No description
  • Rust 95.9%
  • Nix 3.7%
  • CSS 0.3%
  • JavaScript 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kristoffer Søholm 3e7c3deeff
All checks were successful
krisbuild/kris/krisbuild/nix/hello cached
krisbuild/kris/krisbuild/nix/workspace-deps cached
krisbuild/kris/krisbuild/nix/test-deps cached
krisbuild/kris/krisbuild/nix/build cached
krisbuild/kris/krisbuild/nix/test cached
krisbuild/kris/krisbuild/nix/world cached
krisbuild/kris/krisbuild/nix/clippy cached
krisbuild/kris/krisbuild/nix/kb-check cached
krisbuild/kris/krisbuild/nix/deployed succeeded
krisbuild/kris/krisbuild krisbuild kris/krisbuild: all tasks succeeded
Agent unit: run the token preflight as its own unit
The agent unit is delegated and keeps run supervisors alive across a
restart (KillMode=process), and the agent enables cpu and memory in the
unit cgroup's subtree_control so runs get limits. A control process of
that unit (ExecStartPre=) is then spawned into the unit's own cgroup,
which cgroup v2 refuses while leftover runs keep it alive: every restart
with a run in flight failed with "Failed to spawn 'start-pre' task:
Device or resource busy", and the unit crashlooped until the run ended.

The preflight is now krisbuild-agent-preflight.service, a root oneshot
the agent requires and starts after, so it still runs before every
start. The agent unit itself only ever starts its main process, into the
`agent` leaf.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 20:05:32 +02:00
.claude/agents Initial prototype: content-addressed CI scheduler over Nix 2026-08-14 21:38:55 +02:00
.kb Wip 2026-08-20 17:00:53 +02:00
crates Scheduling: CPU requests cap at the node and shrink once a task starves 2026-10-03 19:47:54 +02:00
docs Issued attic tokens by default: a node joins with no secret files 2026-09-29 23:36:06 +02:00
examples CI: one integration-test binary per crate, ci-test profile, mold 2026-09-27 19:32:22 +02:00
nix Agent unit: run the token preflight as its own unit 2026-10-03 20:05:32 +02:00
.gitignore Small tweaks 2026-09-11 21:40:02 +02:00
Cargo.lock Merge origin/main into web-auth: per-node attic tokens 2026-09-28 00:03:14 +02:00
Cargo.toml Merge origin/main into web-auth: per-node attic tokens 2026-09-28 00:03:14 +02:00
CLAUDE.md docs: no consumer repo names; CLAUDE.md points at the public UI 2026-09-29 23:09:10 +02:00
flake.lock Add microVM executor (docker-in-VM) for isolated e2e 2026-08-21 23:48:43 +02:00
flake.nix NixOS module: the whole deployment as options, split into nix/module/ 2026-09-29 23:06:58 +02:00
README.md Initial prototype: content-addressed CI scheduler over Nix 2026-08-14 21:38:55 +02:00
SPEC.md Scheduling: CPU requests cap at the node and shrink once a task starves 2026-10-03 19:47:54 +02:00

krisbuild

A prototype CI system for self-hosted infrastructure, built as a content-addressed task scheduler on top of Nix. See SPEC.md for the design; docs/briefs/ for per-crate implementation briefs.

Layout

Crate Role
kb-core Shared types: task model, GraphChunk NDJSON interchange, agent protocol. The contract between all binaries — treat as frozen.
kb-control-plane Single-binary server: SQLite state, scheduler/matchmaker, agent WebSocket endpoint, HTTP API.
kb-agent Per-node daemon: dials out to the control plane, advertises resources, executes tasks (none/container isolation, nix realization).
kb-eval-nix Nix frontend: evaluates a flake into GraphChunk NDJSON, one task per derivation, edges from the real derivation graph.

Quick start (prototype)

cargo build --workspace
kb-control-plane --config cp.toml &
kb-agent --control-plane ws://localhost:8080/agent &
kb-eval-nix --flake .#checks | curl -X POST --data-binary @- \
    'http://localhost:8080/api/graphs?pipeline=dev&rev=…'