Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
version: 2
updates:
- package-ecosystem: bun
directory: "/"
schedule:
interval: weekly
groups:
dev-dependencies:
dependency-type: development

- package-ecosystem: github-actions
directory: "/"
schedule:
interval: weekly

- package-ecosystem: docker
directory: "/apps/server"
schedule:
interval: weekly

- package-ecosystem: docker
directory: "/apps/web"
schedule:
interval: weekly
55 changes: 55 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
name: CI

on:
pull_request:
branches: [main]
push:
branches: [main]

permissions:
contents: read

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
lint:
name: Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.14
- run: bun install --frozen-lockfile
# Scoped to files touched by this PR/push, rather than the whole repo,
# so this gate doesn't block on pre-existing lint debt outside the
# change under review. actions/checkout doesn't create a local "main"
# branch (only origin/main), so --since is passed explicitly rather
# than relying on biome.json's vcs.defaultBranch to resolve it.
- run: bunx biome ci --changed --since=origin/main --reporter=github

typecheck:
name: Typecheck
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.14
- run: bun install --frozen-lockfile
- run: bun run typecheck

build:
name: Build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.14
- run: bun install --frozen-lockfile
- run: bun run build
33 changes: 33 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
name: CodeQL

on:
pull_request:
branches: [main]
push:
branches: [main]
schedule:
- cron: "24 7 * * 1"

permissions:
contents: read

jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
strategy:
fail-fast: false
matrix:
language: [javascript-typescript]
steps:
- uses: actions/checkout@v4
- uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
- uses: github/codeql-action/analyze@v3
with:
category: "/language:${{ matrix.language }}"
23 changes: 23 additions & 0 deletions .github/workflows/dependency-review.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
name: Dependency review

on:
pull_request:
branches: [main]

permissions:
contents: read
pull-requests: write

jobs:
dependency-review:
name: Scan dependency changes
runs-on: ubuntu-latest
# Requires the repository's "Dependency graph" setting (Settings ->
# Security -> Dependency graph) to be enabled. Non-blocking here so this
# check doesn't fail every PR until that's turned on.
continue-on-error: true
steps:
- uses: actions/checkout@v4
- uses: actions/dependency-review-action@v4
with:
comment-summary-in-pr: on-failure
81 changes: 81 additions & 0 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
name: Docker

on:
pull_request:
branches: [main]
paths:
- apps/server/**
- apps/web/**
- packages/**
- package.json
- bun.lock
- turbo.json
- .github/workflows/docker.yml
push:
branches: [main]
tags: ["v*.*.*"]
paths:
- apps/server/**
- apps/web/**
- packages/**
- package.json
- bun.lock
- turbo.json
- .github/workflows/docker.yml

concurrency:
group: docker-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:
name: Build ${{ matrix.image }}
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
include:
- image: server
dockerfile: apps/server/Dockerfile
- image: web
dockerfile: apps/web/Dockerfile
steps:
- uses: actions/checkout@v4

- uses: docker/setup-qemu-action@v3

- uses: docker/setup-buildx-action@v3

- name: Log in to GHCR
if: github.event_name != 'pull_request'
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Derive image metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/${{ github.repository_owner }}/nyxelos-${{ matrix.image }}
tags: |
type=raw,value=latest,enable={{is_default_branch}}
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=sha,prefix=,format=short

- name: Build and push
uses: docker/build-push-action@v6
with:
context: .
file: ${{ matrix.dockerfile }}
platforms: linux/amd64,linux/arm64
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha,scope=${{ matrix.image }}
cache-to: type=gha,mode=max,scope=${{ matrix.image }}
74 changes: 74 additions & 0 deletions .github/workflows/package.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
name: create-nyxel package

on:
pull_request:
branches: [main]
paths:
- packages/create-nyxel/**
- .github/workflows/package.yml
push:
branches: [main]
tags: ["create-nyxel@*"]
paths:
- packages/create-nyxel/**
- .github/workflows/package.yml

concurrency:
group: package-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:
name: Build & smoke test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.14
- run: bun install --frozen-lockfile
- run: bun run --cwd packages/create-nyxel typecheck
- run: bun run --cwd packages/create-nyxel build
- name: Smoke test the CLI
run: |
node packages/create-nyxel/dist/index.js --help
node packages/create-nyxel/dist/index.js --mode pc --dir /tmp/create-nyxel-smoke-pc --yes
node packages/create-nyxel/dist/index.js --mode server --domain nyxel.example.com --dir /tmp/create-nyxel-smoke-server --yes
test -f /tmp/create-nyxel-smoke-pc/docker-compose.yml
test -f /tmp/create-nyxel-smoke-server/Caddyfile

publish:
name: Publish to npm
needs: build
if: startsWith(github.ref, 'refs/tags/create-nyxel@')
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
with:
bun-version: 1.3.14
- uses: actions/setup-node@v4
with:
node-version: 20
registry-url: https://registry.npmjs.org

