Details

Declarative, Reproducible, Impermanent and Secure Infrastructure Deployment and Management with Nix/NixOS
ID Krumpestar, Miha (Author), ID Ciglarič, Mojca (Mentor) More about this mentor... This link opens in a new window, ID Pančur, Matjaž (Comentor)

.pdfPDF - Presentation file, Download (1,63 MB)
MD5: 7C80C4158E0CCC7C415D5A83D5883DD6

Abstract
Every mainstream operating system and configuration manager treats the filesystem as a mutable global namespace and deployment as a sequence of stateful transformations upon it. The resulting failure modes are treated as inevitable: non-atomic upgrades, component interference, nominal dependency resolution permitting substitution attacks, and configuration irreversibility. Each is structural, not a bug. A purely functional model, as realized in Nix and NixOS, eliminates all four by construction. Four qualities were evaluated: declarative composition, reproducibility, impermanence, and security. Each has been studied in isolation; their composition across heterogeneous infrastructure is tested for the first time. The first systematic survey of the NixOS deployment ecosystem revealed six structural gaps across eighteen tools. Panix, a stateless tool guided by three constraints (statelessness, observer principle, phase isolation), closes four of the six gaps and partially closes a fifth. Its seven-phase pipeline from bare-metal to activation tests whether Nix and NixOS composability extends to multi-flake fleet management. Six machines across four environments were configured from a single flake; a stateless kiosk with TPM-bound encryption and maximum impermanence exercises all four qualities at their extremes. The reproducible system closure extends supply chain integrity to the running system: where SLSA verifies artifact provenance, SBOM provides composition transparency, and in-toto verifies workflow integrity, the closure verifies the operating system from firmware to running services. A design-science evaluation over more than four months confirmed bit-for-bit reproducibility for all six hosts across two isolated Nix stores, Secure Boot on four hosts, and TPM-anchored identity on five. A fresh bare-metal installation completed without operator intervention in 392 seconds. The four qualities compose without compromise: 92\% of module code is shared across all hosts through one architecture with different option values. The mutable assumption is discarded, and the system works.

Language:English
Keywords:Nix, NixOS, Infrastructure as Code, declarative configuration, reproducibility, impermanence, immutable infrastructure, supply chain security
Work type:Master's thesis/paper
Organization:FRI - Faculty of Computer and Information Science
Year:2026
PID:20.500.12556/RUL-185108 This link opens in a new window
Publication date in RUL:23.07.2026
Views:162
Downloads:80
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Secondary language

Language:Slovenian
Title:Deklarativna, ponovljiva, neobstojna in varna postavitev ter upravljanje infrastrukture z Nix/NixOS
Abstract:
Vsak uveljavljeni operacijski sistem in upravljalnik konfiguracije temelji na predpostavki, da je datotečni sistem spremenljiv globalni imenski prostor, postavitev pa zaporedje stanjskih sprememb. Posledice takšnega modela so neatomske nadgradnje, medsebojni vplivi komponent, razreševanje odvisnosti zgolj po imenih, ki omogoča napade z zamenjavo, ter nepovratnost konfiguracije. Te težave niso posledica pomanjkljive implementacije, temveč same zasnove. Čisto funkcijski model, uresničen v sistemih Nix in NixOS, jih odpravlja že na ravni arhitekture. Ovrednotene so bile štiri lastnosti: deklarativna sestava, ponovljivost, neobstojnost in varnost. Čeprav je bila vsaka od njih raziskana samostojno, je njihova celovita uporaba na heterogeni infrastrukturi preizkušena prvič. Prvi sistematični pregled ekosistema postavitve NixOS je razkril šest strukturnih vrzeli med osemnajstimi orodji. Panix, brezstanjsko orodje, zasnovano na treh načelih (brezstanjskosti, načelu opazovalca in fazni izolaciji), odpravlja štiri od šestih vrzeli, peto pa delno. Njegov sedemfazni postopek od gole strojne opreme do aktivacije preverja, ali se sestavljivost Nixa in NixOS-a ohranja tudi pri upravljanju flote z večimi flake-i. Šest računalnikov v štirih okoljih je bilo konfiguriranih iz enega flake-a; brezstanjski kiosk s šifriranjem, vezanim na TPM, in največjo neobstojnostjo preizkuša vse štiri lastnosti do skrajnosti. Ponovljiva sistemska ovojnica razširja integriteto dobavne verige na delujoči sistem: kjer SLSA preverja izvor artefaktov, SBOM preglednost sestave, in-toto celovitost procesa gradnje, sistemska ovojnica pa preverja operacijski sistem od strojne programske opreme do delujočih storitev. Evalvacija po metodologiji oblikovalske znanosti, izvedena v obdobju več kot štirih mesecev, je potrdila ponovljivost na nivoju bitov za vseh šest gostiteljev v dveh medsebojno neodvisnih shrambah Nix, Secure Boot na štirih gostiteljih ter identiteto, zasidrano v TPM, na petih. Sveža namestitev na golo strojno opremo je bila brez posredovanja skrbnika zaključena v 392 sekundah. Štiri lastnosti se medsebojno dopolnjujejo brez kompromisa: 92\% izvorne kode modulov je deljenih med vsemi gostitelji prek ene arhitekture z različnimi vrednostmi nastavitev. Spremenljiva predpostavka je zavržena, in sistem deluje.

Keywords:Nix, NixOS, infrastruktura kot koda, deklarativna konfiguracija, ponovljivost, neobstojnost, nespremenljiva infrastruktura, varnost dobavne verige

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back