ba62b8e1

By: Michael Lynch <git@mtlynch.io>

Use Fly registry auth for Dockerless deploys

Have the deploy script ask flyctl to mint the short-lived registry credentials that Fly expects, then pass those credentials to Skopeo through a temporary auth file. This keeps the NixCI deploy path Dockerless while avoiding raw token authentication issues against registry.fly.io.

Document the deploy flow, including the Nix-built archive, temporary auth setup, registry push, and final image deploy steps.

Suite timing

Time to Start Worker time Duration Time to finish
Config 2s 10s 10s 12s
Eval 10s 1m02s 1m02s 1m13s
Build 16s 6m16s 2m09s 2m25s
Suite 2s 7m29s 2m23s 2m25s

Timeline

0s10s20s30s40s50s1m1m10s1m20s1m30s2m20s