tribuchet: building on eliza treefmt v2.5.0traversed 331 files emitted 267 files for processing formatted 267 files (0 changed) in 11.317s M docs/WORKLOAD_IDENTITY.md diff --git a/docs/WORKLOAD_IDENTITY.md b/docs/WORKLOAD_IDENTITY.md index 3f11b57..08f7ed8 100644 --- a/docs/WORKLOAD_IDENTITY.md +++ b/docs/WORKLOAD_IDENTITY.md @@ -117,12 +117,13 @@ with the old key. ## Building in a remote store -`services.nixbot.buildStore.url` runs `nix build --store --eval-store auto` -instead of building locally, for example against a nix-grpc-store farm. Outputs -stay in that store, so it cannot be combined with `uploaders`. +`services.nixbot.buildStore.url` runs +`nix build --store --eval-store auto` instead of building locally, for +example against a nix-grpc-store farm. Outputs stay in that store, so it cannot +be combined with `uploaders`. With `buildStore.oidcAudience` set, nixbot writes an ID token for that audience to a private file per build, refreshes it every two thirds of `tokenTtl`, and points nix at it through the environment variable `buildStore.credentialEnv` -(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above -with `effect = "build"`, so the store can match `sub`, `ref` or `event`. +(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above with +`effect = "build"`, so the store can match `sub`, `ref` or `event`.