- Python 58.1%
- Nix 40%
- Perl 1.6%
- Go Template 0.3%
|
|
||
|---|---|---|
| ci | ||
| client | ||
| docs | ||
| examples | ||
| identity | ||
| modules | ||
| packages | ||
| patches | ||
| tests | ||
| .gitattributes | ||
| .gitignore | ||
| flake.lock | ||
| flake.nix | ||
| README.md | ||
Kaiba infrastructure
This repository owns the development infrastructure for Kaiba: build scheduling,
builders, caches, and eventually the Git forge. Application repositories expose
Nix checks and packages; this repository decides which revisions and jobs to
build and where to run them. Device protocol and state contracts remain in
kaiba-contracts.
Hydra on Ace
The flake exports Nix-packaged Python tests, an ARM64 hydraJobs output,
NixOS modules for Hydra, Mako's HTTPS proxy and backup receiver, and native
qualification/integration tests. See the deployment runbook
for deployment, staged jobset setup, backups and recovery.
nix build --no-link .#checks.x86_64-linux.selector
python3 ci/setup_hydra.py # preview; provisioning starts disabled
kaiba-provisioning imports the locked inventory policy to expose the ten ARM64
derivations to Hydra. Hydra evaluates each repository's main directly; GitHub
Actions remains the PR gate during rollout.
Human passkey access
The flake also exports Keycloak, SSH certificate issuer, host trust, and encrypted
backup modules, plus the Linux kaiba-login package. See the
human access runbook for deployment, initial owner
enrollment, workstation login, revocation, and recovery. Human credentials remain
separate from pilot device identities and automation credentials.
Selector prototype
ci/select_jobs.py compares evaluated derivation paths for a fixed job inventory at the base
and proposed revisions. It emits JSON listing jobs to build and why. It does
not schedule Hydra builds. Provisioning's GitHub Actions workflow now uses
derivation-based selection independently of this Hydra rollout.
python3 -m unittest discover -s tests
python3 ci/select_jobs.py \
--inventory ci/provisioning-arm64.json \
--base examples/base.json --head examples/head.json
The example selects the single check whose derivation differs. Add
--changed-path .github/workflows/ci.yml to demonstrate a conservative full
selection after a workflow change. The manifests contain synthetic derivation
paths for demonstration; they are not evaluated repository revisions.
See the CI design for the evaluation boundary, rollout order, and prerequisites before using selection in a required check.
Ownership
| Repository | Owns |
|---|---|
| Kaiba project repos | Flake outputs, tests, application packages and modules |
kaiba-infra |
CI policy, job inventory, builders, caches, and human access infrastructure |
nix-pseudo-design |
Existing personal host configurations until deliberately migrated |
kaiba-contracts |
Product and device state contracts |
Host-specific addresses and module composition live in nix-pseudo-design.
Private keys and administrator credentials remain outside Git and the Nix store.