docs(install): CLI-233 Trust floxhub-1 for Nix installs - #102
Merged
Merged
Conversation
Packages published to FloxHub-hosted catalogs are signed with floxhub-1, which the Flox installer trusts by default. A system that got Nix through some other path (nix profile install, nix-darwin, NixOS) never receives that key, so installing a published package fails as untrusted with no doc pointing at the fix. Add floxhub-1 alongside the existing flox-cache-public-1 key in every Nix trust-configuration example on the generic-install page and in troubleshooting, and add a short section to the signing-keys page naming the default key and linking installers of Nix straight to the fix. While touching these blocks, also fix nix-darwin's nix.settings and NixOS's configuration.nix examples, which set substituters and trusted-public-keys instead of their extra- counterparts; the bare form replaces Nix's defaults instead of merging into them, the same defect install-flox/troubleshooting.mdx already documents as a common misconfiguration. Refs: CLI-233 Forge-Agent: implementation-worker (d44c191) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
Author
Implementation handoff noteJudgment calls this implementation made that reading the diff or exercising the feature will not surface. Each one names what it was responsive to and what happens if nobody answers. Decisions exercising the code will not reveal
Taken on trust
As of Via Forge (implementation-worker) • d44c191 |
The prior paragraph pointed Nix-installed users at the generic-Nix install page for "the exact key value and the config syntax." That makes the fix two hops away from the error it explains. Show the nix.conf line and the NixOS/nix-darwin nix.settings block directly, with the real floxhub-1 key, and keep the generic-Nix page linked only as further reading (it also covers the flox cache-public key, which this page has no reason to duplicate). Refs: CLI-233 Forge-Agent: implementation-worker (d44c191) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
billlevine
marked this pull request as ready for review
September 25, 2026 19:44
billlevine
requested review from
Kaysahni,
dcarley,
mkenigs and
stephenyeargin
September 25, 2026 19:45
stephenyeargin
approved these changes
Sep 25, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Nix installs of Flox —
nix profile install, nix-darwin, NixOS — don't trustfloxhub-1, the key FloxHub-hosted catalogs sign published packages with. Installing a published package on one of those systems fails as untrusted, with no doc pointing at the fix. This addsfloxhub-1alongside the existingflox-cache-public-1cache key in every Nix trust-configuration example on the install and troubleshooting pages, and adds a section to the signing-keys page that names the default key and gives thenix.confandnix.settingsfix inline.Delegated by bill@flox.dev via CLI-233
The Flox installer trusts
floxhub-1out of the box, but a system that got Nix some other way never receives it. Flox's own error for this case (Package '<name>' is not signed by a trusted key., confirmed againstcli/flox-rust-sdk/src/providers/buildenv.rsin flox/flox) already links to the signing-keys page, which didn't mentionfloxhub-1at all.Every code block that lists
flox-cache-public-1in a Nix trust-configuration example —/etc/nix/nix.conflines, flakenixConfig, NixOS/nix-darwinnix.settings— now listsfloxhub-1beside it. Two of those examples (nix-darwin'snix.settingsand NixOS'sconfiguration.nix) also usedsubstituters/trusted-public-keysinstead ofextra-substituters/extra-trusted-public-keys; the bare form replaces Nix's default list instead of merging into it, the same misconfigurationtroubleshooting.mdxalready documents, so it's fixed alongside the key addition rather than shipped a second time. The signing-keys page's new paragraph adds its ownnix.confline andnix.settingsblock with the realfloxhub-1value, instead of sending the reader to the install page for it. The install page stays linked for the full example, which also covers theflox-cache-public-1binary-cache key. Thefloxhub-1value is verified verbatim againstrootfs/common/etc/nix/flox.confin flox/flox-installers.Be suspicious of the
floxhub-1key value itself — it appears nowhere else inflox/docs, so nothing else in this repo cross-checks it against flox-installers.concepts/cuda-catalog-and-cache.mdxalso listsflox-cache-public-1, but for trusting Flox's CUDA build cache, not for installing FloxHub-published packages, so it's untouched here.Further work
.conf,.ini, flakenixConfig, NixOS/nix-darwinnix.settings) that share no common template. A cheaper drift guard — a CI grep assertingfloxhub-1appears next to everyflox-cache-public-1— would need its own ticket.customer/signing-keys.mdx:121changesnix.settings.trusted-public-keystonix.settings.extra-trusted-public-keysin the pre-existing "NixOS, nix-darwin, or home-manager" example, the same extra- fix applied to the install and troubleshooting pages. It isn't required to fix the floxhub-1 gap this PR is about — drop that hunk if it's out of scope for this ticket.🤖 Generated with Claude Code
Via Forge (implementation-worker) • d44c191