fix(nix): prevent local builds on ATM hardware (max-jobs = 0)
The ATM should never compile from source — only download pre-built binaries from cachix/cache.nixos.org. If a derivation isn't cached, the upgrade fails cleanly instead of trying to build on the mSATA. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
b7858a08c7
commit
7f9e1d2da0
1 changed files with 3 additions and 0 deletions
|
|
@ -108,7 +108,10 @@
|
||||||
security.sudo.wheelNeedsPassword = false;
|
security.sudo.wheelNeedsPassword = false;
|
||||||
|
|
||||||
# Allow lamassu user to use nix commands + pull from aiolabs binary cache
|
# Allow lamassu user to use nix commands + pull from aiolabs binary cache
|
||||||
|
# max-jobs = 0: never build locally — only download from substituters.
|
||||||
|
# If a derivation isn't cached, the build fails instead of compiling on the ATM.
|
||||||
nix.settings = {
|
nix.settings = {
|
||||||
|
max-jobs = 0;
|
||||||
trusted-users = [ "root" "lamassu" ];
|
trusted-users = [ "root" "lamassu" ];
|
||||||
substituters = [ "https://cache.nixos.org" "https://aiolabs.cachix.org" ];
|
substituters = [ "https://cache.nixos.org" "https://aiolabs.cachix.org" ];
|
||||||
trusted-public-keys = [
|
trusted-public-keys = [
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue