NixCon is a community-oriented conference for contributors and users of Nix and NixOS. It's about sharing experiences, inspiring people and discussing future development. We would like to learn about how you use Nix and NixOS in your organization and what you are currently working on. The growth of NixOS as a project brings its own challenges and we would like to know how you think the user experience can be improved and how NixOS can be scaled.
- NixCon - the community conference about Nix & NixOS
- Github: NixCon - the community conference about Nix & NixOS
![]()
microvm.nix is a Flake to run lightweight NixOS virtual machines on NixOS. Starting with the reasons why for the remainder of this chapter, this handbook guides you through the provisioning of MicroVMs on your NixOS machine.
Compartmentalization
NixOS makes running services a breeze. Being able to quickly rollback configuration is a life-saver. Not so much however on systems that are shared by multiple services where maintenance of one affects others.
Increase stability by partitioning services into virtual NixOS systems that can be updated individually.
microvm.nix can isolate your /nix/store into exactly what is required for the guest's NixOS: the root filesystem is a read-only erofs/squashfs file-systems that include only the binaries of your configuration. Of course, that holds only true until you mount the host's /nix/store as a share for faster build times, or mount the store with a writable overlay for Nix builds inside the VM.
The Case Against Containers
Linux containers are not a single technology but a plethora of kernel features that serve to isolate various system resources so that the running system appears as one. It is still one shared Linux kernel with a huge attack surface.
Virtual machines on the other hand run their own OS kernel, reducing the attack surface to the hypervisor and its device drivers. The resource usage however incurs some overhead when compared with containers, with memory allocation being especially inflexible.
microvm.nix is a tool that helps you building the guest's OS and running it in ways that are easier than writing a Dockerfile, once you know how to put a NixOS config into a flake.nix file.
Just Virtual Machines?
Full virtualization has been available for a long time with QEMU and VirtualBox. The MicroVM machine type highlights that virtualization overhead has been reduced a lot by replacing emulated devices with virtio interfaces that have been optimized for this environment.
This Flake offers you to run your MicroVMs not only on QEMU but with other Hypervisors that have been explicitly authored for virtio. Some of them are written in Rust, a programming language that is renowned for being safer than C.
NixVim - A Neovim configuration system for nix
A KISS deployment tool to keep your NixOS fleet (servers & workstations) up to date.
This name was chosen because Bento are good, and comes with the idea of "ready to use". And it doesn't use "nix" in its name.
Use with flakes: nix shell github:rapenne-s/bento
Nix is a powerful package manager for Linux and other Unix systems that makes package management reliable and reproducible.
- Resources
- Learning
- Discovery
- Installation Media
- Channel History
- Deployment Tools
- Virtualisation
- Command-Line Tools
- Development
- DevOps
- Programming Languages
- Arduino
- Clojure
- Crystal
- Elm
- Gleam
- Haskell
- Haxe
- Lean
- Node.js
- OCaml
- PHP
- PureScript
- Python
- Ruby
- Rust
- Scala
- Zig
- NixOS Modules
- NixOS Configuration Editors
- Overlays
- Distributions
- Community
If your machine doesn't currently have an operating system installed, you can still run nixos-anywhere remotely to automate the install. To do this, you would first need to boot the target machine from the standard NixOS installer. You can either boot from a USB or use netboot.
The NixOS installation guide has detailed instructions on how to boot the installer.
When you run nixos-anywhere, it will determine whether a NixOS installer is present by checking whether the /etc/os-release file contains the identifier VARIANT_ID=installer. This identifier is available on releases NixOS 23.05 or later.
If an installer is detected, nixos-anywhere will not attempt to kexec into its own image. This is particularly useful for targets that don't have enough RAM for kexec or don't support kexec.
NixOS starts an SSH server on the installer by default, but you need to set a password in order to access it.
NixOS is a Linux distribution where everything is described as code, with one exception: during installation, the disk partitioning and formatting are manual steps. disko aims to correct this sad 🤡 omission.
This is especially useful for unattended installations, re-installation after a system crash or for setting up more than one identical server.

Setting up a new machine is time-consuming, and becomes complicated when it needs to be done remotely. If you're installing NixOS, the nixos-anywhere tool allows you to pre-configure the whole process including:
- Disk partitioning and formatting
- Configuring and installing NixOS
- Installing additional files and software
You can then initiate an unattended installation with a single CLI command. Since nixos-anywhere can access the new machine using SSH, it's ideal for remote installations.
Once you have initiated the command, there is no need to 'babysit' the installation. It all happens automatically.
You can use the stored configuration to repeat the same installation if you need to.

In dieser Artikelserie stellen wir die Linux-Distribution NixOS vor. Im ersten Teil geht es um die grundlegenden Konzepte des Betriebssystems.
- NixOS Teil 1 - Ein deklaratives Betriebssystem
- NixOS Teil 2 - Installation und Konfigurationsdatei
- NixOS Teil 3 - Paketmanagement
- NixOS Teil 4 - Persönliche Erfahrungen und Empfehlungen

Die Installation von NixOS ähnelt der von Arch Linux. Daher sollten Personen, die schon einmal Arch Linux installiert haben, keine grösseren Probleme damit haben. Ich zeige hier alle Befehle, welche ich für die Installation verwendet habe. Die Installation verwendet eine LUKS Verschlüsselung mit LVM und UEFI.

