fix(nix): prevent local builds on ATM hardware (max-jobs = 0)

The ATM should never compile from source — only download pre-built
binaries from cachix/cache.nixos.org. If a derivation isn't cached,
the upgrade fails cleanly instead of trying to build on the mSATA.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-02 14:58:26 -05:00
commit 7f9e1d2da0

View file

@ -108,7 +108,10 @@
security.sudo.wheelNeedsPassword = false;
# Allow lamassu user to use nix commands + pull from aiolabs binary cache
# max-jobs = 0: never build locally — only download from substituters.
# If a derivation isn't cached, the build fails instead of compiling on the ATM.
nix.settings = {
max-jobs = 0;
trusted-users = [ "root" "lamassu" ];
substituters = [ "https://cache.nixos.org" "https://aiolabs.cachix.org" ];
trusted-public-keys = [