5 ms·
I can haz smoller NixOS ISOs?
- lordkrandel 4mo agoHey, thanks, nice adventure! I will have a look. I'm trying to ditch Arch for NixOS and I'm starting from Distrobox probably. Super useful!
- HardwareLust 4mo agoWhy ditch Arch?
- lordkrandel 4mo agoMainly because I favor NixOS's idea of control over the system, and because Arch is getting too popular (steamos, omarchy), making it a target. The recent AUR plague is actually a symptom, to me.
- HardwareLust 4mo agoPretty good reasoning, thanks!
- craftkiller 4mo agoThat's how I manage all of my virtual machines: building an ISO from a NixOS config and booting it as a virtual machine. I'm going to take some time to see what bits of this I can copy to slim down my ISOs. One additional benefit: I build all my software from source (by disabling the nix cache) so stripping out these extra programs will not only slim down my ISOs but it will also reduce the build time.
- khuedoan 4mo agoCurious bout your use case for building all software from source, is it because you're worried about the supply chain since nixpkgs builds don't have reproducibility guarantee?
- craftkiller 4mo agoI was already building the vast majority of it from source because I enable CPU optimizations for the specific microarchitecture in the machine (nixpkgs.hostPlatform.gcc.arch and nixpkgs.hostPlatform.gcc.tune), so once I learned about the risk of supply chain attack on the nix cache, disabling it entirely was a pretty small change. So far, I'd say the biggest negative (aside from the build times that I was already experiencing due to the optimizations) is that GNU savannah will temporarily IP ban you when you download too much from them. For example, building the grub that is used for the ISOs downloads like 70+ patches from GNU Savannah which frequently triggers the IP ban.
- BobbyTables2 4mo agoI assume you like it more than Gentoo? Building from stage1 with customized CFLAGS was all the rage then…
- chickensong 4mo ago> the risk of supply chain attack on the nix cache Do you not trust hydra, the infra hosts, the people, all of it? What could be done to improve the cache's posture?
- craftkiller 4mo agoOne suggestion for improving the cache's posture: Give each dedicated builder machine a TPM. On each builder, generate a TPM-backed signing key. Only use those TPM-backed keys for signing packages that end up in the cache. That way we'd ensure that signed packages _must_ have been built on the dedicated build machines (due to the TPM) rather than potentially uploaded from a compromised developer machine using a compromised signing key. It seems the current situation is there is a single signing key that has been in use since 2015 which implies that key is not tied to specific hardware and therefore could be leaked/exfiltrated/copied: https://github.com/NixOS/rfcs/pull/149/files#diff-ac4cc42774897d03700afa5e998e676b494ee685860d9ee08dfa2b14d7566273R22 https://github.com/NixOS/rfcs/pull/149/files#diff-ac4cc42774...
- funcDropShadow 4mo agoYou could manage those VMs with https://microvm-nix.github.io/microvm.nix/ https://microvm-nix.github.io/microvm.nix/ that helps with mounting the nix store read only from the host into the vm. That should save more space than trying to reduce the dependencies of the system closure of the vm.
- lordkrandel 4mo ago[dupe]
- nylonstrung 4mo agohttps://sidhion.com/blog/nixos_server_issues/ https://sidhion.com/blog/nixos_server_issues/ Here's another good article on the topic It's unfortunate that Perl and Python are core deps, as well as Bash
- nh2 4mo agoNote that's somewhat out of date: > `bin/switch-to-configuration` is a Perl script from the beginning Since NixOS 24.11 the default is `switch-to-configuration-ng`, in Rust. That is a 2.8 MB binary, compared to NixOS's 55 MB Perl distribution. Thus such Perl-less systems shrunk that dependency by 20x regarding activation switching. And since NixOS 25.11, `nixos-rebuild-ng` in Python replaces its former Perl counterpart, see https://wiki.nixos.org/wiki/Nixos-rebuild https://wiki.nixos.org/wiki/Nixos-rebuild
- krautsauer 4mo agoLess than they used to be: https://github.com/NixOS/nixpkgs/issues/267982 https://github.com/NixOS/nixpkgs/issues/267982 https://github.com/NixOS/nixpkgs/issues/428908 https://github.com/NixOS/nixpkgs/issues/428908
- tfrancisl 4mo agoThere is a project by a group of nix/nixos enthusiasts aiming to replace some of these core deps https://github.com/manic-systems/nixos-core https://github.com/manic-systems/nixos-core. I havent tire-kicked it much, but it seems useful.
- arikrahman 4mo agoWhat's most amazing is how easy it is to switch kernels on NixOS as this article touched on. This prompted me to switch to Cachy kernels, and after some caching delay (apparently need to switch once before caches set) I was able to take advantage of a completely different OS's core strength. Truly the one OS to rule them all.
- bilkow 4mo agoSorry, I am a bit confused about the caching delay, which seems to suggest you can switch kernels without rebooting? That's not what the wiki suggests[0], and what even happens to running programs? Or do you mean just changing the "default" boot to a different kernel, which in other distros would require changing the boot loader config? [0] https://nixos.wiki/wiki/Linux_kernel https://nixos.wiki/wiki/Linux_kernel
- traverseda 4mo agoIf memory serves the cachyos-nix flakes sets a cache for pre-built kernels, but that cache isn't available until you rebuild. So if you want to use the cache you need to do two steps, add cachyos to your inputs, rebuild, switch the kernel, rebuild. Then reboot to use the new kernel.
- arikrahman 4mo agoCorrect, I should've worded that better for more clarity.
- cwel 4mo agoThe article does not mention switching kernels. It comments on the size of the kernel + modules; and trimming down unused modules. Of all the things to get nixpilled over, this isn't one.
- xyzzy_plugh 4mo ago> we should be able to disable shipping Nix entirely, by setting nix.enable = false. It was at this point I began to question the entire exercise. If you don't want nix to even be installed, do you really want NixOS at all? It would probably be much simpler to just build an image from scratch with the packages you want, composed in the way you want them, rather than contort the NixOS "UX" to produce the image you want.
- KingMachiavelli 4mo ago> build an image from scratch with the packages you want Using what? Using NixOS to configure a system is orthogonal to the system actually running the Nix binary. Nix/Nixpkgs provide well maintained package derivations and module configuration for the largest amount of software of any ecosystem. IMO it's far simpler than Yocto or Buildroot or the dozen OCI container builder ecosystems that go in and out of favor.
- xyzzy_plugh 4mo agoUsing Nix of course. My point is that if you care deeply about what is being installed in the image, size, dependencies, bloat, etc. then perhaps using the NixOS abstraction is the wrong approach. Instead of building "down" by taking things away, build "up"
- bow_ 4mo ago> My point is that if you care deeply about what is being installed in the image, size, dependencies, bloat, etc. then perhaps using the NixOS abstraction is the wrong approach. Instead of building "down" by taking things away, build "up" Those aren't necessarily oppposing points. NixOS is a declarative distro. It also happens to come with some defaults that, I assume, caters to the commonly expected use case (and maybe has some historical roots as well). NixOS is not a minimal, build-from-scratch distro. It's more opinionated than e.g. Arch. For example, it ships with firewall turned on by default (https://nixos.wiki/wiki/Firewall https://nixos.wiki/wiki/Firewall). Another example: the default list of packages is somehow Perl, rsync, and strace (https://search.nixos.org/options?channel=26.05&query=defaultPackages#show=option%253Aenvironment.defaultPackages https://search.nixos.org/options?channel=26.05&query=default...). Blanking this default to an empty list is IME harmless. The declarative nature is probably the subtext the author is trying to convey: what are the things one can do to disable these defaults, to reach a very minimal system (ISO really) that one can then build as one wishes.
- overtone1000 4mo agoIt's always fun to see an interrobang in the wild.
- siraben 4mo agoI got a bootable NixOS iso down to 91 MB. Pointed Claude at the Nixpkgs repo and asked it to strip things aggressively and inspect the build closure iteratively. But the resulting ISO: - has no network - can't switch configurations - doesn't have a text editor https://gist.github.com/siraben/a8fce9912891d85e1ec3cf74081ba4f6 https://gist.github.com/siraben/a8fce9912891d85e1ec3cf74081b...
- Chu4eeno 4mo agoI miss tomsrtbt and all the other single floppy distros, it was surprisingly complete for 1.44MB (including networking, with more protocols than the average browser, and text editors): https://web.archive.org/web/19990506100919/http://www.toms.net/rb/tomsrtbt.FAQ https://web.archive.org/web/19990506100919/http://www.toms.n... (mulinux iirc boasted about having 100 commands or something like that)
- whazor 4mo agoI wonder if it makes sense to create distroless containers like this.
- poelzi 4mo agoi'm doing this using nix2container and a rust program that generates a landlock filter so i can mount nix store and only the supplied derivates are visible :) coming to you in a few month, tix.im tbh, this is the most powerful computer program I have ever seen. Working on this now for over 6 month, ~600k LOC. I think it will grow to 800k in the base package. Unfortunately, uncompromised security requires quite some LOC. This works: tix workflow submit ../vx-maintainer/workflows/change-management/default.nix --follow -- --feature-branch="feat/2lines" --instructions="tui overview should show running flows in 2 lines. 2 line: running steps, done, failed, etc. reports counter: info/success/failed/warning/error sparkle line with load ... . then if extended by double click, each running step has a line. what step, memory, cpu usage, token counters, ... subgraphs should be rendered under the parent flow. Title should always show that subgraph. details has link to parent " --source-repo=/home/poelzi/Projects/tix/tixim --implementor=opencode\#gpt-5.5 I get a human gate after the plan is finished where I can give feedback (in this workflow). And then another gate when everything is done. 4 different models, multiple harnesses, multiple reviews, rest cases etc. :) It makes me so smile watching the workflow progress. And the shit becomes global in a few days...
- deleted 4mo ago[deleted]
- ChrisRR 4mo ago"Can haz smol" Why are we talking in fake childish speak?
- fragmede 4mo agoFewer tokens. Costs more to use full sentences. smol word less token cnt
- apt-get 4mo agoConsidering "I Can Has Cheezburger" and that kind of lolspeak is nearly 20 years old now, I'm not surprised to see some people unfamiliar with it nowadays :-)
- ChrisRR 4mo agoI'm very familiar with it, I'm almost 40. But as you say, its time passed almost 2 decades ago and now it's just cringeworthy baby talk