Impure tests

You can have NixCI automatically run impure test using secrets and the internet.

Step 1: Configuration

To activate the impure testing mechanism, add a test section to your NixCI configuration.

For example, this example test configures the packages.x86_64-linux.impure-test package to be run as a test:

{
  test = {
    example = {
      branches = ":default";
      package = "packages.x86_64-linux.impure-test";
    };
  };
}

In particular, NixCI will nix run packages.x86_64-linux.impure-test, which will execute the package's meta.mainProgram.

Step 2: Secrets & Environment Variables

Tests can access secrets and SSH keys as environment variables. See the Secrets & SSH Keys documentation for how to declare and use them.

NixCI also automatically provides git metadata as environment variables during tests.

Reference schema

test: # optional
  # default: {}
  # Test Configurations
  <key>: 
    # TestConfiguration
    enable: # optional
      # default: true
      # enable this test
      <boolean>
    package: # required
      # package of which the main program will be run
      <string>
    system: # optional
      # system on which the test will be run
      <string>
    branches: # optional
      # default: :any
      # branches from which may be tested
      # one of
      [ # the branches to run on, with nothing excluded
        # any of
        [ # every ref
          :any
        , # the repository's default branch
          :default
        , # every ref; deprecated, write :any instead
          any
        , # a branch name
          <string>
        , - # any of
            [ # every ref
              :any
            , # the repository's default branch
              :default
            , # every ref; deprecated, write :any instead
              any
            , # a branch name
              <string>
            ]
        ]
      , # BranchFilter
        run-on: # optional
          # default: :any
          # branches to run on
          # any of
          [ # every ref
            :any
          , # the repository's default branch
            :default
          , # every ref; deprecated, write :any instead
            any
          , # a branch name
            <string>
          , - # any of
              [ # every ref
                :any
              , # the repository's default branch
                :default
              , # every ref; deprecated, write :any instead
                any
              , # a branch name
                <string>
              ]
          ]
        do-not-run-on: # optional
          # default: []
          # branches not to run on, even when they are in "run-on"
          # any of
          [ # every ref
            :any
          , # the repository's default branch
            :default
          , # every ref; deprecated, write :any instead
            any
          , # a branch name
            <string>
          , - # any of
              [ # every ref
                :any
              , # the repository's default branch
                :default
              , # every ref; deprecated, write :any instead
                any
              , # a branch name
                <string>
              ]
          ]
      ]
    in-repo: # optional
      # Run the job in a checkout of the repository at the right revision
      # default: False
      # Setting this to false is more efficient if the job doesn't need to access to git history.
      # You can use ${self} to refer to the flake source if you need access to the repository contents at the current commit only.
      <boolean>
    secrets: # optional
      # default: []
      # secrets provided to the test
      - <string>
    ssh-keys: # optional
      # default: []
      # ssh keys provided to the test
      - # SshKeyConfiguration
        secret: # required
          # name of the secret on NixCI to use as the private key
          <string>
        public-key: # required
          # public key of the ssh key
          <string>