-coded, so adding or removing # a host needs no change to this workflow. - name: Evaluate NixOS host configurations if: steps.detect.outputs.run == 'true' run: | set -euo pipefail hosts=$(nix eval --raw '.#nixosConfigurations' \ --apply 'cfgs: builtins.concatStringsSep "\n" (builtins.attrNames cfgs)') for host in $hosts; do echo "::group::eval $host" nix eval --raw ".#nixosConfigurations.$host.config.system.build.toplevel.drvPath" echo echo "::endgroup::" done - name: Evaluate Darwin host configurations if: steps.detect.outputs.run == 'true' run: | set -euo pipefail hosts=$(nix eval --raw '.#darwinConfigurations' \ --apply 'cfgs: builtins.concatStringsSep "\n" (builtins.attrNames cfgs)') for host in $hosts; do echo "::group::eval $host" nix eval --raw ".#darwinConfigurations.$host.config.system.build.toplevel.drvPath" echo echo "::endgroup::" done