Skip to content

fix(ci): pin which Nix Renovate's post-upgrade tasks use - #1107

Merged
jbw976 merged 1 commit into
crossplane:mainfrom
jbw976:nix-dupe
Aug 5, 2026
Merged

fix(ci): pin which Nix Renovate's post-upgrade tasks use#1107
jbw976 merged 1 commit into
crossplane:mainfrom
jbw976:nix-dupe

Conversation

@jbw976

@jbw976 jbw976 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description of your changes

This PR applies the same fix from crossplane/crossplane#7709 to crossplane-runtime, which has been verified to work OK for CC in crossplane/crossplane#7707 (comment).

I have:

Need help with this checklist? See the cheat sheet.

Renovate's Go dependency PRs fail their post-upgrade tasks with "error:
experimental Nix feature 'nix-command' is disabled", so nix run .#tidy
and nix run .#generate never refresh our vendor hashes or generated code.

This entrypoint installs Nix from apt and configures it through
/etc/nix/nix.conf. Renovate's Nix manager installs its own through
containerbase whenever it updates flake.lock, and that one lands earlier
on PATH and reads its config from containerbase's cache.

This has always been possible but giving lock file maintenance a higher
priority in crossplane#1096 moved those updates to the front of the run, where they
now poison every post-upgrade task after them.

This commit has the entrypoint publish a crossplane-nix launcher that
pins both the binary and the config directory it reads, and points the
post-upgrade tasks at it. RENOVATE_ALLOWED_COMMANDS no longer permits a
bare nix, so a command still spelled that way fails on the allowlist
instead of silently running against the wrong Nix.

Signed-off-by: Jared Watts <jbw976@gmail.com>
@jbw976
jbw976 requested a review from a team as a code owner August 5, 2026 15:59
@jbw976
jbw976 requested a review from phisco August 5, 2026 15:59
@jbw976
jbw976 merged commit c4f6622 into crossplane:main Aug 5, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants