Skip to content

Terraform Provider for Cachix

CI Go Report Card Terraform Registry License: MPL-2.0

Manage Cachix binary caches as infrastructure-as-code with Terraform or OpenTofu.

Features

  • cachix_cache resource — create, read, import, and delete binary caches.
  • cachix_cache data source — reference existing caches (managed elsewhere or public).
  • cachix_user data source — look up the authenticated account, including subscription and storage usage.
  • Automatic signing-key generation, exposed as public_signing_keys for nix.conf.
  • Robust HTTP client with retries and exponential backoff on 429/5xx responses.

Requirements

Usage

terraform {
  required_providers {
    cachix = {
      source  = "takeokunn/cachix"
      version = "~> 1.0"
    }
  }
}

provider "cachix" {
  # auth_token = var.cachix_auth_token   # or set CACHIX_AUTH_TOKEN
}

# Create and manage a cache.
resource "cachix_cache" "example" {
  name      = "my-cache"
  is_public = true
}

# Reference an existing public cache.
data "cachix_cache" "nixpkgs" {
  name = "nixpkgs"
}

# Look up the authenticated user.
data "cachix_user" "current" {}

output "trusted_public_keys" {
  value = cachix_cache.example.public_signing_keys
}

Authentication

The provider reads the API token from, in order of precedence:

  1. The auth_token argument in the provider block.
  2. The CACHIX_AUTH_TOKEN environment variable.
export CACHIX_AUTH_TOKEN="your-token-here"

Full documentation, including every attribute, is published on the Terraform Registry.

Development

This repository ships a Nix flake that provides the entire toolchain (Go, Terraform, golangci-lint, goreleaser, terraform-docs).

nix develop            # Enter a dev shell with every tool pinned
nix build              # Build the provider binary
nix flake check        # Run build, unit tests, gofmt, and golangci-lint
nix run .#docs         # Regenerate the registry documentation
nix run .#testacc      # Acceptance tests (requires CACHIX_AUTH_TOKEN)

If you use direnv, running direnv allow loads the dev shell automatically via the checked-in .envrc (use flake).

Inside nix develop you can also use the Go toolchain directly, e.g. go test ./... or go generate ./....

CI runs a single nix flake check, so a green nix flake check locally mirrors exactly what runs on pull requests.

See CONTRIBUTING.md for the full contributor guide.

License

MPL-2.0

About

Terraform provider for Cachix

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages