Add a Nix flake that builds the Paseo daemon (server + CLI) and
provides a NixOS module for declarative deployment.
Package (nix/package.nix):
- Builds relay, server, and CLI workspaces
- Skips onnxruntime-node install script (sandbox-incompatible)
- Rebuilds only node-pty for native terminal support
- Source filter excludes app/website/desktop workspaces
NixOS module (nix/module.nix):
- Systemd service with configurable user, port, listen address
- allowedHosts for DNS rebinding protection
- relay.enable to toggle remote access via app.paseo.sh
- inheritUserEnvironment to expose user tools (git, ssh) to agents
- openFirewall and extra environment variables
ci: add Nix hash maintenance scripts and workflows
scripts/fix-lockfile.mjs:
Adds missing resolved/integrity fields to package-lock.json for
workspace-local overrides. Idempotent, uses `npm view`.
scripts/update-nix.sh:
Runs fix-lockfile.mjs, prefetches deps, computes NAR hash, and
updates npmDepsHash in nix/package.nix. Supports --check for CI.
.github/workflows/nix-build.yml:
Builds the Nix package on push/PR and verifies the lockfile and
hash are up to date.
.github/workflows/fix-nix-hash.yml:
Auto-fixes lockfile signatures and Nix hash on dependabot PRs.
fix: update npmDepsHash after upstream sync
nix: allowlist workspace symlinks instead of blocklist
Prevents build failures when upstream adds new workspace packages.