feat: nix flake with package, NixOS module and dev shell

nix run / nix build produce a wrapped CLI that pins libpcsclite by store
path, the package build runs the test suite (so nix flake check is CI),
programs.boltcard-writer.enable installs it and turns on pcscd, and
nix develop / nix-shell give the uv workflow used on Arch.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-09-20 21:53:07 +02:00
commit 959b6ea17d
4 changed files with 132 additions and 7 deletions

View file

@ -164,14 +164,31 @@ If the user cannot access the reader (permission errors from pcscd), Arch's
pcsclite uses polkit: the session must be a local active login, or add a rule
for `org.debian.pcsc-lite.access_pcsc` / `access_card`.
## NixOS
## Nix / NixOS
```nix
services.pcscd.enable = true; # ships the ccid driver
The repo is a flake. Run it without installing anything:
```sh
nix run git+https://git.atitlan.io/aiolabs/boltcard-writer -- readers
nix run git+https://git.atitlan.io/aiolabs/boltcard-writer -- write '<auth link>'
```
then in the repo `nix-shell` (provides `uv` + `libpcsclite`) and use
`uv run boltcard-writer …` as above.
pcscd must be running on the host (`services.pcscd.enable = true;` on NixOS,
which also ships the CCID driver). On NixOS the module does that for you:
```nix
{
inputs.boltcard-writer.url = "git+https://git.atitlan.io/aiolabs/boltcard-writer";
# in your configuration:
imports = [ inputs.boltcard-writer.nixosModules.default ];
programs.boltcard-writer.enable = true; # installs the CLI + pcsc_scan, enables pcscd
}
```
`packages.default` / `overlays.default` expose the package on its own. The
package build runs the test suite, so `nix flake check` doubles as CI. For
hacking, `nix develop` (or `nix-shell`) gives `uv`, Python and `libpcsclite`;
then `uv run boltcard-writer …` and `uv run pytest` work as on Arch.
## Development