• hallettj@leminal.space
    link
    fedilink
    English
    arrow-up
    23
    ·
    8 days ago

    NixOS goes deeper than Ansible/Chef/Puppet. Those options use a declarative config, but they operate on a mutable system - in particular a system with a mutable package manager. They try to run the necessary operations to change the system state to match the config. But it’s not guaranteed that you get exactly the same state if you roll back and forth between declarative config revisions, especially since there are parts of system state outside the scope of the Ansible/Chef/Puppet config.

    OTOH the Nix package manager is immutable down through the package manager, and also through system config files (which are linked to the current config generation in the Nix store). If you use a lock file then the NixOS config describes the exact state of every package, and of every managed config file.