31 ms·
How I like to install NixOS (declaratively)
- ZYbCRq22HbJ2y7 1y agoTitle should be: "How I like to install NixOS (declaratively)"
- secure 1y agoYes. I also submitted my article myself (https://news.ycombinator.com/item?id=44148997 https://news.ycombinator.com/item?id=44148997), but the upvotes came in on this duplicate submission. I don’t know who todsacerdoti is, but looking at their submission history, it looks like this account automatically cross-posts from other sites (maybe lobsters?)
- throw259895 1y agoCorrect. https://news.ycombinator.com/item?id=43249197 https://news.ycombinator.com/item?id=43249197
- Y_Y 1y ago> I don’t know who todsacerdoti is, but looking at their submission history, it looks like this account automatically cross-posts from other sites (maybe lobsters?) That's a pretty serious allegation to make without evidence. Luckily I have some evidence right here: ~ $ python3 repost3.py todsacerdoti 78.0 seconds earlier - michael.stapelberg.ch - I like to install NixOS (declaratively) 92.0 seconds earlier - southcla.ws - Structured Errors in Go 149.0 seconds earlier - home.expurple.me - Why Use Structured Errors in Rust Applications? 101.0 seconds earlier - www.sitongpeng.com - WebSockets guarantee order – so why are my messages scram... 142.0 seconds earlier - volution.ro - PunchCard Key Backup 74.0 seconds earlier - www.youtube.com - Configure Your Git [video] 79.0 seconds earlier - download.vusec.net - Half Spectre, Full Exploit: Hardening Rowhammer Attacks w... 53567.0 seconds earlier - standardcompletions.org - Standard Completions 67.0 seconds earlier - bitfehler.srht.site - FOSS Tools for Infrastructure Testing 97.0 seconds earlier - ratfactor.com - Implementing a Forth ... I checked afterwards, most of those articles have different authors on Lobsters, so it doesn't seem to be one person just funding cool stuff and submitting to both. edit: some stats - 1 posts where HN is earlier within ten minutes 135 posts where HN is after within ten minutes Earliest instance within ten minutes: 2025-05-10T16:00:53Z Average time to repost: 140 seconds @dang - I know the anti-spam countermeasures are secret, and that there may be good reasons for cross-posting, but perhaps this might be a good thing to check for abuse of (even as a cronjob).
- prettymuchnoone 1y agoi don't think @-ing dang works, you should probably send an email to hn@ycombinator.com i think?
- Y_Y 1y agoI was hoping to just kiboz[0] him. For real though he does have a habit of showing up when mentioned even if there isn't an real @mention mechanism. [0] https://en.wikipedia.org/wiki/James_%22Kibo%22_Parry https://en.wikipedia.org/wiki/James_%22Kibo%22_Parry
- aspenmayer 1y agoWhat's the source for repost3.py?
- Y_Y 1y agoShamefully vibe-script-kiddied https://pastebin.com/baF6RKV4 https://pastebin.com/baF6RKV4
- aspenmayer 1y agoI can’t verify this in context without an invite to lobste.rs
- Tomte 1y agoNot visible to me. Probably because of the Guidelines: „Please don't use HN primarily for promotion. It's ok to post your own stuff part of the time, but the primary use of the site should be for curiosity.“
- aspenmayer 1y agoDo you have showdead enabled on your profile?
- dang 1y ago(We since merged the thread and re-upped your submission. We try to favor the author's own post if there is one, and otherwise the one that came first, but it's all pretty ad hoc and depends on what we happen to see.)
- aspenmayer 1y ago[flagged]
- bjackman 1y agoI have recently adopted Nix and NixOS and it's been truly fantastic. It does have a really harsh learning curve though. Big downsides, but for me the upsides are so huge that it's worth it. I had been incrementally building this complex workflow using mkosi. At some point I sat down with a pencil and asked myself "ok, what am I building here, what's the ideal endgame?" I sketched out the system I wanted and pondered it for a bit... And then went "wait, have I just described NixOS?" And yeah basically it's exactly what I wanted and more. Funnily enough, this article is _exactly_ what I need as I haven't exactly figured out the best way to install NixOS on a totally blank machine. (So far I have been muddling through what's described in the "Manual installation" section and, yeah it sucks). The exception is for Raspberry Pi where it's straightforward to just build an SD card image from a flake. I had _guessed_ that something like the "Building your own installer" section would work, but because of the nature of Nix I never really feel 100% confident that something is gonna work as I hope until I physically try it. Usually it does. But still, this is a very big downside of Nix!
