treefmt-check
checks.aarch64-darwin.treefmt
· build #390
· raw
1treefmt v2.5.0traversed 331 files2emitted 267 files for processing3formatted 267 files (1 changed) in 9.763s4 M docs/WORKLOAD_IDENTITY.md5diff --git a/docs/WORKLOAD_IDENTITY.md b/docs/WORKLOAD_IDENTITY.md6index 3f11b57..08f7ed8 1006447--- a/docs/WORKLOAD_IDENTITY.md8+++ b/docs/WORKLOAD_IDENTITY.md9@@ -117,12 +117,13 @@ with the old key.10 11 ## Building in a remote store12 13-`services.nixbot.buildStore.url` runs `nix build --store <url> --eval-store auto`14-instead of building locally, for example against a nix-grpc-store farm. Outputs15-stay in that store, so it cannot be combined with `uploaders`.16+`services.nixbot.buildStore.url` runs17+`nix build --store <url> --eval-store auto` instead of building locally, for18+example against a nix-grpc-store farm. Outputs stay in that store, so it cannot19+be combined with `uploaders`.20 21 With `buildStore.oidcAudience` set, nixbot writes an ID token for that audience22 to a private file per build, refreshes it every two thirds of `tokenTtl`, and23 points nix at it through the environment variable `buildStore.credentialEnv`24-(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above25-with `effect = "build"`, so the store can match `sub`, `ref` or `event`.26+(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above with27+`effect = "build"`, so the store can match `sub`, `ref` or `event`.