this derivation will be built: /nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv error: build of '/nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv' on 'ssh-ng://customer@mac02' failed: Cannot build '/nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/h5nip7nxvdjr7f3bnqsph7rf3h5ksy06-treefmt-check Last 25 log lines: > formatted 267 files (1 changed) in 9.763s > M docs/WORKLOAD_IDENTITY.md > diff --git a/docs/WORKLOAD_IDENTITY.md b/docs/WORKLOAD_IDENTITY.md > index 3f11b57..08f7ed8 100644 > --- a/docs/WORKLOAD_IDENTITY.md > +++ b/docs/WORKLOAD_IDENTITY.md > @@ -117,12 +117,13 @@ with the old key. > > ## Building in a remote store > > -`services.nixbot.buildStore.url` runs `nix build --store --eval-store auto` > -instead of building locally, for example against a nix-grpc-store farm. Outputs > -stay in that store, so it cannot be combined with `uploaders`. > +`services.nixbot.buildStore.url` runs > +`nix build --store --eval-store auto` instead of building locally, for > +example against a nix-grpc-store farm. Outputs stay in that store, so it cannot > +be combined with `uploaders`. > > With `buildStore.oidcAudience` set, nixbot writes an ID token for that audience > to a private file per build, refreshes it every two thirds of `tokenTtl`, and > points nix at it through the environment variable `buildStore.credentialEnv` > -(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above > -with `effect = "build"`, so the store can match `sub`, `ref` or `event`. > +(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above with > +`effect = "build"`, so the store can match `sub`, `ref` or `event`. For full logs, run: nix log /nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv error: Cannot build '/nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/h5nip7nxvdjr7f3bnqsph7rf3h5ksy06-treefmt-check