fix(nix): write the registry npmrc where the deps fetch actually reads it #513
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
gmackie/ForgeGraph!513
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/nix-npmrc-userconfig"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Corrects #512, which did not work. npm-registry kept failing with
ERR_PNPM_FETCH_401on the merge commit of #512 itself (rev574dd67101) — which is what gave it away.Why #512 was inert. It hooked
preBuildand wrote the npmrc under$HOME. Reading the nixpkgs source on the node,pnpm.fetchDepsdoes its work ininstallPhase, sopreBuildnever ran at all — andinstallPhasethen does its ownexport HOME=$(mktemp -d), which would have discarded the file anyway:The fix.
preInstallruns inside that phase before pnpm does, andNPM_CONFIG_USERCONFIGsurvives the HOME reset, so the credential actually reaches the fetch.fetchDepsalso acceptsimpureEnvVarsas an argument and appends it to its own list, so #512'soverrideAttrs— which replaced that list, droppingproxyImpureEnvVarsandNIX_NPM_REGISTRY— is gone.Verified on hetzner-fg, not reasoned about. I got this wrong once tonight by trusting a misread
stat, so this time the evidence is direct:narHash: sha256-4pKTGwBq…, matching the hash recorded here, and was registered during that build — every prior attempt 401'd, so it could not have pre-existedforgegraph-registry-0.0.1throughfixupPhase#512's hash was also wrong — I took it from a store path I had not actually verified. It was never exercised, because the fetch never got past the 401. This one is the hash of a fetch I watched succeed.
Wiring is already in place:
FG_NPM_TOKENis in/etc/forgegraph/agent.env(mode 600) and the agent process has it. The durable version — carrying a registry token in the deployment payload the way CI jobs already do — remains a separate server+agent change.🤖 Generated with Claude Code