- secure 1y agoGlad to hear that the article describes exactly what you need :) Try out building an installer and run it in a VM, it only takes a few minutes!
- 7bit 1y agoI dtarted my Linux journey 3 weeks ago with Arch and Ansible to create a declarative system. The installing-part however was tricky, because I have a second disk with Windows and I want to use secure boot. And if I wanted to use Ansible, I would have to create a specific ISO. And then I would have to manually define the disk I want to use or run into the risk of formatting the wrong one and lose a lot of data. Then I found NixOS, which is like Ansible, but better, because Ansible only adds information to a system, but NixOS also ensures that anything that is not declared is removed as well. After three weeks, I realized that the effort to declaratively (or automate an imperstively) install the OS is such a lot of work that does not pay off if you're not going to install multiple systems each week or month. How many commands does it take to actually install NixOS? You partition the disk which take 3 commands. Then you format it, which takes 3 commands. Then you mount the disks, which takes 3 commands. Then you install it, download your configuration and apply it, which is another 2-3 commands. It takes 5 minutes vs whatever effort you put into creating a declarative installer and keeping that up to date. I also had to think of the time it would cost me to actually figure out HOW a declarative installation would work and the tools I would require. I reckon that the first 24 system would essentially be free (opposed to the 2 hours or so it would cost me to figure out declarative OS installations). I decided that for me, it is not worth it, although I am the type of personality that just hates not automating things.
- hgl 1y agoNot to criticize the article, which is very well written, just some extra info: It seems for the author, the custom installer is mainly used for accepting user SSH public key, terminfo, and maybe also locale. Almost none of the packages the author listed get used, including zsh. Since NixOS is installed via nixos-anywhere, it runs a bash script to do everything, and all the script's dependencies will be pulled by nix. For people who don't want to build a custom installer, or their cloud environment doesn't allow one, you can simply host a script somewhere and download and run it on the remote machine to add your SSH public key and other customizations, including partitioning the disk. Note that the author used disko to partition the disk declaratively. Disko won't work for a machine with very limited ram, because disko runs in the installer, and needs to install tools to the ram to do the partition. I wrote a nix configuration library[1] that also does NixOS installation (uses nixes-anywhere under the hood), where you can choose between using disko, a default script[2] that handles 90% of the use cases (using only the default tools available on a vanilla NixOS installer, so nothing gets installed to the ram), or your own script. [1] https://github.com/hgl/nixverse https://github.com/hgl/nixverse [2] https://github.com/hgl/nixverse/blob/main/load/partitionScript.nix https://github.com/hgl/nixverse/blob/main/load/partitionScri...
- secure 1y ago> Almost none of the packages the author listed get used, including zsh Just to clarify: the point of having packages like lshw and zsh available is not for the case of performing the automated installation (where, yes, they are not used), but for the case where I want to interactively poke around in a booted installer to inspect the target system.
- hgl 1y agoThat's fair, having a remote shell environment that you feel comfortable to poke around is pretty great. For git, you commented "for checking out github.com/stapelberg/configfiles". I wonder if you sometimes install NixOS locally from the installer? If so, I can understand having those packages around can be very useful.
- 1y ago
- guerrilla 1y agoYou know, I don't see why Arch and other distros couldn't have a declarative abstraction layer. You don't hsve to go full Nix or GUIX just to hsve that.
- secure 1y agoSuSE Linux (around since the 90s) had such a single-layer-manages-everything approach, so yes, it’s not a new concept. I used to think that you don’t need Nix to get most of the benefits that Nix/NixOS are known for. And to a certain extent, that’s true — you can achieve much in other scenarios. But by now, I think the reason why Nix/NixOS work well and deliver these powerful abstractions is because they are Nix all the way down, giving you an unparalleled level of integration/reach for your declarative layer.
- abound 1y agoAs far as "declarative abstraction layers" go, I think the reason that distros don't have them is because they exist one level of abstraction higher in tools like Ansible or Chef.
