Why Nix?
If you’ve opened this PDF, you already have your own motivation for learning Nix. Here’s how it helps me. As a researcher, I tend to work on a series of short-term projects, mostly demos and prototypes. For each one, I typically develop some software using a compiler, often with some open source libraries. Often I use other tools to analyse data or generate documentation, for example.
Build and share reproducible software environments with Nix and NixOS
What if told you, that you can have a portable Neovim configuration, that runs on any system that has Nix? And that you only need a single nix run command to execute it, without having to clone your .config/neovim and install your plugins?
Learn alongside me - The nix programming language can be a little intimidating, do what I do and you'll know it too!
This manual will eventually describe how to install, use, and extend Home Manager.
- GitHub - nix-community/home-manager: Manage a user environment using Nix [maintainer=@khaneliman, @rycee] · GitHub
- Home Manager - NixOS Wiki
- Home Manager - Official NixOS Wiki
This section lists the values and functions built into the Nix language evaluator. All built-ins are available through the global builtins constant.
Some built-ins are also exposed directly in the global scope:
- derivation
- import
- abort
- throw
Nix is a purely functional package manager. This means that it treats packages like values in purely functional programming languages such as Haskell — they are built by functions that don’t have side-effects, and they never change after they have been built. Nix stores packages in the Nix store, usually the directory /nix/store, where each package has its own unique subdirectory such as
/nix/store/b6gvzjyb2pg0kjfwrjmg1vfhh54ad73z-firefox-33.1/
where b6gvzjyb2pg0… is a unique identifier for the package that captures all its dependencies (it’s a cryptographic hash of the package’s build dependency graph). This enables many powerful features.
Let’s talk about Docker and Nix today. Before explaining what Nix is, if you don’t know yet, and before going into the details, I will show you a snippet similar to a Dockerfile for creating a Redis image equivalent to the one in docker hub.
The final image will be around 42mb (or 25mb) in size, compared to 177mb.
EDIT: as mentioned on HN, alpine-based images can even go around 15mb in size.
If you want to try this, the first step is to install Nix.
Build Your Own Darknet
Discover the simplest way to re-enter independent computing with our framework. Placing control directly at your fingertips.
Self-hosting services empowers you with greater control and flexibility over your data. However, maintaining such systems today often comes with significant technical challenges, including firewall/NAT configuration, data loss prevention, and security management.
The Clan project aims to lower the technical barriers of self-hosting with NixOS, making it accessible even to non-technical users. Our goal is to simplify the installation and maintenance of NixOS machines.
In this talk, we will present the new NixOS extensions we've developed to scale self-hosting, including VPN integration, backup management, secret management, a unified CLI for installation and updates, and an inventory system for managing clusters of machines.
We will also provide a sneak preview of the upcoming graphical user interface.
NixCon is a community-oriented conference for contributors and users of Nix and NixOS. It's about sharing experiences, inspiring people and discussing future development. We would like to learn about how you use Nix and NixOS in your organization and what you are currently working on. The growth of NixOS as a project brings its own challenges and we would like to know how you think the user experience can be improved and how NixOS can be scaled.
- NixCon - the community conference about Nix & NixOS
- Github: NixCon - the community conference about Nix & NixOS
![]()
microvm.nix is a Flake to run lightweight NixOS virtual machines on NixOS. Starting with the reasons why for the remainder of this chapter, this handbook guides you through the provisioning of MicroVMs on your NixOS machine.
Compartmentalization
NixOS makes running services a breeze. Being able to quickly rollback configuration is a life-saver. Not so much however on systems that are shared by multiple services where maintenance of one affects others.
Increase stability by partitioning services into virtual NixOS systems that can be updated individually.
microvm.nix can isolate your /nix/store into exactly what is required for the guest's NixOS: the root filesystem is a read-only erofs/squashfs file-systems that include only the binaries of your configuration. Of course, that holds only true until you mount the host's /nix/store as a share for faster build times, or mount the store with a writable overlay for Nix builds inside the VM.
The Case Against Containers
Linux containers are not a single technology but a plethora of kernel features that serve to isolate various system resources so that the running system appears as one. It is still one shared Linux kernel with a huge attack surface.
Virtual machines on the other hand run their own OS kernel, reducing the attack surface to the hypervisor and its device drivers. The resource usage however incurs some overhead when compared with containers, with memory allocation being especially inflexible.
microvm.nix is a tool that helps you building the guest's OS and running it in ways that are easier than writing a Dockerfile, once you know how to put a NixOS config into a flake.nix file.
Just Virtual Machines?
Full virtualization has been available for a long time with QEMU and VirtualBox. The MicroVM machine type highlights that virtualization overhead has been reduced a lot by replacing emulated devices with virtio interfaces that have been optimized for this environment.
This Flake offers you to run your MicroVMs not only on QEMU but with other Hypervisors that have been explicitly authored for virtio. Some of them are written in Rust, a programming language that is renowned for being safer than C.
NixVim - A Neovim configuration system for nix
A KISS deployment tool to keep your NixOS fleet (servers & workstations) up to date.
This name was chosen because Bento are good, and comes with the idea of "ready to use". And it doesn't use "nix" in its name.
Use with flakes: nix shell github:rapenne-s/bento
Nix is a powerful package manager for Linux and other Unix systems that makes package management reliable and reproducible.
- Resources
- Learning
- Discovery
- Installation Media
- Channel History
- Deployment Tools
- Virtualisation
- Command-Line Tools
- Development
- DevOps
- Programming Languages
- Arduino
- Clojure
- Crystal
- Elm
- Gleam
- Haskell
- Haxe
- Lean
- Node.js
- OCaml
- PHP
- PureScript
- Python
- Ruby
- Rust
- Scala
- Zig
- NixOS Modules
- NixOS Configuration Editors
- Overlays
- Distributions
- Community
The Nix language is designed for conveniently creating and composing derivations – precise descriptions of how contents of existing files are used to derive new files. It is a domain-specific, purely functional, lazily evaluated, dynamically typed programming language.
You may quickly encounter Nix language expressions that look very complicated. As with any programming language, the required amount of Nix language code closely matches the complexity of the problem it is supposed to solve, and reflects how well the problem – and its solution – is understood. Building software is a complex undertaking, and Nix both exposes and allows managing this complexity with the Nix language.
Yet, the Nix language itself has only few basic concepts that will be introduced in this tutorial, and which can be combined arbitrarily. What may look complicated comes not from the language, but from how it is used.
Overview
This is an introduction to reading the Nix language, for the purpose of following other tutorials and examples.
Using the Nix language in practice entails multiple things:
- Language: syntax and semantics
- Libraries: builtins and pkgs.lib
- Developer tools: testing, debugging, linting, formatting, …
- Generic build mechanisms: stdenv.mkDerivation, trivial builders, …
- Composition and configuration mechanisms: override, overrideAttrs, overlays, callPackage, …
- Ecosystem-specific packaging mechanisms: buildGoModule, buildPythonApplication, …
- NixOS module system: config, option, …
This tutorial only covers the most important language features, briefly discusses libraries, and at the end will direct you to reference material and resources on the other components.