Sign in

Graham Christensen

@grahamc.com
1.7K followers 399 following 665 posts

determinate.systems. Nix obsessed. he/him 📻 no5ig

PostsRepliesMedia
Graham Christensen @grahamc.com · 21/12/2025
Hmm.. it's built with nixos-unstable, and we just published one yesterday. Is it stale?
100
Graham Christensen @grahamc.com · 08/10/2025
Interesting. Nix carefully tracks runtime and build time dependencies, so this seems surprising to me.
200
Reposted by Graham Christensen
Determinate Systems @determinate.systems · 18/07/2025
Build for Linux from your Mac. It just works, with Determinate #Nix. Zero config.
1111
Graham Christensen @grahamc.com · 18/07/2025
Hell yea
020
Graham Christensen @grahamc.com · 18/07/2025
@dangoodin.bsky.social re your DNS article ... for a good time: dig +noall +short disk.vhd.gz.base64.grahamc.com TXT | cut -d'"' -f2 | base64 -d | gzip -d > minimal.vhd
010
Graham Christensen @grahamc.com · 09/07/2025
Got a link?
100
Graham Christensen @grahamc.com · 16/05/2025
ah! I need some custom stickers made in bulk on short order
120
Graham Christensen @grahamc.com · 16/05/2025
Where do people get good stickers from? In the distant past I've used StickerMule.
200
Graham Christensen @grahamc.com · 13/05/2025
Hey y’all, I could use help: if you’re using the determinate nix installer in GitHub actions and you’re seeing an increase in CI failures — let me know? We’re slowly rolling out a new version and suspect there is an edge case we haven’t covered.
000
Graham Christensen @grahamc.com · 07/05/2025
So this merged: github.com/DeterminateS... (not yet released, see the linked comment)
github.com
Lazy trees v2 by edolstra · Pull Request #27 · DeterminateSystems/nix-src
Motivation Less invasive variant of NixOS#6530. We now mount lazy accessors on top of /nix/store without materializing them, and only materialize them to the real store if needed (e.g. in the deriv...
160
Graham Christensen @grahamc.com · 02/05/2025
I love the sentiment of this style of message (which I’ve seen you do a bunch of times.) I’ve always wondered what it means though. Is there like, a procedure/coordination? I’d love to see behind the curtain!
220
Graham Christensen @grahamc.com · 02/05/2025
Oh my god that is beautiful.
000
Graham Christensen @grahamc.com · 29/04/2025
Upgrade to Determinate Nix 3.4, by ... I mean, that picture :) but for posterity: determinate-nixd login sudo determinate-nixd upgrade Or install it for the first time from docs.determinate.systems (we recommend the package on macOS!)
docs.determinate.systems
Determinate documentation
An end-to-end toolchain for using Nix courtesy of Determinate Systems
000
Graham Christensen @grahamc.com · 29/04/2025
Anyway, Determinate Nix 3.4.1 is now out. It warns if you're using channels, and implicit, or indirect (registry) flake references in flake.nix files. Determinate Nixd had some nits picked, like over-eager error logging. And of course, the `upgrade` command is more instructive.
100
Graham Christensen @grahamc.com · 29/04/2025
This represents our values in a lot of ways: Be honest & transparent: We know this isn't great, here's the bug. Don't make things worse: Here's how to move forward. It should feel good to use: It has system specific instructions depending if you're on macOS, NixOS, and Linux.
100
Graham Christensen @grahamc.com · 29/04/2025
In the meantime, Determinate Nix 3.4.1 helps you upgrade more successfully. Where it used to crash out on a ridiculous error, now it _tells you_ that you have to log in.
