For agents, on top of README.md, which they read first.
- The module only launches the sidecar CLI. What happens in the
database is the CLI's (
crates/postjevsql-sidecar). Never add SQL to the unit: that would be a second engine beside the one the container image and users' own Postgres call. - The generated TOML is in the store, so it names secret FILES only:
passwords as
/run/credentials/postjevsql-sidecar.service/…paths (LoadCredential), the API key asapiKeyFile. Never interpolate a secret into it or a command line: both are world-readable (the store,/proc). The nixosTest greps for the password. sidecar-cli.nixreusespackage.nixthroughpassthru.buck; change the sandbox build there, once.package.nixparsesthird-party/BUCK'shttp_archiveblocks at eval and throws on any other shape; if reindeer's output changes, fix the match, never hand-list crates. Adding a major means adding it toPG_MAJORS; the package builds it with--target-platforms //platforms:pgNN(third-party/pg_major.bzlsets pgrx's feature).package.nix'ssrcis a fileset of what//crates/postjevsql:extreads, docs excluded, so doc and test edits do not rebuild it. A new directory or root file the build reads must be added to that list, or buck fails in the sandbox with a missing path.- Build through the flake (
nix build .#), which passes the pinned buck2; nixpkgs' own buck2 has the h2 window bug (tests/CLAUDE.md).