diff --git a/.github/workflows/deploy.yaml b/.github/workflows/deploy.yaml index 99896ac..855665d 100644 --- a/.github/workflows/deploy.yaml +++ b/.github/workflows/deploy.yaml @@ -111,7 +111,10 @@ jobs: node: ${{ fromJSON(needs.changes.outputs.nodes) }} name: ${{ matrix.node }} - runs-on: ubuntu-latest + # Build on a runner whose arch matches the target, so the closure builds + # natively (no emulation) and we can drop --remote-build. terebithia is + # aarch64; everything else is x86_64. + runs-on: ${{ matrix.node == 'terebithia' && 'ubuntu-24.04-arm' || 'ubuntu-latest' }} environment: name: ${{ matrix.node }} @@ -134,13 +137,14 @@ jobs: mkdir -p ~/.ssh echo "StrictHostKeyChecking accept-new" >> ~/.ssh/config - # --remote-build builds the closure natively on the target, so aarch64 - # (terebithia) needs no emulation on this x86 runner. + # Build on the runner (native arch), then copy only the output-closure + # diff to the target. Without --remote-build we no longer ship the whole + # derivation closure to the target over ssh-ng, which was ~24 min to the + # small VPS. The target substitutes standard paths from cache.nixos.org. - name: Deploy ${{ matrix.node }} run: | nix develop .#default --command deploy \ --skip-checks \ - --remote-build \ --ssh-user kierank \ --ssh-opts="-o StrictHostKeyChecking=accept-new" \ .#${{ matrix.node }} diff --git a/flake.nix b/flake.nix index c27eed3..5eaa4e5 100644 --- a/flake.nix +++ b/flake.nix @@ -187,6 +187,27 @@ }) ]; }; + + # deploy-rs.lib.activate embeds the deploy-rs binary in each node's + # activation closure. Taken straight from the flake input (whose nixpkgs + # follows ours) that binary is in no cache and compiles from source — fine + # under --remote-build (built once on the target), but a per-run source + # build on the CI runner now that we build there. Swap in nixpkgs' cached + # binary via deploy-rs's documented overlay, keeping its lib functions. + deployRsLib = + system: + (import nixpkgs-unstable-small { + inherit system; + overlays = [ + deploy-rs.overlays.default + (_final: prev: { + deploy-rs = { + inherit (nixpkgs-unstable-small.legacyPackages.${system}) deploy-rs; + lib = prev.deploy-rs.lib; + }; + }) + ]; + }).deploy-rs.lib; in { # NixOS configuration entrypoint @@ -344,7 +365,7 @@ profiles.system = { sshUser = "kierank"; user = "root"; - path = deploy-rs.lib.aarch64-linux.activate.nixos self.nixosConfigurations.terebithia; + path = (deployRsLib "aarch64-linux").activate.nixos self.nixosConfigurations.terebithia; }; }; prattle = { @@ -352,7 +373,7 @@ profiles.system = { sshUser = "kierank"; user = "root"; - path = deploy-rs.lib.x86_64-linux.activate.nixos self.nixosConfigurations.prattle; + path = (deployRsLib "x86_64-linux").activate.nixos self.nixosConfigurations.prattle; }; }; };