- guerrilla 1y agoI think you're right.
- matrss 1y agoI can't speak about Chef, but Ansible is as far removed from declarative as is possible when compared to guix and nix.
- XorNot 1y agoAnd thank god for that. I'm very thoroughly over declarative management systems: the world isn't declarative, and all these systems are only as good as their implementation. Ansible at least doesn't lie to you about this: it provides the tools to be declarative, but doesn't pretend to understand your problems better then you.
- blue_pants 1y agoSlightly offtopic, does anyone know how to setup vscode dev containers with podman on NixOS? I tried vscode-fhs and some consulted wiki[0], but encountered some issues with gid ranges for commands like `sudo apt install ...` inside a container. Is there an guide for it? [0] https://wiki.nixos.org/wiki/Podman https://wiki.nixos.org/wiki/Podman
- chuckadams 1y agoWhile the Nix package manager still has a vertical learning curve, I found NixOS itself to be pretty idiotproof to install, with pretty much the same clicky installer experience as Ubuntu. I do remember a couple of things like `nix search` were broken out of the box -- in fact I don't think I ever got it working, I still just use the website to search for packages.
- secure 1y agoYeah, the clicky installer is pretty nice and smooth, but I mention in the article why the clicky installer is not good enough for me to install VMs — you cannot customize/pre-load it, and I want to minimize the manual steps.
- _kb 1y agoI've been using NixOS since 2018. I still use https://search.nixos.org https://search.nixos.org. It's a great interface for the same dataset. There's nothing wrong with that.
- dankobgd 1y agoI gave it a go twice and i just couldn't stick to using it. So many annoying little problems in general that i gave up. I configured system in the end but it was still annoying. I even had conflicts with some pkgs like Smile emoji picker and Gearlever, ok you can say: why do you need that? but lets say i do. And i got a conflict and couldn't install them together. I thought the whole point of nix is to have independent pkgs but i get in practice a conflict which now i have to figure out how to solve and there is no info online. There are many bugs and bad abstractions. I can use nix for local dev (devshells) though. With Ansible i get repeatable setup of my whole system. I can setup and install every program, configure it (dotfiles), setup services automatically and users and i have vault to easily encrypt secrets end embed them or template things out which is much nicer than using nix. I run a playbook and set everything up in 15 mins and the most "annoying" thing i have to do is basically log into few websites that i use daily.
- femiagbabiaka 1y agoInteresting, I’m not sure how you managed to get conflicts between packages, that’s a violation of the Nix model. If you describe the issue more I’d like to dig into it, even if you don’t use Nix any longer it’d be nice to fix the issue for those who do.
- dankobgd 1y agoI forgot exactly what it said in error msg, but it was some conflict with like Meson build file apparently already existed or something
- femiagbabiaka 1y agoInteresting, I’ll try to repro! For clarity, each “derivation” (lets say package) builds in its own hermetically sealed filesystem with its own dependencies. So conflicts in build system configuration shouldn’t be possible unless those packages are doing something impure (unlikely since the Nixpkgs CI tests for it) or the end user is doing something impure (still really hard to do).
- perrygeo 1y agoI've been trying to get a reasonable Linux-based audio setup on my desktop. Linux audio is a confusing disaster and I'd basically given up on Ubuntu, having run through so many debugging steps I had no idea how my system even got to this state. I figured what the hell, let's try NixOS and see if I can set it up declaratively. At least that way if it fails, I have documentation about what exactly is failing. I discovered the audio packages I needed easily enough. But things weren't great, there was occasional noticeable lag on the mic and midi devices. Ok, let's try to compile a realtime linux kernel... Wait there's an entire project dedicated to Nix audio setup! (https://github.com/musnix/musnix https://github.com/musnix/musnix) After a few minutes integrating with my config, and about an hour to compile the kernel. Rebooted and bam. It's almost like working with analog in terms of perceivable lag. I know this says more about Musnix than Nix, but I think it highlights the advantages of configuring your system with a real programming language. All the "audio stuff" was able to fit behind a well-designed abstraction barrier. Going back to a "do this, now do this" tutorial feels like the dark ages. The only thing keeping me from going all-in on Nix is that it's package management strategy starts bleeding into your software project's dependency management. This is a huge problem IMO, I can't run C/C++ or Python projects the "old way" and no one is willing to upend their build system and lock it into nix. Some languages work great and allow a clean barrier between system<>app. I use Clojure, Rust, Gleam, Go, Lua on nix without any issues, it does seem to be the C/C++ ecosystem and dynamic linked shared libraries that are the problem.
