* Rejiggered CI * don't use prod dockerhub * Added explicit bash shell * pass cachix singing key * checkout first * removed no-auto-link-without-protocol * pass docker hub creds as inputs * wip * wip