An Overview of Nix in Practice
slice.zone
slice.zone
My biggest issue with homebrew is you’re always at head and you always upgrade the world. This is not good when you want repeatable things to happen. My second biggest issue with nix is you can pin things, but it’s pinned to some obtuse hash of the world. I build embedded code and I just want my toolchains to work perfectly, including avoiding the weird cmake bug in >3.25 that keeps dropping —std=20 from my arguments and then failing to build my “modern” c++ code. The amount of work this takes is too damn high with both brew and nix.
Previously, I worked on and delivered a developer command line Swiss Army knife type tool, you have probably seen them. They do everything from build, docker, package, test, submit code, tail logs, etc. These have a ton of dependencies, and when you support Macs you end up using homebrew. Your install can then be broken by someone brew installing something mundane in their own machine. Not good. I tried to use nix for this, but packaging coverage wasn’t enough so I ended up wasting time packaging my own dependencies. Not good. I ended up putting a parallel brew repo up in my private git repo, then using a hidden brew that wasn’t on the user’s regular path to install the tools I needed at the right versions, and only upgrade them after I’d confirmed they worked. Still a waste of time and space but at least it didn’t suck up weeks of my time.
I’m back in a similar space. I’ve got a complex set of tooling I want to share the install with to my teammates so we don’t have random issues with it, and we’re on Mac, Linux, and Windows. I just want to pin to version numbers (and a bunch of it is python with version pinned requirements, installed by scripts that someone wrote who doesn’t use nix and expects a global imperative environment) so I’m back to hosting my own brew repo. This is really what nix should make trivial but to me it’s a leaky abstraction. I keep having to look under the hood and do my own work to make it function.
Part of why I still just use nix-env instead of doing it the "right" way - it provides that simple "just install it" interface.
Have you looked into it all? I think it uses flatpak and containerizaton to separate the base OS from everything else.
Not sure if it would help with my driver issues though.
It's a variant of Silverblue with Nvidia drivers built in.
Little to none of it will be helped by docker. Trust me, if there was an easy button for this I would have pressed it already.
Well said, lol
I'd love to see more concerted efforts going the other direction -- managing complexity by working to make the system simpler and compartmentalizing additional functionality. System snaps, now packaging lxd and cups, are probably the closest mainstream example today.
However, I do agree that there is a lot of unnecessary complexity in our tech stacks today; though I blame much of this on how young the concept of computing and information theory still is. We're still exploring, we're still building, and it's really exciting to me to have the opportunity to work in a space that is only in its infancy. There is so much room for almost anyone in the field to bring innovations and improvements, if only so many of us weren't slaves to grinding our bones, and finite time, to dust creating things of dubious moral value under an almost singular focus on monetary wealth and the threat of death and ostracism.
I have exactly this problem. I need to run centos7-era binary application on rocky9, and of course, it does not compile on the new gcc compiler in rocky9, and also some libraries are missing/have changed too much.
I was thinking I will run the app in a centos7 container on rocky9 machine, but this creates lots of unwelcome complications and additional work.
I'm not very familiar with Nix, but it seems one could install Nix on rocky9 and then somehow use it to build my application against the centos7 devel libraries. Do you think this is a plausible pathway for compiling and running such an old application? It would be great if I could just compile the old app on the new system and forget about containers.
OMG, this is almost exactly the thinking/feeling that has kept me happily addicted to linux distros (and FLOSS in general) for almost 2 decades! And, now, hearing this about Nix, seems quite tempting. :-)
> "What I find to be most useful for me is declarative system management via NixOS. My memory span is virtually nonexistent nowadays, and having a way to declare my servers completely idempotently is an incredible way to avoid confusion and stress. I like having that philosophy extended to my personal projects and user environment, as it ensures a level of consistency and reproducibility that I haven’t found anywhere else..."
For me, as much as i love diving into arcane topics around linux ditros, etc., there is still something to be said for limits on patience. so for some things, i actually don't want to spend time and attention, and want the benefits of a declarative approach. Maybe its an age thing for me, but moreso a thing of patience...and Nix here is ticking the right boxes.
