What problem are you trying to solve?
Summary
Devbox hard-codes https://cache.nixos.org as its binary cache. Nix itself can be pointed at a mirror (substituters in nix.conf), but devbox still contacts cache.nixos.org directly. As a result, devbox can't install packages where only an internal mirror is reachable (air-gapped CI runners, corporate networks), even when the project has a complete devbox.lock and every package is available from the mirror.
Please add an environment variable, for example DEVBOX_BINARY_CACHE, that overrides this URL. That would match how DEVBOX_SEARCH_HOST and DEVBOX_CACHE work today.
Environment
- Devbox 0.18.4 (official
devbox_0.18.4_linux_amd64 release binary); also reproduced with 0.17.2
- Nix 2.35.2
- Linux x86_64 (container)
nix.conf: substituters = https://artifactory.example.com/artifactory/api/nix/cache.nixos.org-nix-remote (a pull-through mirror of cache.nixos.org)
DEVBOX_CACHE=https://artifactory.example.com/artifactory/github.com (a mirror of github.com)
Steps to reproduce
- On a machine with internet access, create a project and commit its
devbox.json and devbox.lock:
devbox init && devbox add hello
- In an environment where only the mirror is reachable (outbound traffic to
cache.nixos.org, github.com etc. is blocked) and Nix's substituters points at the mirror, run:
Actual behavior
Devbox sends HEAD https://cache.nixos.org/<hash>.narinfo. That request fails, so devbox treats the package as not cached and builds it from nixpkgs sources on GitHub:
Info: Installing the following packages to the nix store: hello@latest
unpacking 'github:NixOS/nixpkgs/c27cdad491a991b11ed731760aa2ef8db0cb0410' into the Git cache...
error:
… while fetching the input 'github:NixOS/nixpkgs/c27cdad491a991b11ed731760aa2ef8db0cb0410'
error: Failed to open archive (Source threw exception: error: unable to download 'https://github.com/NixOS/nixpkgs/archive/c27cdad491a991b11ed731760aa2ef8db0cb0410.tar.gz': Could not connect to server (7) CONNECT tunnel failed, response 403)
Error: nix: command error: nix ... build --impure --no-link 'github:NixOS/nixpkgs/c27cdad491a991b11ed731760aa2ef8db0cb0410#hello': exit code 1
The locked store path (/nix/store/wzr035k31pmpn2caabq8qwv1npg571z9-hello-2.12.3) is available from the configured substituter. If devbox knew the package was cached, Nix could substitute it directly. This fallback also ignores DEVBOX_CACHE.
In 0.17.2 the failed request was a hard error instead:
Error: Head "https://cache.nixos.org/wzr035k31pmpn2caabq8qwv1npg571z9.narinfo": Filtered
Expected behavior
Devbox either uses a binary cache URL I can configure, or follows Nix's configured substituters, so that installing a locked project needs only the mirror.
Where the URL is hard-coded (v0.18.4)
| Location |
Purpose |
internal/devpkg/narinfo_cache.go:19: const binaryCache = "https://cache.nixos.org" |
HEAD request for <hash>.narinfo to decide whether a package is cached; a miss triggers the GitHub fallback above |
internal/shellgen/tmpl/flake.nix.tmpl:51: fromStore = "https://cache.nixos.org"; |
builtins.fetchClosure in the generated flake |
internal/lock/resolve.go:185 (nix.StorePathFromHashPart(ctx, sysInfo.StoreHash, "https://cache.nixos.org")) also hard-codes the URL. It's only used by the /v1/resolve path (DEVBOX_FEATURE_RESOLVE_V2=0), which is not the default.
Related: the stdenv nixpkgs input ignores DEVBOX_CACHE
DEVBOX_CACHE rewrites nixpkgs flake inputs for packages to <DEVBOX_CACHE>/nixos/nixpkgs/archive/<rev>.tar.gz (internal/shellgen/nixpkgs.go). The stdenv input is still written verbatim (nixpkgs.url = "{{ .Stdenv }}"; in flake.nix.tmpl:5), so nix print-dev-env downloads https://github.com/NixOS/nixpkgs/archive/<rev>.tar.gz directly. Applying the same mirror logic to the stdenv input would let a locked project work with only the mirror reachable. I can open this as a separate issue if you prefer.
What solution would you like?
