Skip to content

Commit 874b40c

Browse files
feat(nix): add Nix flake for building, developing, and containerizing OpenShell
- flake.nix coordinates modular Nix files under ./nix/ - builds all 3 binaries (openshell, openshell-server, openshell-sandbox) - dev shell provides rustc, cargo, clippy, rustfmt, protoc, kubectl, helm - OCI container image via dockerTools (~48 MiB compressed, ~131 MiB uncompressed, non-root) - 15 container smoke tests via nix run .#container-test - source filtering for reproducible builds without .git or target/ - README covers usage, architecture, tested results, and a sandboxing comparison between Nix and OpenShell (honest about both strengths and weaknesses) - .gitignore updated for /result symlink
1 parent 834f8aa commit 874b40c

10 files changed

Lines changed: 818 additions & 0 deletions

File tree

‎.gitignore‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -193,6 +193,9 @@ mise.local.toml
193193
# Ignore plans for now
194194
architecture/plans
195195

196+
# Nix build output
197+
result
198+
196199
# Claude
197200
.claude/settings.local.json.claude/worktrees/
198201
.claude/worktrees/

‎flake.lock‎

Lines changed: 59 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎flake.nix‎

Lines changed: 93 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,93 @@
1+
# Quick start:
2+
#
3+
# nix build Build all 3 binaries (openshell, openshell-server, openshell-sandbox)
4+
# nix run Run openshell (default binary)
5+
# nix run -- --help Show CLI help
6+
# nix run -- --version Show version
7+
# nix develop Enter the dev shell (rustc, cargo, clippy, protoc, kubectl, helm, ...)
8+
# nix develop -c cargo build Run a single command inside the dev shell
9+
# nix develop -c rustc --version Check Rust version available in the dev shell
10+
#
11+
# Container:
12+
#
13+
# nix build .#container Build the OCI container image (creates ./result symlink)
14+
# docker load < result Load it into Docker
15+
# docker run --rm openshell:0.0.0 Run container (default entrypoint shows help)
16+
# docker run --rm -it --entrypoint /bin/bash openshell:0.0.0 Interactive shell
17+
# docker image inspect openshell:0.0.0 --format='{{.Size}}' Check uncompressed size
18+
#
19+
# Testing:
20+
#
21+
# nix run .#container-test Run 15 container smoke tests (requires Docker)
22+
# nix flake check Run all checks (builds package + dev shell)
23+
#
24+
# Formatting:
25+
#
26+
# nix fmt Format all Nix files
27+
# nix fmt -- --check flake.nix nix/*.nix Check formatting without modifying
28+
#
29+
{
30+
description = "OpenShell — safe, sandboxed runtimes for autonomous AI agents";
31+
32+
inputs = {
33+
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
34+
flake-utils.url = "github:numtide/flake-utils";
35+
};
36+
37+
outputs =
38+
{
39+
self,
40+
nixpkgs,
41+
flake-utils,
42+
}:
43+
flake-utils.lib.eachDefaultSystem (
44+
system:
45+
let
46+
pkgs = import nixpkgs { inherit system; };
47+
48+
# Pure data — no pkgs needed
49+
constants = import ./nix/constants.nix;
50+
51+
# Source filters
52+
sources = pkgs.callPackage ./nix/source-filter.nix { inherit constants; };
53+
54+
# OpenShell package (all workspace binaries)
55+
openshell = pkgs.callPackage ./nix/package.nix {
56+
inherit constants sources;
57+
};
58+
59+
# OCI container image
60+
container = pkgs.callPackage ./nix/container.nix {
61+
inherit constants openshell;
62+
};
63+
64+
# Container smoke-test script
65+
container-test = pkgs.callPackage ./nix/container-test.nix {
66+
inherit constants container;
67+
docker = pkgs.docker-client;
68+
};
69+
70+
in
71+
{
72+
packages = {
73+
default = openshell;
74+
inherit
75+
openshell
76+
container
77+
container-test
78+
;
79+
};
80+
81+
devShells.default = pkgs.callPackage ./nix/shell.nix {
82+
inherit openshell;
83+
};
84+
85+
formatter = pkgs.nixfmt;
86+
87+
checks = {
88+
inherit openshell;
89+
shell = self.devShells.${system}.default;
90+
};
91+
}
92+
);
93+
}

0 commit comments

Comments
 (0)