Cache Population
Populating the cache involves uploading .nar files and .narinfo metadata to your OCI registry. For most users the aeroflare push command is the way to do this: you point it at a Nix installable, and it prepares, compresses, and uploads the resulting store paths directly to the registry.
Push via CLI (recommended)
aeroflare push takes one or more Nix installables and uploads them. This is the most predictable way to populate the cache — you decide exactly what gets pushed, and no proxy needs to be running.
Pushing an Installable
A push target can be a ./result symlink, a flake reference, or a store path. Anything not built yet is built first:
nix run github:ItzEmoji/aeroflare -- push ./result
nix run github:ItzEmoji/aeroflare -- push nixpkgs#hello
nix run github:ItzEmoji/aeroflare -- push github:owner/repo#default
To push an exact store path instead, use --store-path:
nix run github:ItzEmoji/aeroflare -- push --store-path /nix/store/13x...-my-package
Pushing Multiple Paths
You can provide a file containing a list of store paths (one per line).
nix path-info --all > paths.txt
nix run github:ItzEmoji/aeroflare -- push --input paths.txt --workers 100
Note: You can increase the --workers flag to speed up the upload process. The default is 50.
Alternative: automated push via run
If you'd rather build and push in a single step, the run execution wrapper detects new store paths generated by the inner command and pushes them automatically.
Important: Currently, if you want Aeroflare to successfully push the resulting artifacts, you must pass the
--print-out-pathsflag to your Nix build command so Aeroflare knows what to upload.
nix run github:ItzEmoji/aeroflare -- run -- nix build .#default --print-out-paths
Pushing Signatures
If you are maintaining a public cache, you must sign the .narinfo files so that downstream Nix clients trust them.
- Generate a Nix signing key pair:
nix-store --generate-binary-cache-key my-cache-name cache-priv-key.pem cache-pub-key.pem
- Pass the private key to the push command:
nix run github:ItzEmoji/aeroflare -- push --store-path /nix/store/... --signing-key ./cache-priv-key.pem
Clients consuming this cache will need to add the contents of cache-pub-key.pem to their trusted-public-keys in nix.conf.