The heredoc-based script writer in web.nix was indenting content inside
a nix '' string, which caused bash to prepend whitespace before the
#!/usr/bin/env bash shebang. The kernel rejected this as 'Exec format
error' (203/EXEC), preventing systemd from starting mcpedia-web.service.
Fix: use writeShellScriptBin instead of a raw heredoc. This ensures the
shebang starts at column 0 and uses the nix-resolved bash path.
Replace --external approach (which failed because @mcpedia/* workspace
packages couldn't resolve their npm deps like ioredis/bullmq at runtime)
with full bundling. The key fixes:
1. Bundle all code into a single JS file (no --external for @mcpedia/*)
- This inlines @mcpedia/core, @mcpedia/queue, ioredis, bullmq, etc.
- Produces ~2.6MB self-contained binary, no node_modules needed
2. Fix .bun cache symlink issues in nix sandbox:
- After bun install, copy .bun cache with cp -rL to dereference
relative symlinks that break in nix build sandbox
- This was the root cause of 'File not found msgpackr-extract' errors
3. Only @mcpedia/config, embeddings, types kept external (lightweight,
no npm deps) - resolved via packages/ source symlinks at runtime
All 3 services (api, mcp, worker) now build and run successfully in nix store.
Resolves CI failure run 32474463114 ('Cannot find module @mcpedia/core').