# ADR-0004: Nix-built OCI images start server-side with Crucible; local Anvil images deferred - **Status:** Accepted - **Date:** 2026-06-12 - **Migrated from:** `sow-docs` `07-decisions-log.md` entry **D29**, on the retirement of `sow-docs`. Content is the original decision, unchanged. - **Decision:** Introduce Nix-built OCI images as an artifact-production option, starting with `sow-tools`/Crucible in server-side CI. `sow-tools` will grow a Nix-built `crucible` package plus `crucible-image`; PR CI builds/smokes it and `main` publishes the normal pinned OCI image `registry.westgate.pw/deployment/crucible:`. `docker/Dockerfile` stays during parity and as the client-compatible fallback. - **Local rule:** Nix users may get optional wrappers that provide tools and call the existing Dockerfiles for local Anvil/NWServer testing. A true `nix build .#nwserver-test-image` is explicitly deferred until real `sow-codebase/src` exists and the Dockerfile image is proven. - **Rationale:** Server-side image build shape is harder to change once deploy promotion and registry gates are active, so prove Nix image builds before cutover. Crucible is the lowest-risk pilot because it is a Go toolchain image; NodeBB and Anvil/NWServer depend more heavily on upstream container filesystem semantics. - **Non-goals:** no source builds in `sow-platform`; no `nix-sidecar` or Kubernetes-style runtime cache layer; no removal of client Dockerfiles.