- run: bun install --frozen-lockfile
- run: bun run --cwd packages/create-nyxel build

- name: Verify tag matches package.json version
run: |
TAG_VERSION="${GITHUB_REF#refs/tags/create-nyxel@}"
PKG_VERSION=$(node -p "require('./packages/create-nyxel/package.json').version")
if [ "$TAG_VERSION" != "$PKG_VERSION" ]; then
echo "Tag create-nyxel@$TAG_VERSION does not match package.json version $PKG_VERSION"
exit 1
fi

- name: Publish
working-directory: packages/create-nyxel
run: npm publish --provenance --access public
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
31 changes: 31 additions & 0 deletions .github/workflows/pr-title.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
name: PR title

on:
pull_request_target:
types: [opened, edited, synchronize, reopened]

permissions:
contents: read
pull-requests: read

jobs:
conventional-commit:
name: Conventional commit format
runs-on: ubuntu-latest
steps:
- uses: amannn/action-semantic-pull-request@v5
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
types: |
feat
fix
docs
style
refactor
perf
test
build
ci
chore
revert
25 changes: 23 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,9 +21,24 @@ Run NyxelOS entirely on your hardware or deploy it across a server cluster. Full
---
### 📖 Getting Started & Deployment Modes

#### 🚀 Just want to run it? `npx create-nyxel`
No checkout, no build toolchain — this pulls the published `ghcr.io/quavon-dev/nyxelos-*` images and writes only the Docker Compose files you need to run NyxelOS.
```bash
npx create-nyxel
# or: bunx create-nyxel

cd nyxel
docker compose up -d
```
See [`packages/create-nyxel`](packages/create-nyxel) for all options (`--mode`, `--dir`, `--tag`, `--domain`, ...).

> 💡 Everything below this point (`git clone`, `bun install`, `docker compose -f docker-compose.*.yml up --build`) is the **development** workflow — building from source. Use it if you're contributing to NyxelOS, not just running it.

#### 💻 Local Development (Dev Machines / Quick Test)
Ideal for development and personal testing without Docker. Requires [Bun](https://bun.sh) 1.3+.
```bash
git clone https://github.com/Quavon-dev/nyxelos.git
cd nyxelos
bun install

# Setup environment files
Expand All @@ -43,8 +58,8 @@ Give Nyxel access to your local ecosystem! The `apps/companion-macos` package fu

This is the bridge between AI and your desktop life. Full detail in [`apps/companion-macos/README.md`](apps/companion-macos/README.md).

#### 🐳 Docker Compose Deployment (PC Mode / Server Mode)
Deploying via Docker is the recommended path for stability.
#### 🐳 Building the Docker Images From Source (PC Mode / Server Mode)
Prefer to build from this checkout instead of using the published images? Same compose files, with `--build`:

**🖥️ PC Mode (Testing/Home Server):**
```bash
Expand Down Expand Up @@ -90,12 +105,18 @@ apps/
packages/
db/: Drizzle Schema & Repository Layer (Postgres/SQLite) 🗄️
model-providers/: Handles routing between local and cloud AI models. ☁️⚡️
create-nyxel/: The `npx create-nyxel` / `bunx create-nyxel` setup CLI. 🚀
```

### ⚙️ Development Tools
* **DB Migration:** Use `bun run db:generate` and `bun run db:migrate`.
* **Knowledge Base:** All documentation lives in the Obsidian vault, automatically synced via ADR-0013.

### 🤖 CI/CD
* **Pull requests:** lint, typecheck, and build run on every PR (`.github/workflows/ci.yml`), alongside a conventional-commit PR title check, CodeQL analysis, and a dependency review.
* **Docker images:** `apps/server` and `apps/web` are built on every PR (validation only) and pushed to `ghcr.io/quavon-dev/nyxelos-server` / `nyxelos-web` on merges to `main` and version tags (`.github/workflows/docker.yml`).
* **`create-nyxel`:** built and smoke-tested on every PR, published to npm on `create-nyxel@<version>` tags (`.github/workflows/package.yml`).

🔗 **Architecture Plan:** [`docs/ARCHITECTURE.md`](docs/ARCHITECTURE.md)
🔗 **Installation Guide:** [`docs/INSTALL.md`](docs/INSTALL.md)
🔗 **Obsidian Knowledge Base:** [`knowledge-base/`](knowledge-base/)
Loading
Loading