The Pain of NixOS Beginners - Documentation and Flakes
NixOS is a highly distinctive Linux distribution built upon the Nix package manager, with a design philosophy that sets it apart from traditional distributions like Ubuntu, CentOS, Arch Linux and others.
One of NixOS's major advantages over other distributions lies in its reproducibility and declarative configuration, allowing users to replicate consistent system environments across multiple machines.
While NixOS is powerful, its strength also comes with increased system complexity. This makes it more challenging for newcomers. One major challenge is that the knowledge accumulated on other Linux distributions is not easily transferable to NixOS. Another is that official and community documentation is often scattered and outdated. These issues have troubled many NixOS beginners.
One can observe these issues with the experimental feature of the Nix package manager called Flakes. Inspired by package managers like npm and Cargo, Flakes uses flake.nix to record all external dependencies and flake.lock to lock their versions. This significantly enhances the reproducibility and composability of the Nix package manager and NixOS configurations.
Flakes' advantages have made it widely popular within the community: according to official surveys, over half of the new Nix repositories created on GitHub now utilize Flakes.
However, to maintain stability, the official documentation covers barely any Flakes-related content. This has left many Nix/NixOS users feeling confused. They see everyone using Flakes and want to learn it too, but find nowhere to start, often having to piece together scattered information, search through Nixpkgs source code, or seek help from more experienced users.
This manual describes how to install, use and extend NixOS, a Linux distribution based on the purely functional package management system Nix, that is composed using modules and packages defined in the Nixpkgs project.
Additional information regarding the Nix package manager and the Nixpkgs project can be found in respectively the Nix manual and the Nixpkgs manual.
If you encounter problems, please report them on the Discourse, the Matrix room, or on the #nixos channel on Libera.Chat. Alternatively, consider contributing to this manual. Bugs should be reported in NixOS’ GitHub issue tracker.
disko can either be used after booting from a NixOS installer, or in conjunction with nixos-anywhere if you're installing remotely.
Before using disko, the specifications of the disks, partitions, type of formatting and the mount points must be defined in a Nix configuration. You can find examples of typical configurations in the Nix community repository, and use one of these as the basis of your own configuration.
You can keep your configuration and re-use it for other installations, or for a system rebuild.
disko is flexible, in that it supports most of the common formatting and partitioning options, including:
Disk layouts: GPT, MBR, and mixed.
Partition tools: LVM, mdadm, LUKS, and more.
Filesystems: ext4, btrfs, ZFS, bcachefs, tmpfs, and others.
It can work with these in various configurations and orders, and supports recursive layouts.

I erase my systems at every boot.
Over time, a system collects state on its root partition. This state lives in assorted directories like /etc and /var, and represents every under-documented or out-of-order step in bringing up the services.
“Right, run myapp-init.”
These small, inconsequential “oh, oops” steps are the pieces that get lost and don’t appear in your runbooks.
“Just download ca-certificates to … to fix …”
Each of these quick fixes leaves you doomed to repeat history in three years when you’re finally doing that dreaded RHEL 7 to RHEL 8 upgrade.
“Oh, touch /etc/ipsec.secrets or the l2tp tunnel won’t work.”Setting up a new machine is time-consuming, and becomes complicated when it needs to be done remotely. If you're installing NixOS, the nixos-anywhere tool allows you to pre-configure the whole process including:
- Disk partitioning and formatting
- Configuring and installing NixOS
- Installing additional files and software
You can then initiate an unattended installation with a single CLI command. Since nixos-anywhere can access the new machine using SSH, it's ideal for remote installations.
Once you have initiated the command, there is no need to 'babysit' the installation. It all happens automatically.
You can use the stored configuration to repeat the same installation if you need to.
What it is, why we made it, and how it fits into the Nix ecosystem
Zero to Nix is a highly opinionated learning resource for Nix created by Determinate Systems. We believe Zero to Nix fills a major gap for two reasons:
- We find most of the existing Nix documentation to be difficult to navigate for beginners. Sources like the Nixpkgs manual, the official website, Nix Pills, and semi-official sources like nix.dev are all great once you have a strong sense of how Nix works and what it provides. We encourage you to explore them and we even link them in many places in Zero to Nix. But together they can be daunting to the uninitiated, and we wanted to provide a gentle "front end" to the official documentation sources.
- We strongly believe that flakes are the future of Nix and that people onboarding into Nix should use them from the get-go. But flakes are currently marked as an experimental feature of Nix and are thus not discussed in any of the official Nix documentation sources (with the exception of the Wiki entry for flakes).
This repository contains code to run Deuxfleurs' infrastructure on NixOS.
Our abstraction stack
We try to build a generic abstraction stack between our different resources (CPU, RAM, disk, etc.) and our services (Chat, Storage, etc.), we develop our own tools when needed.
Our first abstraction level is the NixOS level, which installs a bunch of standard components:
- Wireguard: provides encrypted communication between remote nodes
- Nomad: schedule containers and handle their lifecycle
- Consul: distributed key value store + lock + service discovery
- Docker: package, distribute and isolate applications
