T1: dev PDS moves to ZDS (devenv runner + smoke)
closedParent: bug 75966cc (cell architecture tracking).
Goal
Replace the Bluesky reference-image dev PDS with ZDS in devenv up, so dev
matches the locked production pick (ZDS) from day one.
Scope
- New runner (replace/retire
nix/scripts/serve-pds-upstream.sh): build ZDS (Zig via devenv or pinned container), envZDS_DB=$SOVRN_DATA_DIR/zds/zds.sqlite3,ZDS_BLOBSTORE_PATH=$SOVRN_DATA_DIR/zds/blobs, fixed dev secrets,:3000. devenv.nix:processes.pdspoints at the ZDS runner; health gate ondescribeServer; extendsovrn-resetto wipe ZDS state.PDSProvisionerstub docs note ZDS as the live target (no prod wiring here).
Acceptance
devenv upbrings ZDS healthy; smoke passes: create account, resolve handle, OAuth login via authbroker, upload blob, export CAR.- CI matrix runs the same smoke; reference-image leftovers removed.
- Split follow-up if big: 1a runner, 1b smoke/contract suite.
2 Comments
ZDS Dev PDS Implementation Plan
Goal: Build ZDS from source with Nix, run it natively via
devenv processes upon:3000, and verify with a 5-step smoke (account, handle, OAuth, blob, CAR); the same Nix binary ships to the production cell (T2).Architecture: New
nix/pkgs/zds.nixZig package (main-branch rev pin,fetchZigDepsFOD for simplest robust offline deps) exposed asflake.packages.zds; native runnernix/scripts/serve-zds.shexecs${zds}/bin/zdswith fixed dev env (ZDS_DB,ZDS_BLOBSTORE_PATH, secrets);devenv.nix:processes.pdspoints at the runner; reference-image leftovers removed; bash smokescripts/smoke-zds.sh+just smoke-zdscovers acceptance.Tech Stack: Zig 0.16.0 (
pkgs.zig_0_16,zig.hook), ZDStangled.org/zat.dev/zdsmain-rev, SQLite + disk blobs, bash/curl/jq smoke (curl+jq already in devenv shell), podman removed from PDS path, Goauthbrokerfor OAuth leg.User choices locked: main-branch rev pin · native binary (not OCI) · runner+smoke in one plan · simplest build over hermeticity (
fetchZigDepsFOD). No CI yet (hosting/CI still being evaluated) — smoke isjust smoke-zds, CI wiring is a later follow-up.Task 1: Nix ZDS package from source
Files: - Create:
nix/pkgs/zds.nix- Create:nix/pkgs/zds-deps.nix(FOD wrapper) - Reference:nix/pkgs/stalwart.nix:1-73,nix/lib.nix:1-84,flake.nix:1-43Run:
nix eval --raw nixpkgs#zig_0_16.version 2>&1 || devenv shell nixpkgs#zig -- zig versionExpected:0.16.0(matches ZDSminimum_zig_version = "0.16.0").Run:
git ls-remote https://tangled.org/zat.dev/zds HEADExpected: one SHA. Record full 40-char SHA + date forrev/version(e.g.version = "0.3.1+unstable-2026-09-14").nix/pkgs/zds.nixRun:
nix --extra-experimental-features 'nix-command flakes' build .#zds --print-out-paths -L 2>&1 | tail -20Expected: FAIL first time withexpected sha256:...forsrc-hash/depsHash→ paste back, re-run until PASS andresult/bin/zds --helplists--port --db --host.Task 2: Flake + Justfile build entrypoints (prod-reusable binary)
Files: - Modify:
flake.nix:30-42- Modify:Justfile:50-71(mirrorbuild-stalwart)packages.zdsUpdate the
NOTE:comment atflake.nix:10-16→ ZDS is now Nix-built; keep one line noting the old@atproto/pdsworkspace:*breakage is historical.just build-zds(prod reuse + libc gate)Run:
nix --extra-experimental-features 'nix-command flakes' build .#zds --print-out-paths && ls -la result/bin/zds && just build-zdsExpected: PASS,deployment/.local/zds-prod/bin/zdsexecutable, glibc check OK.Task 3: Dev runner script (native binary)
Files: - Create:
nix/scripts/serve-zds.sh- Reference:nix/scripts/serve-pds-upstream.sh:1-58,nix/scripts/serve-stalwart.sh:40-51nix/scripts/serve-zds.shMake executable:
chmod +x nix/scripts/serve-zds.sh.Run:
bash -n nix/scripts/serve-zds.sh && shellcheck nix/scripts/serve-zds.shExpected: PASS.Open question: confirm
ZDS_PERMISSIONED_DATA=truein dev (matches prod; gatescom.atproto.space.*). If smoke hits spaces lexicons, keeptrue.Task 4:
devenv.nixwiring (processes, reset, health, toolchain)Files: - Modify:
devenv.nix:6-11,42-83,94-117,119-143,177-187zdsderivation + Zig toolchain(curl+jq already added to devenv shell per user — verify present, do not duplicate.)
