Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

nixserv — Nix Build Server

Purpose

nixserv is the dedicated binary cache and distributed build server for the cluster. It runs Attic backed by PostgreSQL and S3 storage, and acts as a remote build daemon for distributed Nix builds.

Entry Point

Architecture / Services / Scope

Attic Binary Cache

  • Attic: Self-hosted Nix binary cache server, served at cache.racci.dev.
  • Storage is backed by the Storage Coordinator with zstd chunked/compressed NAR storage.
  • The Attic database uses PostgreSQL on the Database Coordinator.
  • Requires proof-of-possession for uploads, with a 14-day default garbage-collection retention period run on a schedule.

Distributed Builds

As a distributedBuilders host, nixserv exposes the builder user over SSH. Other hosts configure nix.distributedBuilds and connect to it as a remote build machine (ssh-ng) to offload Nix builds.

Secrets

Declared secrets

Secret keyPurpose
ATTIC_ENVIRONMENTAttic environment file
POSTGRES/ATTIC_PASSWORDAttic database password

Operational Notes / Assumptions

  • The cache endpoint and the build daemon rely on the Storage Coordinator for object storage and the Database Coordinator for the metadata database.
  • The Attic HTTP endpoint is served through the IO Coordinator reverse proxy.

References