Its use of the Nix package manager means that each package is installed in its own directory with immutable and signed contents. That alone means that the setup is incredibly easy to reproduce across multiple machines, something that is an obvious benefit when dealing with different facets of a government.
Id argue an immutable distro would likely serve the same purpose but maybe its also because nixos isnt as “locked down” so itd be easier to configure for a specific purpose?
The big draw is probably that it’s declarative, so you can define installations as code much the same way as you would do with Terraform. Instead of needing a pile of messy Ansible playbooks running custom scripts to change anything (and which can break if the target machine has an unexpected config), you’d just have one that pushes a new version of the config and runs nixos-rebuild. Rollbacks are just as easy if anything breaks. What’s not to like?
I am curious, what makes NixOS such a good choice?
From the article:
Id argue an immutable distro would likely serve the same purpose but maybe its also because nixos isnt as “locked down” so itd be easier to configure for a specific purpose?
The big draw is probably that it’s declarative, so you can define installations as code much the same way as you would do with Terraform. Instead of needing a pile of messy Ansible playbooks running custom scripts to change anything (and which can break if the target machine has an unexpected config), you’d just have one that pushes a new version of the config and runs nixos-rebuild. Rollbacks are just as easy if anything breaks. What’s not to like?
nix is on a whole different level than silverblue and other ‘atomic’ distributions.
But not curious enough to read the article.
You know, you could simply be helpful.
Sure.
It’s in the fourth paragraph, starting with
and ending with