processes.pdswith native runnerDelete the
Decision 2026-08-24comment about the spaces-alpha image.sovrn-resetto wipe ZDS statesovrn-pdscontainer name removed (native process); oldpds/dir intentionally orphaned (one-time stale reference state).Health at
devenv.nix:119-143already polls3000/xrpc/com.atproto.server.describeServer— keep. Same forenterTest.Run:
devenv processes up -d && sleep 5 && curl -fsS http://127.0.0.1:3000/xrpc/com.atproto.server.describeServer | jq . && curl -fsS http://127.0.0.1:3000/xrpc/_health; devenv processes downExpected: both 200;describeServershowsinviteCodeRequired:false.Task 5: Retire reference-image leftovers
Files: - Delete:
nix/scripts/serve-pds-upstream.sh- Modify:flake.nix:10-16,docs/06-pds-selection.md:8-16Run:
rm nix/scripts/serve-pds-upstream.shEditdocs/06-pds-selection.md:8-16dev-runtime note →Development runs nix-built ZDS natively on :3000 (nix/pkgs/zds.nix + nix/scripts/serve-zds.sh); the Bluesky spaces-alpha image was retired in T1 (bug f1be097).Run:
rg -n "serve-pds-upstream|pds-spaces-alpha|ghcr.io/bluesky-social/atproto|SOVRN_PDS_IMAGE" --glob '!devenv.lock' --glob '!.devenv/**'Expected: zero hits except historical ADR mentions.Task 6: Smoke suite (5-step acceptance, no CI yet)
Files: - Create:
scripts/smoke-zds.sh- Modify:Justfile:185-189(addsmoke-zdstarget),internal/pdsprovisioner/provisioner.go:39-40(doc note) - Reference: upstreamtools/smoke.sh,internal/authbroker/authbroker.go,internal/integration/helpers_test.go:27-38scripts/smoke-zds.sh(bash,set -euo pipefail, curl+jq from devenv shell; PDS athttp://127.0.0.1:3000)Implementer: add
scripts/testdata/pixel.png1×1 fixture, strict OAuth leg viaauthbroker.StartLogin($HANDLE)helper if cheap, else metadata-gate + WARN as above.just smoke-zdsRun:
devenv processes up -d && just smoke-zds; ST=$?; devenv processes down; exit $STExpected:SMOKE OK: did:plc:..., exit 0.Task 7: Final verification + handoff
Run:
sovrn-reset; devenv processes up -d; sleep 5; curl -fsS http://127.0.0.1:3000/xrpc/com.atproto.server.describeServer; just smoke-zds; just testExpected: describeServer 200,SMOKE OK,just testPASS.Run:
nix --extra-experimental-features 'nix-command flakes' build .#zds --print-out-paths; ./result/bin/zds --help | head -20Expected: out-path recorded;--helpmatches serve-zds.sh env. Paste out-path + rev into bug f1be097 comment for T2.Done (commit zwrxyorl). T1 dev-ZDS complete, all acceptance green.