110
Graham Christensen @grahamc.com · 29/04/2025
that means you have to log in to FlakeHub to download prebuilt upgrades. This is not some brain genius number-go-up-maxxing, but an annoying side effect of Product Design Decisions. I wrote up a tracking ticket for folks while we solve that: github.com/DeterminateS...
github.com
Tracking: Upgrading Determinate Nix soft-requires credentials. · Issue #45 · DeterminateSystems/nix-src
Because FlakeHub Cache does not offer any public caches, upgrading Determinate Nix requires being logged in to FlakeHub to download Determinate Nix. This is ... not ideal, to say the least. Further...
100
Graham Christensen @grahamc.com · 29/04/2025
An awkward UX issue of Determinate Nix is that we serve it from FlakeHub Cache, which has no unauthenticated access. We do that to make the auth backend very straightforward, avoiding complexity that could lead to leaking customer cache entries. But...
140
Graham Christensen @grahamc.com · 26/04/2025
💪
000
Graham Christensen @grahamc.com · 26/04/2025
That is THE use case, yeah! I agree. That’s exactly why we’re doing this 💪
020
Graham Christensen @grahamc.com · 26/04/2025
It is a VERY bizarre feature, and I’m glad to be deprecating it 😅
020
Graham Christensen @grahamc.com · 26/04/2025
These two strategic changes are aimed at eliminating confusion and surprise, and are based on working with our users and hearing their feedback. I can't wait for Determinate Nix 3.4 to ship on Monday!
010
Graham Christensen @grahamc.com · 26/04/2025
The two issues compound with `nixpkgs` (indirect flakeref) and `<nixpkgs>` (nix path/channel "diamond" reference.) They look similar, but mean entirely different things. It gets worse when root's channels are configured differently from a user's. Even worse still on macOS.
110
Graham Christensen @grahamc.com · 26/04/2025
Similarly, we frequently see confusion when locking a flake which uses implicit inputs and indirect flakerefs. Indirect flakerefs are great on the CLI. Determinate Nix will start warning when you use them as a flake.nix input url, where they're a negative: github.com/DeterminateS...
github.com
Intent to ship: deprecating usage of flake registry entries in `flake.nix` inputs · Issue #37 · DeterminateSystems/nix-src
This is an entry of our roadmap for Determinate Nix, which is guided by user and customer feedback. Over the next months, we will progressively deprecate usage of shorthand flake registry entries a...
210
Graham Christensen @grahamc.com · 26/04/2025
We've seen countless users trip themselves up on outdated channels and confusing them for the `nixpkgs` flake ref used by `nix run nixpkgs#`, etc. Determinate Nix Installer hasn't shipped configured channels for years, and now we're warning against them: github.com/DeterminateS...
github.com
Intent to ship: deprecation of channels · Issue #34 · DeterminateSystems/nix-src
This is an entry of our roadmap for Determinate Nix, which is guided by user and customer feedback. Over the next months, we will progressively deprecate channels and the nix-channel command. This ...
130
Graham Christensen @grahamc.com · 26/04/2025
The next release of Determinate Nix will start addressing two issues that commonly confuse our users: 1. `nix-channel` is deprecated, and using it will issue a warning. 2. Using an indirect flakeref or implicit registry input in a flake.nix will also raise a warning. >>>
2112
Reposted by Graham Christensen
Determinate Systems @determinate.systems · 16/04/2025
Determinate Nix 3.3.1 is now out and folks, it is not playing games. We've added JSON logging to Nix and a whole new UX around fixing hash mismatches during Nix builds—and we've fixed some long-standing paper cuts to boot. determinate.systems/posts/change...
determinate.systems
Changelog: JSON logging, a new experience around hash mismatches, and more
JSON logging has the potential to unlock all kinds of ergonomic benefits, starting with hash mismatches but with plenty of room to expand beyond that
052
Reposted by Graham Christensen
Determinate Systems @determinate.systems · 02/04/2025
Determinate #Nix 3.2: we fixed the infamous `git add` error. Really.
191
Graham Christensen @grahamc.com · 01/04/2025
051
Graham Christensen @grahamc.com · 29/03/2025
Hm? No, the daemon tracked the error and the GitHub action wrote the annotation using the error from the daemon.
