Conversation
Adds a Nix flake so the project can be installed and run directly
from GitHub without manual compilation:
nix run github:coleam00/Archon
nix profile install github:coleam00/Archon
Adds devbox.json for reproducible development environments:
devbox shell
devbox run build
Also updates README install instructions to include Nix and Devbox.
Note: Pre-existing test failures documented (missing dependencies
in nix-shell environment, not caused by Nix changes).
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
✅ Files skipped from review due to trivial changes (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughThis PR adds Nix flake support to enable Nix users to install Archon with a single command. It introduces a flake.nix that fetches platform-specific release binaries, a devbox.json for reproducible development, and updates documentation and .gitignore for Nix artifacts. ChangesNix Flake Distribution and Development Setup
Sequence Diagram(s)sequenceDiagram
participant User as User
participant Flake as flake.nix
participant GitHub as github.com:Releases
participant Stdenv as nixpkgs:stdenv
User->>Flake: run `nix run github:coleam00/Archon` or `nix profile install`
Flake->>GitHub: fetch platform-specific release asset (v0.3.12)
Flake->>Stdenv: wrap asset in stdenv.mkDerivation (install to $out/bin/archon)
Stdenv-->>User: provide runnable `archon` via flake app/profile
🎯 3 (Moderate) | ⏱️ ~20 minutes
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
flake.nix (1)
24-32: Document the version and hash update process for maintainers.The flake hardcodes version
0.3.12and platform-specific SHA256 hashes. When releasing a new version, both the URL (line 25), the version field (line 37), and all four hashes (lines 27-30) must be updated in sync.Consider documenting this in a comment or adding a note to the release workflow to update the flake as part of the release checklist.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@flake.nix` around lines 24 - 32, The flake pins Archon at v0.3.12 with platform-specific SHA256s in the archon-bin fetchurl block (see url "https://github.com/coleam00/Archon/releases/download/v0.3.12/${selectBinary}" and the per-platform sha256 map keyed by ${platform}), so update instructions are needed; add a brief comment above the archon-bin definition documenting the exact steps maintainers must do when bumping versions: update the URL version token (vX.Y.Z), regenerate or compute all four platform SHA256 values, and update the separate "version" field used elsewhere in the flake/release workflow, or alternatively add a note in the repository release checklist/workflow to run the hash generation and update these fields in sync.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@flake.nix`:
- Around line 24-32: The flake pins Archon at v0.3.12 with platform-specific
SHA256s in the archon-bin fetchurl block (see url
"https://github.com/coleam00/Archon/releases/download/v0.3.12/${selectBinary}"
and the per-platform sha256 map keyed by ${platform}), so update instructions
are needed; add a brief comment above the archon-bin definition documenting the
exact steps maintainers must do when bumping versions: update the URL version
token (vX.Y.Z), regenerate or compute all four platform SHA256 values, and
update the separate "version" field used elsewhere in the flake/release
workflow, or alternatively add a note in the repository release
checklist/workflow to run the hash generation and update these fields in sync.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 0008aed5-69a5-4b18-bc12-c5dec36f99df
📒 Files selected for processing (4)
.gitignoreREADME.mddevbox.jsonflake.nix
Review SummaryVerdict: minor-fixes-needed Your PR adds Nix flake and Devbox support — a great addition for users who prefer Nixpkgs-managed packages. The README was updated correctly. However, the Starlight docs site is missing the new Nix install block entirely on two user-facing pages. Blocking issues
Suggested fixes
Minor / nice-to-have
Compliments
Reviewed via maintainer-review-pr workflow (Pi/Minimax). Aspects run: code-review, docs-impact. |
- Add Nix (Flakes) subsection to installation.md with run/profile commands - Add Nix code block to hero/install splash on index.mdx - Add Nix flake checksum update instructions to releasing.md - Remove nodejs_20 from devbox.json (bun is sufficient)
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/docs-web/src/content/docs/contributing/releasing.md`:
- Around line 80-103: Rename the duplicate "### 4" after the "Update Nix Flake
(Optional)" section to "### 5" so the subsequent "Verify the Release" heading is
numbered properly, and update the description about the sha256 map to state that
the hashes belong to the `fetchurl` hash map (not the `selectBinary` block);
keep the note about updating `version = "X.Y.Z"` and the sha256 map but change
the reference from `selectBinary` to `fetchurl` so readers edit the correct
field in flake.nix.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 663d0eec-1137-4ed5-ae41-a8f9fe160359
📒 Files selected for processing (4)
devbox.jsonpackages/docs-web/src/content/docs/contributing/releasing.mdpackages/docs-web/src/content/docs/getting-started/installation.mdpackages/docs-web/src/content/docs/index.mdx
| ### 4. Update Nix Flake (Optional) | ||
|
|
||
| After the release workflow completes, update `flake.nix` to use the new version: | ||
|
|
||
| ```bash | ||
| # 1. Update the version string in flake.nix | ||
| # 2. Prefetch the new binary hashes for all platforms | ||
| nix-prefetch-url --type sha256 https://github.com/coleam00/Archon/releases/download/vX.Y.Z/archon-darwin-arm64 | ||
| nix-prefetch-url --type sha256 https://github.com/coleam00/Archon/releases/download/vX.Y.Z/archon-darwin-x64 | ||
| nix-prefetch-url --type sha256 https://github.com/coleam00/Archon/releases/download/vX.Y.Z/archon-linux-arm64 | ||
| nix-prefetch-url --type sha256 https://github.com/coleam00/Archon/releases/download/vX.Y.Z/archon-linux-x64 | ||
|
|
||
| # 3. Update the sha256 map in flake.nix with the new hashes | ||
| # 4. Commit the changes | ||
| git add flake.nix | ||
| git commit -m "chore: update Nix flake to vX.Y.Z" | ||
| git push origin main | ||
| ``` | ||
|
|
||
| The fields to change in `flake.nix`: | ||
| - `version = "X.Y.Z"` (line near the top) | ||
| - `sha256` map in the `selectBinary` block (one hash per platform) | ||
|
|
||
| ### 4. Verify the Release |
There was a problem hiding this comment.
Fix step numbering and flake.nix field location text.
Two doc inaccuracies here: this introduces a second “### 4” (next section should become step 5), and the sha256 map is described as being in the selectBinary block even though it belongs to the fetchurl hash map. Please correct both to avoid release-process mistakes.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/docs-web/src/content/docs/contributing/releasing.md` around lines 80
- 103, Rename the duplicate "### 4" after the "Update Nix Flake (Optional)"
section to "### 5" so the subsequent "Verify the Release" heading is numbered
properly, and update the description about the sha256 map to state that the
hashes belong to the `fetchurl` hash map (not the `selectBinary` block); keep
the note about updating `version = "X.Y.Z"` and the sha256 map but change the
reference from `selectBinary` to `fetchurl` so readers edit the correct field in
flake.nix.
|
Addressed review feedback. Ready for re-review. |
|
@$levonk related to #1696 — overlapping area or partial fix. |
|
@$levonk related to #1766 — overlapping area or partial fix. |
|
@$levonk related to #1696 — overlapping area or partial fix. |
|
@$levonk related to #1766 — overlapping area or partial fix. |
Review SummaryVerdict: minor-fixes-needed Adds Nix flake support for running Archon via Blocking issues
Suggested fixes(none — no HIGH findings) Minor / nice-to-have
ComplimentsSolid infrastructure PR. The Nix flake is comprehensive (Darwin support, sops-nix, nix-darwin compatible, proper Reviewed via maintainer-review-pr workflow (Pi/Minimax). Aspects run: code-review, docs-impact. |
- Renumber Nix Flake section from ### 4 to ### 5 - Renumber Verify the Release section from ### 4 to ### 6 - Add comment to flake.nix version line for discoverability
d21411b to
50dc9c9
Compare
|
Nice catch, ready for re-review |
|
Closing after review — the current shape is a maintenance liability rather than a reproducibility win: the flake fetches a hardcoded prebuilt binary (pinned to v0.3.12, already several releases behind) with hand-pasted hashes that would need manual re-syncing every release, no CI exercises the Nix path (it would rot silently), and the branch commits a machine-local artifact (.devbox/gen/scripts/.hooks.sh with a hardcoded user path). If there's real demand for Nix support, the acceptable form is a source-building flake gated by |
Summary
nix run github:owner/repopattern for reproducible installationsUX Journey
Before
After
Architecture Diagram
Before
After
Connection inventory:
Label Snapshot
risk: lowsize: Sclicli:installationChange Metadata
featurecliLinked Issue
Validation Evidence (required)
Commands and result summary:
Result: Passed successfully on x86_64-darwin. Warning about incompatible systems is expected (only current system checked by default).
nix build .#packages.defaultResult: Successfully built archon package from v0.3.12 binary release.
nix flake checkoutput showing successful validationbun run testskipped because it requires full dependency installation viabun installwhich is not applicable in Nix context; Nix changes are isolated to installation method and don't affect application codeSecurity Impact (required)
No)No) - Downloads from existing GitHub releases (already happens with curl/brew)No)No)Compatibility / Migration
Yes) - Existing installation methods (curl, brew, bun) unchangedNo)No)Human Verification (required)
What was personally validated beyond CI:
nix flake checkpassed, binary download hashes verified for all platforms (x86_64-linux, aarch64-linux, x86_64-darwin, aarch64-darwin)Side Effects / Blast Radius (required)
Rollback Plan (required)
Risks and Mitigations
Closes #1766 (nice!)
Summary by CodeRabbit
Documentation
Chores