No description
  • Python 58.1%
  • Nix 40%
  • Perl 1.6%
  • Go Template 0.3%
Find a file
Adam f12f33f45b
Merge pull request #5 from PseudoDesign/codex/passkey-human-login
Add passkey human logins and short-lived SSH certificates
2026-09-28 23:20:28 -04:00
ci Create immutable Hydra jobsets for PR and manual CI runs (#4) 2026-09-28 16:00:19 -04:00
client Harden identity startup and complete real passkey client flow 2026-09-28 22:44:52 -04:00
docs Add passkey human identity and short-lived SSH access 2026-09-28 22:25:43 -04:00
examples Establish Kaiba CI infrastructure boundary and ARM64 selector 2026-09-26 17:56:26 -04:00
identity Harden identity startup and complete real passkey client flow 2026-09-28 22:44:52 -04:00
modules Retain Nix closure context for custom OIDC trust bundles 2026-09-28 22:53:45 -04:00
packages Add passkey human identity and short-lived SSH access 2026-09-28 22:25:43 -04:00
patches Report Hydra jobs to GitHub and publish successful closures to Cachix (#3) 2026-09-27 14:46:36 -04:00
tests Harden identity startup and complete real passkey client flow 2026-09-28 22:44:52 -04:00
.gitattributes Add passkey human identity and short-lived SSH access 2026-09-28 22:25:43 -04:00
.gitignore Establish Kaiba CI infrastructure boundary and ARM64 selector 2026-09-26 17:56:26 -04:00
flake.lock feat: add staged Hydra CI and backup modules for Ace 2026-09-26 20:25:31 -04:00
flake.nix Add passkey human identity and short-lived SSH access 2026-09-28 22:25:43 -04:00
README.md Add passkey human identity and short-lived SSH access 2026-09-28 22:25:43 -04:00

Kaiba infrastructure

This repository owns the development infrastructure for Kaiba: build scheduling, builders, caches, and eventually the Git forge. Application repositories expose Nix checks and packages; this repository decides which revisions and jobs to build and where to run them. Device protocol and state contracts remain in kaiba-contracts.

Hydra on Ace

The flake exports Nix-packaged Python tests, an ARM64 hydraJobs output, NixOS modules for Hydra, Mako's HTTPS proxy and backup receiver, and native qualification/integration tests. See the deployment runbook for deployment, staged jobset setup, backups and recovery.

nix build --no-link .#checks.x86_64-linux.selector
python3 ci/setup_hydra.py  # preview; provisioning starts disabled

kaiba-provisioning imports the locked inventory policy to expose the ten ARM64 derivations to Hydra. Hydra evaluates each repository's main directly; GitHub Actions remains the PR gate during rollout.

Human passkey access

The flake also exports Keycloak, SSH certificate issuer, host trust, and encrypted backup modules, plus the Linux kaiba-login package. See the human access runbook for deployment, initial owner enrollment, workstation login, revocation, and recovery. Human credentials remain separate from pilot device identities and automation credentials.

Selector prototype

ci/select_jobs.py compares evaluated derivation paths for a fixed job inventory at the base and proposed revisions. It emits JSON listing jobs to build and why. It does not schedule Hydra builds. Provisioning's GitHub Actions workflow now uses derivation-based selection independently of this Hydra rollout.

python3 -m unittest discover -s tests
python3 ci/select_jobs.py \
  --inventory ci/provisioning-arm64.json \
  --base examples/base.json --head examples/head.json

The example selects the single check whose derivation differs. Add --changed-path .github/workflows/ci.yml to demonstrate a conservative full selection after a workflow change. The manifests contain synthetic derivation paths for demonstration; they are not evaluated repository revisions.

See the CI design for the evaluation boundary, rollout order, and prerequisites before using selection in a required check.

Ownership

Repository Owns
Kaiba project repos Flake outputs, tests, application packages and modules
kaiba-infra CI policy, job inventory, builders, caches, and human access infrastructure
nix-pseudo-design Existing personal host configurations until deliberately migrated
kaiba-contracts Product and device state contracts

Host-specific addresses and module composition live in nix-pseudo-design. Private keys and administrator credentials remain outside Git and the Nix store.