1@README.md 2 3- **The module only launches the sidecar CLI.** What happens in the 4 database is the CLI's (`crates/postjevsql-sidecar`). Never add SQL to the 5 unit: that would be a second engine beside the one the container image and 6 users' own Postgres call. 7- **The generated TOML is in the store, so it names secret FILES only:** 8 passwords as `/run/credentials/postjevsql-sidecar.service/…` paths 9 (`LoadCredential`), the API key as `apiKeyFile`. Never interpolate a 10 secret into it or a command line: both are world-readable (the store, 11 `/proc`). The nixosTest greps for the password. 12- **`sidecar-cli.nix` reuses `package.nix` through `passthru.buck`;** change 13 the sandbox build there, once. 14- **`package.nix` parses `third-party/BUCK`'s `http_archive` blocks at eval 15 and throws on any other shape;** if reindeer's output changes, fix the 16 match, never hand-list crates. Adding a major means adding it to 17 `PG_MAJORS`; the package builds it with `--target-platforms 18 //platforms:pgNN` (`third-party/pg_major.bzl` sets pgrx's feature). 19- **`package.nix`'s `src` is a fileset of what `//crates/postjevsql:ext` 20 reads, docs excluded,** so doc and test edits do not rebuild it. A new 21 directory or root file the build reads must be added to that list, or 22 buck fails in the sandbox with a missing path. 23- **Build through the flake (`nix build .#`), which passes the pinned 24 buck2;** nixpkgs' own buck2 has the h2 window bug (`tests/CLAUDE.md`).