feat(nix): add Determinate Nix to douro-installed config

Resolves the cachix binary cache hash mismatch between local dev machines
(Determinate Nix 2.33) and douro (stock Nix 2.18). With both sides using
Determinate Nix, `cachix push` from local builds produces store paths that
douro's 4am auto-upgrade can download directly instead of building from source.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-01 14:45:50 -05:00
commit 31c5376317
2 changed files with 216 additions and 9 deletions

View file

@ -19,9 +19,13 @@
url = "github:cachix/devenv";
inputs.nixpkgs.follows = "nixpkgs-unstable";
};
# Determinate Nix — ensures douro uses same nix version as dev machines
# so cachix binary cache hits match (nix 2.33 hashes == nix 2.33 hashes)
determinate.url = "https://flakehub.com/f/DeterminateSystems/determinate/3";
};
outputs = { self, nixpkgs, nixpkgs-unstable, flake-utils, rust-overlay, devenv }:
outputs = { self, nixpkgs, nixpkgs-unstable, flake-utils, rust-overlay, devenv, determinate }:
let
system = "x86_64-linux";
@ -87,6 +91,7 @@
hardwareModule
./deploy/nixos/configuration.nix
./deploy/nixos/lamassu-atm.nix
determinate.nixosModules.default
({ config, lib, pkgs, ... }: {
services.lamassu-atm = {
enable = true;