- riehwvfbk 1y agoIt's most likely not C/C++ per se, but rather the eleventy billion ways different projects build these libraries. Bazel for example builds everything in a well-contained sandbox and it all works, but only for the C/C++ libraries it builds natively. The magic ingredient is RPATH, but most Makefiles do not set it. However, one can add an extra build step with patchelf and inject an RPATH.
- grep_name 1y agoC/C++ is a PITA and I'm not a C/C++ developer, but I do find that I'm able to get around the issue 90% of the time using steam-run (although that feels kludgy as hell and I really wish there were a better option for getting linked libraries working normally). I think the real answer is to get good enough with nix to build a flake quickly for the project you're working with, but that seems like a lot to learn. Maybe easier if you're more familiar with C/C++ dependencies and build tools than me though. Musnix looks really interesting. My whole audio setup looks like this in my nixconfig: hardware.pulseaudio.enable = false; services.pipewire = { enable = true; alsa.enable = true; alsa.support32Bit = true; pulse.enable = true; jack.enable = true; }; hardware.bluetooth.enable = true; hardware.bluetooth.powerOnBoot = true; services.blueman.enable = true; This works great for my workflow of using headphones + BT 100% of the time, but weirdly it almost never works for the built-in speakers on my framework. I might try musnix if that ever bothers me, but it's actually kind of a feature for me since my laptop can never just start blaring whatever I was watching / listening to into public
- mrbluecoat 1y agoReminds me of a similar approach with ZFS: https://github.com/ascension-association/zbm-void-ts https://github.com/ascension-association/zbm-void-ts
- tracnar 1y agoI was always surprised that NixOS doesn't have a better story there, the main install instructions are to do manual partitioning, generate a config, edit it, etc. What I had expected at first would be that you'd write the config first and then deploy it, like in the article. But even with the method presented here you have the imperative step of running nixos-anywhere. Having something like the ignition system of Fedora CoreOS where you'd point at an existing config and it would install everything would make more sense IMO. Or pre build an iso which installs itself.
- edude03 1y agoI built something like this a few years ago. Essentially how it worked is you'd specify the path to a nix flake in the kernel parameters, and once the installer was booted it would pull that flake and run it (which ran the installer, formatted the disks and restarted the system). It was part of a larger project but I wonder how the nix team would feel about a small binary that would be included in the default installer image that does this
- s0l1dsnak3123 1y agoI'd love to see something like this. The lack of installer automation in the official installation docs was surprising to me when I first started.
- bqmjjx0kac 1y agoI just "lustrated" [0] my Debian Stable machine onto NixOS on Friday, and it's gone surprisingly well! It sounds silly, but I installed this way because I didn't want to figure out how to mount my LVM + LUKS encrypted partition on the live USB. What is lustrating? Basically, you run the NixOS installation tools on an existing Linux installation (install the tools with the Nix package manager). The installer wipes out anything on / that doesn't belong, with a few exceptions, including /home and anything listed in /etc/NIXOS_LUSTRATE, a file you create as part of the installation steps. [0]: https://nixos.org/manual/nixos/stable/#sec-installing-from-other-distro https://nixos.org/manual/nixos/stable/#sec-installing-from-o...
- gigatexal 1y agoI want to like NixOS I just hate the language — idk maybe I’m in the minority. Give me a functional language like F# or some better DSL that builds a DAG and then you’re golden.
- vincentkriek 1y agoThe language and the compiler infrastructure is for me the biggest problem. It's very hard to understand what is going wrong when it goes wrong. Most advice feel like copy pasting existing code without knowing what it does. Learning this also complicates things as I am feeling overwhelmed with all the things needed for simple configuration structures instead of starting out with a simple program.
