Get in Touch

Course Outline

Declarative System Governance and Sovereignty

  • Analyze the operational risks associated with imperative configuration management, specifically configuration drift and audit non-compliance.
  • Examine the Nix store architecture, derivation mechanisms, and the application of pure functions in system construction.
  • Contrast NixOS methodologies with traditional distributions, emphasizing system immutability and the integrity of atomic upgrades.

Deployment Foundations and Core Operations

  • Execute the installation of NixOS from ISO media, covering both manual and automated partitioning strategies.
  • Review the syntactic and semantic components of the Nix language, including sets, functions, and import mechanisms.
  • Interpret the structure of the configuration.nix file and the functional logic of the module system.
  • Utilize command-line tools such as nix search and system documentation to identify and verify package options.

Declarative Package and Service Administration

  • Implement system-wide and user-specific package management strategies using the nix-env interface.
  • Configure and enable systemd services through declarative definitions to ensure consistent service states.
  • Apply custom package overrides and overlays to tailor system components for specific operational requirements.
  • Optimize the Nix store through systematic garbage collection and space management practices.

Establishing Reproducible Operational Environments

  • Develop ad-hoc development contexts using nix-shell and shell.nix specifications.
  • Leverage Nix Flakes to enforce lockfile-based reproducibility across distributed projects.
  • Utilize devenv and devshell frameworks to streamline onboarding processes for technical teams.
  • Integrate Direnv to facilitate automatic and context-aware environment switching.

Fleet Management and Remote Deployment

  • Manage heterogeneous server fleets using NixOps and Colmena orchestration tools.
  • Configure remote building capabilities and binary cache synchronization for efficient distribution.
  • Implement robust secrets management protocols utilizing agenix and sops-nix for secure deployment for government applications.
  • Validate deployment configurations using NixOS virtual machines and containerized testing environments.

System Integrity, Updates, and Recovery

  • Execute system state changes using nixos-rebuild modes including switch, test, and boot.
  • Perform atomic rollbacks to prior system generations to ensure operational continuity.
  • Manage Nix channels and version pinning to guarantee reproducible update cycles.
  • Configure emergency recovery procedures and bootloader settings to maintain system availability.

Advanced Implementation and Continuous Integration

  • Deploy NixOS containers and lightweight virtualization instances for isolated workloads.
  • Implement cross-compilation workflows and ARM architecture builds for diverse hardware platforms.
  • Generate custom ISO and netboot images to support specific deployment and recovery scenarios for government infrastructure.
  • Integrate Hydra continuous integration pipelines to automate testing and distribution of Nix packages.

Requirements

  • Advanced proficiency in Linux system administration and shell scripting.
  • A foundational understanding of functional programming paradigms.
  • Experience with Git and version-controlled configuration management workflows.

Target Audience

  • Infrastructure engineers requiring reproducible and declarative system architectures.
  • DevOps teams aiming to transition from Ansible, Puppet, or Chef to Nix-based management.
  • Organizations with mandates for bit-for-bit reproducible deployments, including government entities.
 21 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories