NixOS in the Corporate Trenches: Cuts and Bruises

NixOS promises a utopian, purely reproducible future. But deploying it inside a legacy corporate network feels like trench warfare. Standard fetchers get gunned down by enterprise proxies, and security teams deploy Endpoint Detection and Response (EDR) agents like landmines on our beautifully immutable operating system.

In this talk, I’ll walk you through my ongoing campaign to build a secure, fully provisioned NixOS Developer VM for a strict corporate client. I’ll share the battle scars of custom proxy packaging, the frontline struggle of EDR integration, and the covert operation of deploying air-gapped, sandboxed AI.

Join me to learn how to survive (and win) in the corporate trenches!

Nicolas Goudry

Hi, I’m Nicolas Goudry, a DevOps engineer mainly focused on Kubernetes and Cloud Native technologies.
I love exploring ways to make development environments more reliable and reproducible, and I’ve spent way too much time working with Nix and its ecosystem (but I love it).