010
Graham Christensen @grahamc.com · 29/03/2025
You can try it now: github.com/DeterminateS...
github.com
Annotate hash mismatches when Determinate features are enabled by gustavderdrache · Pull Request #158 · DeterminateSystems/nix-installer-action
Description When Determinate features are enabled, this PR adds GitHub Actions annotations to point users directly to hash mismatches in their source files. Example: - uses: DeterminateSystem...
010
Graham Christensen @grahamc.com · 28/03/2025
Is this anything?
260
Reposted by Graham Christensen
Determinate Systems @determinate.systems · 17/03/2025
Let’s be real: any GitHub Action could expose your secrets at any time. Just look at the latest CVE uncovered in the popular tj-actions/changed-files Action. Static, long-lived secrets are a major 🚩. The solution? Don't rely on them, there is a better way. 🧵👇
132
Graham Christensen @grahamc.com · 17/03/2025
@arrdem.com nice to find you again =)
110
Graham Christensen @grahamc.com · 12/03/2025
@hankgreen.bsky.social my daughter is named Io, and ++ on your video about paying more attention to Jupiter's moons.
000
Graham Christensen @grahamc.com · 01/03/2025
can we please just get a move on, and (1) make Ed25519 FIPS-140, and (2) get Ed25519 in HSMs and AWS KMS?
270
Graham Christensen @grahamc.com · 27/02/2025
Autonomous Sensory Materials Lithography
000
Graham Christensen @grahamc.com · 27/02/2025
It looks like you misspelled Oils.pub
130
Graham Christensen @grahamc.com · 27/02/2025
This Firefox ToS hubbub is wild. It is amazing they didn't have one before. Lawyers like to spell out things like "If you type things into our program, we will do things with it." Which is the fundamental operating principle of a browser! You type things into it, and things happen!
040
Graham Christensen @grahamc.com · 26/02/2025
How is it that most glasses companies take 7-10 days, when there are plenty of companies that will get them to you next day?
000
Reposted by Graham Christensen
Determinate Systems @determinate.systems · 25/02/2025
To support streamlined NixOS deployments to AWS, we now offer Determinate NixOS AMIs that come with Determinate Nix and fh, the CLI for FlakeHub, installed. Authenticate with STS, apply your configuration, and you're off to the races. determinate.systems/posts/nixos-amis
determinate.systems
Introducing Determinate AMIs for NixOS
Deploy NixOS configurations with just two commands
073
Graham Christensen @grahamc.com · 15/02/2025
Evidently, GitHub Actions' API has no way to trigger a workflow, and then know the ID of the run that was triggered.
010
Graham Christensen @grahamc.com · 11/02/2025
Yeah :(
000
Graham Christensen @grahamc.com · 11/02/2025
Which international law?
100
Graham Christensen @grahamc.com · 11/02/2025
Maps, being so utterly political, are touched by the digital age. Online maps present different boundaries and names depending on where you are.
241
Graham Christensen @grahamc.com · 02/02/2025
You know, I've never actually seen you and techconnectify in the same room ...
000
Graham Christensen @grahamc.com · 29/01/2025
At 2.5 million customers, each customer would need to open 17 per day: (24 * 60 * 60 * 500) / 2,500,000
110
Graham Christensen @grahamc.com · 29/01/2025
Hey @quinnypig.com, is it possible AWS support actually gets >500 cases per second? At that rate, is it better to send a thank you reply, or is it more polite to silently resolve closed tickets to avoid extra messages?
Two AWS support tickets opened in the same second, with their case ID being different by over 500.
131
Graham Christensen @grahamc.com · 25/01/2025
Where does that start to change? For example the other day it was -15 :)
100
Graham Christensen @grahamc.com · 24/01/2025
Do I know any swift devs that do contract work? I’ve got a project!
315