Skip to content
Nix binary cache

Download Nix outputs instead of rebuilding them.

Share completed store paths and their dependencies with compatible Linux and macOS builds. Nix keeps its derivations and substitution rules.

.boringcache.toml
workspace = "my-org/app"

[adapters.nix]
tag = "nix-cache"
command = ["nix", "build", "."]
boringcache nix
permissions:
  contents: read
  id-token: write

steps:
  - uses: boringcache/one@f0fb9b2d926a32b10c543e92093ba00c5a291b79 # v1.33.0
    with:
      mode: nix
      trust-policy: auto
  - run: nix build .
steps:
  - label: Build
    command: >
      boringcache ci run
      --oidc-provider buildkite
      -- boringcache nix
build:
  timeout: 1h
  id_tokens:
    BORINGCACHE_OIDC_TOKEN:
      aud: urn:boringcache:workload
  script:
    - boringcache ci run --oidc-provider gitlab -- boringcache nix

How BoringCache fits your build.

Completed paths

Retrieve published outputs on a fresh machine.

Their closures

Make the required output dependencies available too.

Scoped trust

Keep global Nix signature checks enabled.

A binary cache for your existing Nix builds.

BoringCache provides the HTTP cache endpoint. For multi-user Nix, the runner identity needs the trusted-user permissions required by the per-command setup.

See what your Nix builds restore and publish.

Inspect binary-cache reads, transfers, and published cache data in your workspace.

Explore the workspace →
Workspace insights

Cache activity

Inspect reads, misses, and writes.

Transfers

See what each build downloads and uploads.

Storage

Track stored cache data in your workspace.

Keep shared-cache publication in trusted jobs.

Give consumers restore access and publishers a separate permission. Connect supported CI through OIDC or use scoped credentials.

Connect your CI →

Separate readers and publishers

  • Trusted builds Publish shared cache for the next build Read + publish
  • Pull requests Restore cache without replacing it Read only
  • Local development Use a scoped credential for the workspace Scoped access

Before you connect.

Does BoringCache replace the Nix store?
No. Nix still handles derivations, closures, store paths, and substitution. BoringCache provides the HTTP binary-cache endpoint used for shared reads and writes.
Do Nix signature checks stay enabled?
Yes. Trust is limited to the runner-local BoringCache store for the invocation.
What changes for multi-user Nix?
The runner user or one of its groups must be listed in Nix trusted-users so the per-command substituter and hook settings can reach the daemon.
Read the Nix setup guide →

Start with your next Nix build.

Install the CLI. Run onboarding to connect your repository and configure your cache.

30 GB of cache free. No credit card required.

curl -sSL https://install.boringcache.com/install.sh | sh
boringcache onboard
boringcache nix