postjevsql.git / nix / CLAUDE.md
1@README.md
2
3- **The module only launches the sidecar CLI.** What happens in the
4  database is the CLI's (`crates/postjevsql-sidecar`). Never add SQL to the
5  unit: that would be a second engine beside the one the container image and
6  users' own Postgres call.
7- **The generated TOML is in the store, so it names secret FILES only:**
8  passwords as `/run/credentials/postjevsql-sidecar.service/…` paths
9  (`LoadCredential`), the API key as `apiKeyFile`. Never interpolate a
10  secret into it or a command line: both are world-readable (the store,
11  `/proc`). The nixosTest greps for the password.
12- **`sidecar-cli.nix` reuses `package.nix` through `passthru.buck`;** change
13  the sandbox build there, once.
14- **`package.nix` parses `third-party/BUCK`'s `http_archive` blocks at eval
15  and throws on any other shape;** if reindeer's output changes, fix the
16  match, never hand-list crates. Adding a major means adding it to
17  `PG_MAJORS`; the package builds it with `--target-platforms
18  //platforms:pgNN` (`third-party/pg_major.bzl` sets pgrx's feature).
19- **`package.nix`'s `src` is a fileset of what `//crates/postjevsql:ext`
20  reads, docs excluded,** so doc and test edits do not rebuild it. A new
21  directory or root file the build reads must be added to that list, or
22  buck fails in the sandbox with a missing path.
23- **Build through the flake (`nix build .#`), which passes the pinned
24  buck2;** nixpkgs' own buck2 has the h2 window bug (`tests/CLAUDE.md`).