Report Hydra jobs to GitHub and publish successful closures to Cachix #3

Merged
ams-tech merged 2 commits from codex/hydra-github-ci into main 2026-09-27 14:46:37 -04:00
ams-tech commented 2026-09-27 12:46:13 -04:00 (Migrated from github.com)

Hydra now supports per-job GitHub commit statuses for both Kaiba main jobsets and retryable publication of successful provisioning build closures to Cachix. Tokens are loaded through systemd credentials and kept out of the Nix store and Hydra backups.

The notifier uses each dependent build's own evaluation and persists HTTP failures for retry. Publication validates the ten-job ARM64 inventory, includes build dependencies, and retains failed uploads. Both integrations are opt-in; the runbook covers setup, rotation, diagnostics and rollback.

Validation: 22 Python tests in the locked Nix environment; 10 assertions against the patched native Hydra notifier; full Hydra/PostgreSQL VM integration test with credential isolation, publication retry, service restart and backup restoration. The companion provisioning change keeps PR/manual builders on GitHub and gates main delegation behind a repository variable.

Live acceptance on Ace: the service-only candidate test-activated with the existing kernel and pilot identity intact. Both repositories now have their expected GitHub success statuses, the notification retry queue drained after credential correction, and all ten provisioning closures were published successfully. The exact-commit waiter also passed from an external GitHub runner: https://github.com/PseudoDesign/kaiba-provisioning/actions/runs/36335709462. Companion PRs: PseudoDesign/nix-pseudo-design#9 and PseudoDesign/kaiba-provisioning#92.

Hydra now supports per-job GitHub commit statuses for both Kaiba main jobsets and retryable publication of successful provisioning build closures to Cachix. Tokens are loaded through systemd credentials and kept out of the Nix store and Hydra backups. The notifier uses each dependent build's own evaluation and persists HTTP failures for retry. Publication validates the ten-job ARM64 inventory, includes build dependencies, and retains failed uploads. Both integrations are opt-in; the runbook covers setup, rotation, diagnostics and rollback. Validation: 22 Python tests in the locked Nix environment; 10 assertions against the patched native Hydra notifier; full Hydra/PostgreSQL VM integration test with credential isolation, publication retry, service restart and backup restoration. The companion provisioning change keeps PR/manual builders on GitHub and gates main delegation behind a repository variable. Live acceptance on Ace: the service-only candidate test-activated with the existing kernel and pilot identity intact. Both repositories now have their expected GitHub success statuses, the notification retry queue drained after credential correction, and all ten provisioning closures were published successfully. The exact-commit waiter also passed from an external GitHub runner: https://github.com/PseudoDesign/kaiba-provisioning/actions/runs/36335709462. Companion PRs: PseudoDesign/nix-pseudo-design#9 and PseudoDesign/kaiba-provisioning#92.
Sign in to join this conversation.
No description provided.