Skip to content

Pin and provision a reproducible Guix-first toolchain #23

Description

@hyperpolymath

Outcome

Make Bag builds and owned-node execution reproducible under the estate’s Guix-first policy.

Scope

  • Replace unbounded latest tool declarations with reviewed Guix/toolchain pins.
  • Decide and document whether to pin Zig 0.15.2 or complete and test the Zig 0.16 migration.
  • Provision wasmtime, Elixir/Erlang, Idris2, Just, OpenSSH signing support, GitHub CLI, and required certificates.
  • Remove or repair the generic mise.toml template entries that name unsupported/banned tools and generate noisy resolution failures.
  • Add just doctor checks that distinguish required, optional, and unavailable capabilities.
  • Produce a reproducible build record and dependency/SBOM output.

Acceptance criteria

  • A clean Guix environment can run build, proofs, focused integration tests, and the full dogfood manifest.
  • The selected Zig version is explicit and the suite cannot silently move to an incompatible compiler.
  • wasmtime-dependent checks are either provisioned and green or explicitly suspended before execution.
  • No Nix dependency is introduced.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationBots, schedulers, dispatch, self-healing, fan-outcicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesmeta:roadmapForward planning; not yet actionable workpriority:p0Critical - drop other work

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions