feat: Fireworks gateway module for Claude Code and OpenCode - #112
Merged
Merged
Conversation
## Summary
- Adds a Nix-native stand-in for FireConnect, which can't work here: it
rewrites `~/.claude/settings.json` and `~/.config/opencode/opencode.json`
in place, and both are read-only symlinks into the Nix store. The module
writes the settings the CLI would instead. It ships inert — both harness
flags default to `false`, so this commit changes no runtime behavior.
- Pins OpenCode to nixpkgs-unstable. The 1.18.30 in the weekly snapshot
cannot run a single prompt, which blocked testing the gateway at all.
- Routine dependency refresh: `nix flake update` plus a Neovim plugin sync.
## Changes
### home-manager/programs/fireworks.nix (new)
- `enable` is a per-harness attrset (`claude`, `opencode`) so OpenCode can
run on Fireworks while Claude Code stays on stock Anthropic. `anyEnabled`
gates only the shared sops secret.
- Claude Code: `ANTHROPIC_BASE_URL` plus router assignments for the Opus,
Sonnet, Haiku, Fable and subagent model slots, alongside the behavior
tuning FireConnect applies (tool search re-enabled, Explore inherit cap
disabled, server-side auto-mode off, telemetry off).
- OpenCode: a `fireworks-ai` provider block with context/output limits for
the routers, which models.dev doesn't carry. Merges with the existing
ollama provider.
- The API key is kept out of both generated configs, since they land
world-readable in the Nix store and this repo is public. OpenCode reads
the sops secret via `{file:...}` interpolation; Claude Code gets it from
an `ANTHROPIC_CUSTOM_HEADERS` export in fish, as `settings.env` only
holds literals.
- Declares no `ANTHROPIC_API_KEY`: the gateway authenticates on
`X-Fireworks-Api-Key` alone, and setting one makes Claude Code warn that
a claude.ai session and an API key are both present.
- `sops.secrets` is declared only when enabled, so `nix flake check` still
passes for anyone without the key in `secrets/secrets.yaml`.
### home-manager/programs/opencode.nix
- Pin `package` to `pkgs-unstable.opencode` (1.18.31), following the same
pattern as `neovim.nix` and `codex`. 1.18.30 is built with a bun 1.4.2
that mis-splits the bundle, so `SystemPrompt.environment` dereferences an
undefined node and every prompt fails with `undefined is not an object
(evaluating 'a.name')` — surfacing in the TUI as "Failed to send prompt /
Unexpected server error". It fails before any provider is contacted, so
it reads as a credential problem and isn't one. Fixed upstream in 1.18.31
(anomalyco/opencode#48397). Drop the pin once nixpkgs-weekly catches up.
### home-manager/home.nix
- Import `./programs/fireworks.nix`.
### secrets/secrets.yaml
- Add the encrypted `fireworks_api_key` entry; re-encrypted with sops
3.13.3.
### flake.lock
- `home-manager`: `a3dfb88` -> `7b4c5ec` (2026-09-21 -> 2026-09-25)
- `nixpkgs` (DeterminateSystems nixpkgs-weekly): `dc5d91f` -> `ef34387`
(2026-09-07 -> 2026-09-13)
- `nixpkgs-unstable`: `79b35bf` -> `f9bce96` (2026-09-19 -> 2026-09-26)
- `sops-nix`: `7214124` -> `2bd00bd` (2026-09-20 -> 2026-09-24)
### config/nvim/lazy-lock.json
- Bumped: `SchemaStore.nvim`, `codesnap.nvim`, `friendly-snippets`,
`gitsigns.nvim`, `nvim-dap`, `nvim-lspconfig`, `nvim-treesitter`,
`nvim-web-devicons`, `render-markdown.nvim`.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
~/.claude/settings.jsonand~/.config/opencode/opencode.jsonin place, and both are read-only symlinks into the Nix store. The module writes the settings the CLI would instead. It ships inert — both harness flags default tofalse, so this commit changes no runtime behavior.nix flake updateplus a Neovim plugin sync.Changes
home-manager/programs/fireworks.nix (new)
enableis a per-harness attrset (claude,opencode) so OpenCode can run on Fireworks while Claude Code stays on stock Anthropic.anyEnabledgates only the shared sops secret.ANTHROPIC_BASE_URLplus router assignments for the Opus, Sonnet, Haiku, Fable and subagent model slots, alongside the behavior tuning FireConnect applies (tool search re-enabled, Explore inherit cap disabled, server-side auto-mode off, telemetry off).fireworks-aiprovider block with context/output limits for the routers, which models.dev doesn't carry. Merges with the existing ollama provider.{file:...}interpolation; Claude Code gets it from anANTHROPIC_CUSTOM_HEADERSexport in fish, assettings.envonly holds literals.ANTHROPIC_API_KEY: the gateway authenticates onX-Fireworks-Api-Keyalone, and setting one makes Claude Code warn that a claude.ai session and an API key are both present.sops.secretsis declared only when enabled, sonix flake checkstill passes for anyone without the key insecrets/secrets.yaml.home-manager/programs/opencode.nix
packagetopkgs-unstable.opencode(1.18.31), following the same pattern asneovim.nixandcodex. 1.18.30 is built with a bun 1.4.2 that mis-splits the bundle, soSystemPrompt.environmentdereferences an undefined node and every prompt fails withundefined is not an object (evaluating 'a.name')— surfacing in the TUI as "Failed to send prompt / Unexpected server error". It fails before any provider is contacted, so it reads as a credential problem and isn't one. Fixed upstream in 1.18.31 (fix(core): break filesystem cycle in compiled prompts anomalyco/opencode#48397). Drop the pin once nixpkgs-weekly catches up.home-manager/home.nix
./programs/fireworks.nix.secrets/secrets.yaml
fireworks_api_keyentry; re-encrypted with sops 3.13.3.flake.lock
home-manager:a3dfb88->7b4c5ec(2026-09-21 -> 2026-09-25)nixpkgs(DeterminateSystems nixpkgs-weekly):dc5d91f->ef34387(2026-09-07 -> 2026-09-13)nixpkgs-unstable:79b35bf->f9bce96(2026-09-19 -> 2026-09-26)sops-nix:7214124->2bd00bd(2026-09-20 -> 2026-09-24)config/nvim/lazy-lock.json
SchemaStore.nvim,codesnap.nvim,friendly-snippets,gitsigns.nvim,nvim-dap,nvim-lspconfig,nvim-treesitter,nvim-web-devicons,render-markdown.nvim.