If you are using an Apple Silicon laptop and you want to deploy to an x86-64 Linux box, this can get a bit annoying due needing to deal with cross compilation in nix.
server:
@echo "Deploying machine (with ssh-agent forwarding): '$(MACHINE)'"
NIX_SSHOPTS="-A" \
nix run nixpkgs#nixos-rebuild -- switch \
--flake .#$(MACHINE) \
--target-host $(MACHINE).$(DOMAIN) \
--build-host $(MACHINE).$(DOMAIN) \
--no-reexec \
--verbose \
--sudo
Which has been working well. I admit I do not understand what all of these flags do in detail.This uses ssh agent forwarding, and then sudo via PAM. That allows for passwordless sudo. Building (well, activating) without sudo is pretty involved last I checked, I could not get it to work.