Making Nix (particularly with flakes) my primary dependency this year has shifted my focus away from the operating system/Linux distribution I’m running on to making a totally portable env. I.E. I can be pretty comfortable on any OS, assuming I can use Nix.
It’s been really fun and useful for work and my homelabbing.
Here’s my Nix flakes repo for anyone curious: https://github.com/heywoodlh/flakes
Question, why the "heavily flake-based" organization? i.e. why structure your subdirectories as full flakes rather than e.g. modules?
heywoodlh.wezterm.enable = true;
But, ultimately, it boils down to that I haven’t gotten around to it yet. :)
To me, my first thought is to always deploy applications through containers (Podman + Systemd is my personal preference).
I see this as at least some isolation, I know containers are not a fool proof security system, but it at least some other layer, simple to deploy elsewhere, etc.
Is there a reason to preference running something "natively" in Nix over just using containers? Is Nix giving me anything if I mostly deploy containers? My servers are bootstrapped via pyinfra, and generally I just need to setup ssh, wg and a container runtime, so config drift isn't really much of an issue.
The Docker Compose story is a bit rough around the edges, though. I’m actually working on a tool to automatically convert a Compose project into a NixOS config you can import as-is. Still kinda early, but the basic skeleton works: https://github.com/aksiksi/compose2nix. You can see a sample output file here: https://github.com/aksiksi/compose2nix/blob/main/testdata/Te....
You can also run NixOS containers[1] - so you have a "real" NixOS configuration for your service that is still separated from the rest of the system via systemd-nspawn.
Common services usually have undergone some amount of hardening as well, so you probably aren't giving up much in terms of security vs. containers. Again, your mileage varies tremendously depending on the package, so I do strongly recommend reading the source of the nix module of security is a concern.
I also find that consulting the nix source for a service lets me quickly understand the different pieces that go into a deployment - this may not be an advantage to you if you aren't inclined to dive into nixpkgs source on the regular.
Finally, if you are at all bought in to Nix/NixOS then you will greatly appreciate being able to configure your services using module options that have already been created. You can also run docker containers in NixOS, but you'll experience quite a lot of friction if you want to expose service configuration as nix options. Using an existing NixOS module means someone else has done that work for you.
They do everything in a full programming language. That seems like an unnecessary layer of complexity. Other packages managers seem to mostly avoid the need to ever use the programming features, if they have any. Setup.py files are mostly just a static config, sometimes reading stuff from a file, only occasionally having any logic.
Nix seems like it's trying really hard to let you do whatever unusual stuff you want, rather than focusing on making common things easy.
I think a lot of the issue is that it's source-based, and they are aiming for purity and immutability throughout the whole process, above and beyond what other tools do.
They use unusual terminology and invent new concepts a lot. Like, a "derivation", which I understood at one point but forgot, but is like a Makefile equivalent, you make one with mkDerivation.
When you make a snap package, you pretty much just say "These versions of these .deb packages and these other snaps should be available in the environment of this package" and run it.
You can do "snap run --shell mysnap.mycommand" to mess around in the bash shell that your command would run in. It does pretty much everything I wanted Nix to do, and it's super easy.
I'm sure there are actual reasons why Nix isn't as easy as Snap though ,maybe the scope of the problem is just bigger, but it seems unnecessarily low level and hacker oriented rather than "just works" oriented, and the Nix website doesn't quite make it obvious whether this is a red had style production ready attempt, or am Arch style tinkerer OS.
Interesting. Since I've started using Nix for managing my environment & projects, it's the only thing that I'm confident will work. I have no idea how the RPM & DEB ecosystems, among others, work when random dependency breakage can happen all the time. This is extra true when building Docker images whose Dockerfile's second line is almost always `apt-get update && apt-get install [list-of-packages]`. I've had so many problems with that process over the years that I've wondered how anything worked at all. Nix was like some heavenly realm where I could be 99.9% confident the build would work every time.
I've never heard of kexec before; not very familiar why installing NixOS using kexec is only supported on x86 but not aarch64.
