this derivation will be built: /nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv building '/nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv' on 'ssh-ng://customer@mac02' building '/nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv' treefmt-check> treefmt v2.5.0traversed 331 files treefmt-check> emitted 267 files for processing treefmt-check> formatted 267 files (1 changed) in 9.763s treefmt-check> M docs/WORKLOAD_IDENTITY.md treefmt-check> diff --git a/docs/WORKLOAD_IDENTITY.md b/docs/WORKLOAD_IDENTITY.md treefmt-check> index 3f11b57..08f7ed8 100644 treefmt-check> --- a/docs/WORKLOAD_IDENTITY.md treefmt-check> +++ b/docs/WORKLOAD_IDENTITY.md treefmt-check> @@ -117,12 +117,13 @@ with the old key. treefmt-check> treefmt-check> ## Building in a remote store treefmt-check> treefmt-check> -`services.nixbot.buildStore.url` runs `nix build --store --eval-store auto` treefmt-check> -instead of building locally, for example against a nix-grpc-store farm. Outputs treefmt-check> -stay in that store, so it cannot be combined with `uploaders`. treefmt-check> +`services.nixbot.buildStore.url` runs treefmt-check> +`nix build --store --eval-store auto` instead of building locally, for treefmt-check> +example against a nix-grpc-store farm. Outputs stay in that store, so it cannot treefmt-check> +be combined with `uploaders`. treefmt-check> treefmt-check> With `buildStore.oidcAudience` set, nixbot writes an ID token for that audience treefmt-check> to a private file per build, refreshes it every two thirds of `tokenTtl`, and treefmt-check> points nix at it through the environment variable `buildStore.credentialEnv` treefmt-check> -(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above treefmt-check> -with `effect = "build"`, so the store can match `sub`, `ref` or `event`. treefmt-check> +(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above with treefmt-check> +`effect = "build"`, so the store can match `sub`, `ref` or `event`. error: build of '/nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv' on 'ssh-ng://customer@mac02' failed: Cannot build '/nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/h5nip7nxvdjr7f3bnqsph7rf3h5ksy06-treefmt-check Last 25 log lines: > formatted 267 files (1 changed) in 9.763s > M docs/WORKLOAD_IDENTITY.md > diff --git a/docs/WORKLOAD_IDENTITY.md b/docs/WORKLOAD_IDENTITY.md > index 3f11b57..08f7ed8 100644 > --- a/docs/WORKLOAD_IDENTITY.md > +++ b/docs/WORKLOAD_IDENTITY.md > @@ -117,12 +117,13 @@ with the old key. > > ## Building in a remote store > > -`services.nixbot.buildStore.url` runs `nix build --store --eval-store auto` > -instead of building locally, for example against a nix-grpc-store farm. Outputs > -stay in that store, so it cannot be combined with `uploaders`. > +`services.nixbot.buildStore.url` runs > +`nix build --store --eval-store auto` instead of building locally, for > +example against a nix-grpc-store farm. Outputs stay in that store, so it cannot > +be combined with `uploaders`. > > With `buildStore.oidcAudience` set, nixbot writes an ID token for that audience > to a private file per build, refreshes it every two thirds of `tokenTtl`, and > points nix at it through the environment variable `buildStore.credentialEnv` > -(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above > -with `effect = "build"`, so the store can match `sub`, `ref` or `event`. > +(default `NIX_GRPC_TOKEN_FILE`). The claims are the ones above with > +`effect = "build"`, so the store can match `sub`, `ref` or `event`. For full logs, run: nix log /nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv error: Cannot build '/nix/store/s0g3lrl0r593ysmdhqhjvz7l1mnaj2m0-treefmt-check.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/h5nip7nxvdjr7f3bnqsph7rf3h5ksy06-treefmt-check