Impermanence
nixos.wiki
nixos.wiki
1. https://grahamc.com/blog/erase-your-darlings/
2. https://gist.github.com/mx00s/ea2462a3fe6fdaa65692fe7ee824de...
3. https://gist.github.com/jbott/531b9d555dae7f197f25326ef251f1...
you can also use impermanence with home-manager if you want
It seems like there are two contradictory goals here, each with their own benefits. Impermanence gives you reproducibility, but permanence gives you performance.
Maybe the right tradeoff is to just persist the entire home folder and nothing else (or few other things... I'm not sure I'd want to always download some programs that are quite huge), but the tradeoff is essentially still there.
if you want a reproducible root filesystem, use NixOS. if you want to reproduce your root filesystem on boot, use NixOS with impermanence.
if you want a reproducible home folder, use home manager. if you want to reproduce your home folder on boot, use home manager with impermanence.
I only use impermanence on servers. I don't think there's any point using it on a desktop, or with Home Manager, other than street cred. it just complicates things. I don't really even recommend Home Manager for first time NixOS users for the same reason.
edit: and I want to address this comment:
> I'm not sure I'd want to always download some programs that are quite huge
this isn't how it works; the binaries, as well as the entire initial state of the filesystem, are cached in the Nix cache, a read-only filesystem. you're not downloading everything on every boot.
Tools and dependencies go in nix. Indexes and temporary build stuff is just cache, which you can still have (I'd lean towards regenerating per reboot, but YMMV).
> but it's going to be a lot of effort trying to figure out where all your tools are dumping their state.
Fair. Kind of an indictment of the current state of the ecosystem, but yes.
> but it's going to be a lot of effort trying to figure out where all your tools are dumping their state.
This is true though, if you dont want to manage all of their configs from nix, I would make their dump locations, or $XDG_DIRS/$HOME (if you are lazy) permanent in this case.
With / all in memory it automatically gets wiped and recreated every reboot, without needing to actively erase a disk, and thus with much less drive wear (depending on how frequently you reboot). It’s also faster on some things when loading from RAM instead of the disk. And it’s overall a cleaner, simpler setup.
https://elis.nu/blog/2020/05/nixos-tmpfs-as-root/
You can also put tmpfs on home as well, using Impermanence and Home Manager to persist things like ~/.config and whatever other files or folders need to persist between reboots:
https://elis.nu/blog/2020/06/nixos-tmpfs-as-home/
tmpfs on / is enabled by NixOS’s unique design, in which it keeps the entire system in /nix/store and then softlinks all the paths into their appropriate place in /. With tmpfs on /, NixOS automatically recreates those softlinks in tmpfs on reboot. Very little setup effort is required to make this work.
Unless you’re working on a server with a ton of ram, I also think using tmpfs is more likely to shoot yourself in the foot with excess memory pressure. I don’t know of a way for the kernel to free memory if you write a huge file to the tmpfs partition by mistake, unless you use swap, and then you have the problems that come with that.
Tmpfs might be faster though!
It defaults to 50% of physical RAM, but you can set the size option to whatever you want: https://www.kernel.org/doc/html/latest/filesystems/tmpfs.htm...
(So yes, something to consider, but totally possible to mitigate)
Everything that needs to be persisted for / is done so either in configuration.nix (or equivalent flake), or using Impermanence. Once you've persisted things in one of those, it will remain so for all future derivations.
You can also create separate ZFS pools for things like LXC/LXD that need to persist between boots, but don't naturally go in / or /home.
Rather than using a script for setup, I am using disko [0] with nixos-anywhere [1] and a small home-grown script that integrates with 1Password for deployments and it's wonderful, because everything including disk formatting is now purely declarative.
On my Fedora Silverblue, only /etc and /var are mounted read-write. /home is a symlink to /var/home, /root is a symlink to /var/root.
1: https://www.illucid.net/static/unpublished/erasing-darlings-...
edit: oh, lol, didn't escape the heredoc at all, import zfs / other guile modules, or put parted in the shebang; ah well
that's what i mean by informational
For example, I have still not been able to run Sway as a window manager because I can't find how to set it up properly using Home Manager (doing the equivalent with an .xsession and i3 was no problem). The wiki article about it (https://nixos.wiki/wiki/Sway) has a lot of configuration at the system level configuration.nix, but most of that is missing from the ostensibly equivalent Home Manager config.
It seems like a design error that the Home Manager configuration options do not map 1:1 to the NixOS configuration options for users, and I'm guessing that error is caused by a lack of interest in properly configured multi-user systems.
While I cannot speak to the reasons behind the schism, home-manager is better thought of as independent project that builds off of abstractions in nixpkgs, without taking into account what NixOS does.
And no, it is not a design error to have Home Manager separated from nixpkgs, and unlike a child reply suggests, there's no "schism", and the reasons for separation are rather prosaic, as explained in another blog post of mine [2].
[1] https://drakerossman.com/blog/wayland-on-nixos-confusion-con...
[2] https://drakerossman.com/blog/how-to-add-home-manager-to-nix...
as a teenager i ran gentoo & passively marvelled in the back of my head that this self-described “meta-distribution” was flexible enough to serve as the basis of chromeos or whatever
it's no coincidence that “gentoo but Good Actually” was one of the descriptions i heard that convinced me to give nixos a spin, paralleled further by the fact that i unironically ran gentoo prefix on macos in lieu of homebrew/macports for a while, and would later go on to run nix-darwin
this particular instance of flexibility, though, feeds back nicely into one of the bullet points on the nixos elevator pitch (one little config directory is all you need to care about outside /var or /home). in a sense, running this setup is putting your money where your mouth is as far as that claim is concerned. and hey whoa would you look at that, it works. neat!