I wonder what are the advantages and downsides of nixos-anywhere v.s. nixos-infect.
I would not use it for a production system. Currently trying to migrate off of it to, I dunno, something else and Ansible. Nix has eaten hours of my life and upstream packages break all of the time. Couple of weekends ago the Mullvad module broke. Before that Virtualbox. Before that ZFS. You can have a perfectly fine configuration that you never touch but upstream instability will prevent a nixos rebuild from actually working.
Basically nixpkgs' maintenance policy is that only one version of a package should exist in their repositories. This being intended to reduce maintenance overhead since the nix package manager can freely switch package versions based on the nix channel (read: git branch or commit that nixpkgs is on).
The problem is that unless you meticulously start version pinning all your dependencies, your tooling will always run on the absolute latest version available, regardless of major/minor updates on either stable or unstable. Which can obviously cause problems.
It requires an extra step of care, one not particularly helped by the fact that actual version pinning for an individual package is done by the nixpkgs channel, rather than specifying the desired semver spec so unless you know beforehand what version is at which commit, it probably won't be helpful when it ends up rendering the OS unbootable (not to mention the questionable use in manually typing over git commit hashes but I digress on that).
For grabbing a package from another version of nixpkgs, its quite straightforward to only use that specific nixpkgs for one package and nothing else. NixOS also keeps old generations around in case the new configurations break anything, so I'm not very worried about the OS being rendered unbootable in any case (although I've never managed to break my NixOS, so I can't attest to having made use of this personally).
Not only is this now way cheaper (which increases profit margins for paid services I run), but it's also significantly more reliable as a one-person developer and de facto SRE.
The following explanation in the blogpost suggests that it's not the 'declarative' nature, so much as the application.. I liked the terms "convergent" and "congruent" that I first saw in https://flyingcircus.io/blog/thoughts-on-systems-management-...
"convergent" is "attempts to reach a target state" (like a Terraform apply), whereas "congruent" is "forced to target state" (like destroying/launching a VM).
Also, thanks for the interesting article! It coalesces some concepts that have been tenuously anchored in my mind for awhile. The lack of a story around convergent solutions in the IaC tooling is one of my biggest frustrations and is a primary driver behind my unreasonable love for k8s. Eventual consistency in platform/infra automation is a superpower.
Sounds like it might be by design, source-unavailable software being a ticking bomb among other issues ?
(Games get their source code lost too, and it also sucks when that happens.)
You can call it “by design” I guess, but it’s really more a consequence of their design.
Gitlab can be installed from a repo on Ubuntu, just sayin .. something like
deb https://packages.gitlab.com/gitlab/gitlab-ee/ubuntu/ focal main
That is all the overview that is necessary to understand.
If you also want to distribute pre-built binaries you would use a cache. https://cache.nixos.org/ is exactly that for nixpkgs. You can host your own via http(s), ssh or s3. There is also cachix, which is basically a hosting provider for nix caches that is pretty widespread in the community, I think.
The stable channels are basically "just" branched of from master (or nixpkgs-unstable? not sure) when the given point release is due (there is more to it, for example there is an effort made to make all the packages contained in that release actually buildable, called "Zero Hydra Failures" or ZHF). They will then mostly stay that way apart from the odd backport for security reasons and the likes.
Basically, it is very similar to how a larger software project might be managed with a develop branch and older releases that still receive backports.
(This is my mental model of it anyway, as a user for a few years. There are probably details that might be a bit off or not exactly accurate.)
It's not specifically nixpkgs, but any Nix code generally.
Per the Nix manual[0]:
> Channels are a mechanism for referencing remote Nix expressions and conveniently retrieving their latest version.
e.g. home-manager's suggested channel is just the github tarball for the relevant branch[1]:
nix-channel --add https://github.com/nix-community/home-manager/archive/master.tar.gz home-manager
[0] https://nixos.org/manual/nix/stable/command-ref/nix-channel[1] https://nix-community.github.io/home-manager/index.html#sec-...
You do not necessarily need nginx.
(or even a quality online tutorial?)