nixbot

builds

failed treefmt-check checks.x86_64-linux.treefmt · build #390 · raw

1tribuchet: building on jamie2treefmt v2.5.0traversed 331 files3emitted 267 files for processing4formatted 267 files (1 changed) in 8.819s5 M docs/WORKLOAD_IDENTITY.md6diff --git a/docs/WORKLOAD_IDENTITY.md b/docs/WORKLOAD_IDENTITY.md7index 3f11b57..08f7ed8 1006448--- a/docs/WORKLOAD_IDENTITY.md9+++ b/docs/WORKLOAD_IDENTITY.md10@@ -117,12 +117,13 @@ with the old key.11 12 ## Building in a remote store13 14-`services.nixbot.buildStore.url` runs `nix build --store <url> --eval-store auto`15-instead of building locally, for example against a nix-grpc-store farm. Outputs16-stay in that store, so it cannot be combined with `uploaders`.17+`services.nixbot.buildStore.url` runs18+`nix build --store <url> --eval-store auto` instead of building locally, for19+example against a nix-grpc-store farm. Outputs stay in that store, so it cannot20+be combined with `uploaders`.21 22 With `buildStore.oidcAudience` set, nixbot writes an ID token for that audience23 to a private file per build, refreshes it every two thirds of `tokenTtl`, and24 points nix at it through the environment variable `buildStore.credentialEnv`25-(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above26-with `effect = "build"`, so the store can match `sub`, `ref` or `event`.27+(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above with28+`effect = "build"`, so the store can match `sub`, `ref` or `event`.