3 ms·
We run a fleet. Happy to answer questions here or shoot us a mail at team@wearewizards.io if it's sensitive.
by teh 10y ago
We run a fleet. Happy to answer questions here or shoot us a mail at team@wearewizards.io if it's sensitive.
- tikhonj 10y agoDo you have a blog post about it or something? I don't have specific questions, I'd just love to see how Nix looks in production.
- teh 10y agoNo high level overview, just a fairly specific (and sadly slightly out of date) one here: https://blog.wearewizards.io/how-to-use-nixops-in-a-team https://blog.wearewizards.io/how-to-use-nixops-in-a-team It's still Linux but a lot of common problems go away. E.g. if you remove a user from your config then it's removed on the server (as opposed to Ansible). Or: Because you have a dependency DAG all services that need restarting after a change are known (no more Chef notifies :restart). Or: No more apt-get dist-upgrade. You can have a single package depend on an entirely new version of your OS and keep the old OS in place (except for the kernel version of course).
- viraptor 10y agoHow's the binary security on NixOS these days? The official information I find are... worrying. Specifically: a) security updates are the same as all the other updates and may take days to get to you, do runtime replacements manually yourself (https://nixos.org/wiki/Security_Updates https://nixos.org/wiki/Security_Updates) and b) next to no hardening during compilation (https://nixos.org/wiki/Hardened_NixOS https://nixos.org/wiki/Hardened_NixOS)
- frio 10y agoGood news! Hardened NixOS isn't far: https://github.com/NixOS/nixpkgs/pull/12895 https://github.com/NixOS/nixpkgs/pull/12895 :). I've been watching/waiting for that for a while myself, and the progress on that ticket has been encouraging enough that I've started building out NixOS stuff in anticipation of it landing by 16.09. Now I'm somewhat slavering for it because I've come to like NixOS a lot more than I thought I would...
- teh 10y agoBoth good points. In practice a) hasn't been an issue but for b) we had to apply a fair amount of patches ourselves. Luckily b is almost fixed, and if combined with e.g. grsecurity I think nix has a good story.