<?xml version="1.0"?>
<metadata xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dc="http://purl.org/dc/elements/1.1/"><dc:title>Declarative, Reproducible, Impermanent and Secure Infrastructure Deployment and Management with Nix/NixOS</dc:title><dc:creator>Krumpestar,	Miha	(Avtor)
	</dc:creator><dc:creator>Ciglarič,	Mojca	(Mentor)
	</dc:creator><dc:creator>Pančur,	Matjaž	(Komentor)
	</dc:creator><dc:subject>Nix</dc:subject><dc:subject>NixOS</dc:subject><dc:subject>Infrastructure as Code</dc:subject><dc:subject>declarative configuration</dc:subject><dc:subject>reproducibility</dc:subject><dc:subject>impermanence</dc:subject><dc:subject>immutable infrastructure</dc:subject><dc:subject>supply chain security</dc:subject><dc:description>Every mainstream operating system and configuration manager treats the filesystem as a mutable global namespace and deployment as a sequence of stateful transformations upon it. The resulting failure modes are treated as inevitable: non-atomic upgrades, component interference, nominal dependency resolution permitting substitution attacks, and configuration irreversibility. Each is structural, not a bug. A purely functional model, as realized in Nix and NixOS, eliminates all four by construction. Four qualities were evaluated: declarative composition, reproducibility, impermanence, and security. Each has been studied in isolation; their composition across heterogeneous infrastructure is tested for the first time. The first systematic survey of the NixOS deployment ecosystem revealed six structural gaps across eighteen tools. Panix, a stateless tool guided by three constraints (statelessness, observer principle, phase isolation), closes four of the six gaps and partially closes a fifth. Its seven-phase pipeline from bare-metal to activation tests whether Nix and NixOS composability extends to multi-flake fleet management. Six machines across four environments were configured from a single flake; a stateless kiosk with TPM-bound encryption and maximum impermanence exercises all four qualities at their extremes. The reproducible system closure extends supply chain integrity to the running system: where SLSA verifies artifact provenance, SBOM provides composition transparency, and in-toto verifies workflow integrity, the closure verifies the operating system from firmware to running services. A design-science evaluation over more than four months confirmed bit-for-bit reproducibility for all six hosts across two isolated Nix stores, Secure Boot on four hosts, and TPM-anchored identity on five. A fresh bare-metal installation completed without operator intervention in 392 seconds. The four qualities compose without compromise: 92\% of module code is shared across all hosts through one architecture with different option values. The mutable assumption is discarded, and the system works.</dc:description><dc:date>2026</dc:date><dc:date>2026-07-23 10:00:05</dc:date><dc:type>Magistrsko delo/naloga</dc:type><dc:identifier>185108</dc:identifier><dc:identifier>VisID: 38481</dc:identifier><dc:language>sl</dc:language></metadata>