- woile 1y agoit's the biggest painpoint. I got used to it, but still don't like it that much. I think there are some efforts to build some kind of VM so, in theory, you could put any language on top. https://snix.dev/ https://snix.dev/
- vendiddy 1y agoI think a lot of people including myself feel this way. I really like the Nix model of derivations and approach to deterministic builds. It's the language IMO that prevents it from getting mainstream adoption. I think they would be best served by picking a subset of an FP language that already has good ergonomics and tooling.
- dogmatism 1y agoHave you looked at Guix?
- gigatexal 1y agoYes I have. And it looks sane. The language is a kind of lisp? Scheme? It’s what I’d use if I went this route.
- nothrabannosir 1y agoThe language is bad but the module system is even worse. It’s another language implemented in the nix language. Zero hopes of an LSP or any kind of editor assistance. God have mercy on your soul if the docs for your piece of work are lacking. Not a controversial opinion even in the nix community as far as I know.
- rustcleaner 1y agoAnyone know if Nix solved their politics problem yet? I see a resultant fork exists in auxolotl.
- nylonstrung 1y agoAux never went anywhere and is dead The other politically inspired fork (Lix) is moving very slowly for a project that seeks to replace nixpkgs outright 99% of the actual development in the ecosystem is proceeding like normal
- rustcleaner 1y agoSadness.
- sohrob 1y agoEvery time I try to use NixOS I start off excited about all the benefits it can provide, but it always ends up frustrating me in some way and I'm reminded of why distributions exist in the first place. I don't want to have to dig into a config file for every little aspect of my OS to be in working order and then worry about having some hackey workaround when something has issues due to the lack of adherence to the FHS.
- lolinder 1y ago> I don't want to have to dig into a config file for every little aspect of my OS to be in working order When I see comments like this about NixOS I feel like I must have been using a different breed of distro before and switched to a different NixOS than you did. My experience has been that other distros—even the supposedly stable ones like Debian—are disasters waiting to happen with no clear way of understanding what goes wrong when you do an upgrade and it breaks. Instead of one config file to troubleshoot I have hundreds of config files that I don't even know about that might be at fault. Or it could be not even a config file, it could be that there's a version mismatch that can't be resolved. For me NixOS's config file is a breath of fresh air. If something on my system breaks it's because I made a change to that single config file. If something on my system isn't working yet it's fixable in that single config file. The system is far from perfect, but it's much better than the black magic that other distros lean on.
- breakds 1y agoI think having to debug to find problem of your system is frustrating. But with NixOS, I at least won't be afraid of "breaking the system" or doing something "irreversible". This is totally a peace of mind when tinkering with my setup.
- a_t48 1y agoFor Ubuntu it’s possible to use debootstrap to install to an external drive directly. Once you’ve done that, you can chroot into the new drive, fix up a few things that aren’t handled (mounts, locale), then install any software you want on top. Even stuff like installing new kernel/drivers works. Running docker in the chroot also works, if you copy the setup used in docker-in-docker. I wonder if a similar setup is usable here. Side note wrt tailscale - you should be able to auth without manual registration. Two choices: 1. Make a reusable key that grants the ACL you want to give, store it somewhere secure on your provisioner, then “ssh user@tag sudo tailscale up —-auth-key=$key” to deploy. 2. Make a new tag for “disabled-machine” or similar, locked down with no access. Embed that key in your ISO and use whatever mechanism you have to start it up on boot. Either way you no longer have to copy paste the setup link to your browser, and the machine always starts off with the ACL tags you want (setting an ACL tag automatically disables expiration btw - no need to do both). 2 is likely tricky to do securely, so take care. :)
- mighmi 1y agoGUIX is a pleasure
- djrj477dhsnv 1y agoThe Guix documentation is such a breath of fresh air after struggling with NixOS.
- fdoifdois 1y ago[flagged]
- Mic92 1y agoOne of the nixos-anywhere maintainer here. I am currently debugging the digitalocean cloud-init for the nixos-anywhere-examples repository. Has someone contact to digitalocean regarding that? There is a shebang that could be easily fixed to run on NixOS (/var/lib/cloud/scripts/per-instance/machine_id.sh).
- mauflows 1y agoHere's my own repo with a very similar setup! https://github.com/mjmaurer/infra https://github.com/mjmaurer/infra I build the ISO via a Github action as well. The biggest pain point is adding / removing disks after initial install, which I do imperatively (but still disko for mounting / fstab equivalent)