Proposal
- Add
DEVBOX_BINARY_CACHE (the name is only a suggestion). It defaults to https://cache.nixos.org and is used in all places above.
- Alternative: read the first HTTP(S) entry of Nix's
substituters setting (nix config show substituters), falling back to https://cache.nixos.org.
Alternatives you've considered
Workaround
We currently patch the source at build time: substituteInPlace swaps https://cache.nixos.org for our mirror URL, and the stdenv template line is changed to use the mirror. With both patches, devbox install, devbox run and devbox shell work for locked projects with only the mirror reachable. We'd like to drop this patch.
What problem are you trying to solve?
Summary
Devbox hard-codes
https://cache.nixos.orgas its binary cache. Nix itself can be pointed at a mirror (substitutersinnix.conf), but devbox still contactscache.nixos.orgdirectly. As a result, devbox can't install packages where only an internal mirror is reachable (air-gapped CI runners, corporate networks), even when the project has a completedevbox.lockand every package is available from the mirror.Please add an environment variable, for example
DEVBOX_BINARY_CACHE, that overrides this URL. That would match howDEVBOX_SEARCH_HOSTandDEVBOX_CACHEwork today.Environment
devbox_0.18.4_linux_amd64release binary); also reproduced with 0.17.2nix.conf:substituters = https://artifactory.example.com/artifactory/api/nix/cache.nixos.org-nix-remote(a pull-through mirror ofcache.nixos.org)DEVBOX_CACHE=https://artifactory.example.com/artifactory/github.com(a mirror ofgithub.com)Steps to reproduce
devbox.jsonanddevbox.lock:devbox init && devbox add hellocache.nixos.org,github.cometc. is blocked) and Nix'ssubstituterspoints at the mirror, run:Actual behavior
Devbox sends
HEAD https://cache.nixos.org/<hash>.narinfo. That request fails, so devbox treats the package as not cached and builds it from nixpkgs sources on GitHub:The locked store path (
/nix/store/wzr035k31pmpn2caabq8qwv1npg571z9-hello-2.12.3) is available from the configured substituter. If devbox knew the package was cached, Nix could substitute it directly. This fallback also ignoresDEVBOX_CACHE.In 0.17.2 the failed request was a hard error instead:
Expected behavior
Devbox either uses a binary cache URL I can configure, or follows Nix's configured substituters, so that installing a locked project needs only the mirror.
Where the URL is hard-coded (v0.18.4)
internal/devpkg/narinfo_cache.go:19:const binaryCache = "https://cache.nixos.org"<hash>.narinfoto decide whether a package is cached; a miss triggers the GitHub fallback aboveinternal/shellgen/tmpl/flake.nix.tmpl:51:fromStore = "https://cache.nixos.org";builtins.fetchClosurein the generated flakeinternal/lock/resolve.go:185(nix.StorePathFromHashPart(ctx, sysInfo.StoreHash, "https://cache.nixos.org")) also hard-codes the URL. It's only used by the/v1/resolvepath (DEVBOX_FEATURE_RESOLVE_V2=0), which is not the default.Related: the stdenv nixpkgs input ignores
DEVBOX_CACHEDEVBOX_CACHErewrites nixpkgs flake inputs for packages to<DEVBOX_CACHE>/nixos/nixpkgs/archive/<rev>.tar.gz(internal/shellgen/nixpkgs.go). The stdenv input is still written verbatim (nixpkgs.url = "{{ .Stdenv }}";inflake.nix.tmpl:5), sonix print-dev-envdownloadshttps://github.com/NixOS/nixpkgs/archive/<rev>.tar.gzdirectly. Applying the same mirror logic to the stdenv input would let a locked project work with only the mirror reachable. I can open this as a separate issue if you prefer.What solution would you like?
Proposal
DEVBOX_BINARY_CACHE(the name is only a suggestion). It defaults tohttps://cache.nixos.organd is used in all places above.substituterssetting (nix config show substituters), falling back tohttps://cache.nixos.org.Alternatives you've considered
Workaround
We currently patch the source at build time:
substituteInPlaceswapshttps://cache.nixos.orgfor our mirror URL, and the stdenv template line is changed to use the mirror. With both patches,devbox install,devbox runanddevbox shellwork for locked projects with only the mirror reachable. We'd like to drop this patch.