Skip to content

Allow overriding the hard-coded binary cache URL (https://cache.nixos.org) via an environment variable #2993

Description

@jasal82

What problem are you trying to solve?

Summary

Devbox hard-codes https://cache.nixos.org as its binary cache. Nix itself can be pointed at a mirror (substituters in nix.conf), but devbox still contacts cache.nixos.org directly. As a result, devbox can't install packages where only an internal mirror is reachable (air-gapped CI runners, corporate networks), even when the project has a complete devbox.lock and every package is available from the mirror.

Please add an environment variable, for example DEVBOX_BINARY_CACHE, that overrides this URL. That would match how DEVBOX_SEARCH_HOST and DEVBOX_CACHE work today.

Environment

  • Devbox 0.18.4 (official devbox_0.18.4_linux_amd64 release binary); also reproduced with 0.17.2
  • Nix 2.35.2
  • Linux x86_64 (container)
  • nix.conf: substituters = https://artifactory.example.com/artifactory/api/nix/cache.nixos.org-nix-remote (a pull-through mirror of cache.nixos.org)
  • DEVBOX_CACHE=https://artifactory.example.com/artifactory/github.com (a mirror of github.com)

Steps to reproduce

  1. On a machine with internet access, create a project and commit its devbox.json and devbox.lock:
    devbox init && devbox add hello
  2. In an environment where only the mirror is reachable (outbound traffic to cache.nixos.org, github.com etc. is blocked) and Nix's substituters points at the mirror, run:
    devbox install

Actual behavior

Devbox sends HEAD https://cache.nixos.org/<hash>.narinfo. That request fails, so devbox treats the package as not cached and builds it from nixpkgs sources on GitHub:

Info: Installing the following packages to the nix store: hello@latest
unpacking 'github:NixOS/nixpkgs/c27cdad491a991b11ed731760aa2ef8db0cb0410' into the Git cache...
error:
       … while fetching the input 'github:NixOS/nixpkgs/c27cdad491a991b11ed731760aa2ef8db0cb0410'

       error: Failed to open archive (Source threw exception: error: unable to download 'https://github.com/NixOS/nixpkgs/archive/c27cdad491a991b11ed731760aa2ef8db0cb0410.tar.gz': Could not connect to server (7) CONNECT tunnel failed, response 403)
Error: nix: command error: nix ... build --impure --no-link 'github:NixOS/nixpkgs/c27cdad491a991b11ed731760aa2ef8db0cb0410#hello': exit code 1

The locked store path (/nix/store/wzr035k31pmpn2caabq8qwv1npg571z9-hello-2.12.3) is available from the configured substituter. If devbox knew the package was cached, Nix could substitute it directly. This fallback also ignores DEVBOX_CACHE.

In 0.17.2 the failed request was a hard error instead:

Error: Head "https://cache.nixos.org/wzr035k31pmpn2caabq8qwv1npg571z9.narinfo": Filtered

Expected behavior

Devbox either uses a binary cache URL I can configure, or follows Nix's configured substituters, so that installing a locked project needs only the mirror.

Where the URL is hard-coded (v0.18.4)

Location Purpose
internal/devpkg/narinfo_cache.go:19: const binaryCache = "https://cache.nixos.org" HEAD request for <hash>.narinfo to decide whether a package is cached; a miss triggers the GitHub fallback above
internal/shellgen/tmpl/flake.nix.tmpl:51: fromStore = "https://cache.nixos.org"; builtins.fetchClosure in the generated flake

internal/lock/resolve.go:185 (nix.StorePathFromHashPart(ctx, sysInfo.StoreHash, "https://cache.nixos.org")) also hard-codes the URL. It's only used by the /v1/resolve path (DEVBOX_FEATURE_RESOLVE_V2=0), which is not the default.

Related: the stdenv nixpkgs input ignores DEVBOX_CACHE

DEVBOX_CACHE rewrites nixpkgs flake inputs for packages to <DEVBOX_CACHE>/nixos/nixpkgs/archive/<rev>.tar.gz (internal/shellgen/nixpkgs.go). The stdenv input is still written verbatim (nixpkgs.url = "{{ .Stdenv }}"; in flake.nix.tmpl:5), so nix print-dev-env downloads https://github.com/NixOS/nixpkgs/archive/<rev>.tar.gz directly. Applying the same mirror logic to the stdenv input would let a locked project work with only the mirror reachable. I can open this as a separate issue if you prefer.

What solution would you like?

Proposal

  • Add DEVBOX_BINARY_CACHE (the name is only a suggestion). It defaults to https://cache.nixos.org and is used in all places above.
  • Alternative: read the first HTTP(S) entry of Nix's substituters setting (nix config show substituters), falling back to https://cache.nixos.org.

Alternatives you've considered

Workaround

We currently patch the source at build time: substituteInPlace swaps https://cache.nixos.org for our mirror URL, and the stdenv template line is changed to use the mirror. With both patches, devbox install, devbox run and devbox shell work for locked projects with only the mirror reachable. We'd like to drop this patch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureNew feature or requesttriageIssue needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions