Nix for Cloud Native Platform Engineering: From Imperative Templating to Functional Derivation

The Kubernetes ecosystem currently lacks a unified model for pure and reproducible deployments. Industry standards like Helm and Dockerfiles rely on impure templating and imperative definitions, creating non-deterministic side effects and opaque dependency trees. Often, the industry attempts to mitigate this by adding layers of orchestration (Internal Developer Platforms, GitOps controllers), which can inadvertently increase complexity without addressing the underlying fragility.

This talk demonstrates how to apply Nix’s functional purity to this landscape. By organizing a platform's entire catalogue as a Nix monorepository, inspired by the architecture of nixpkgs, we can shift from managing state to deriving it, achieving total reproducibility for the entire cloud-native stack.

We will explore how Kubenix leverages the OpenAPI specification to treat Kubernetes manifests and Helm charts as Nix expressions, replacing traditional YAML templating with a strongly-typed approach. To address the build layer, we examine how dockerTools brings Nix’s hermetic, network-isolated sandboxing to the OCI ecosystem. By treating containers as first-class dependencies, we can ensure fully reproducible artifacts, optimize storage via shared OCI layers, and generate accurate SBOMs and provenance attestations as natural byproducts. Finally, we will see how the NixOS module system serves as a flexible composition layer for the scalable orchestration of complex cluster configurations.

Let’s stop templating our cloud-native infrastructure and start deriving it with Nix: purely functional, hermetically sealed, and truly reproducible.

Arik Grahl

Arik Grahl is a Staff Software Systems Architect living between Berlin and Barcelona and has more than 15 years of experience in full-stack development and operation of infrastructure on bare metal. At the moment he mainly designs cloud native systems and develops Golang applications close to Kubernetes. Furthermore, he is excited about everything evolving around Nix(OS) and enjoys contributing to Nixpkgs.

He studied computer science (BSc. in 2017, MSc. in 2021) at Technical University (TU) in Berlin. During this time he worked on freelance projects as a full-stack developer and supervised the corresponding IT infrastructure.
He also gained experience with co-founding two companies (2014, 2015) during this time with a focus on web development for small and medium-sized companies.

At his former job, he worked as a DevOps engineer where he also had the leading role in developing a mass-market product. He modernized and implemented operations and infrastructure at this company: containerization of all applications, an implementation of a CI/CD infrastructure, the operation of a self-hosted Kubernetes cluster on Bare Metal together with a Gluster and Ceph storage cluster in various locations in Europe, together with state-of-the-art observability stack. In addition, he was also intensively involved in the further training of employees concerning these technologies. Currently, he works as an Staff Software Systems Architect at SysEleven, where he is involved in the design of a cloud native software supply chain management on top of the managed Kubernetes and the development of Golang applications.

He is interested in IT security, data protection as well as network politics, and is an enthusiastic advocate of free and open-source software (FOSS). He is happy to take part in meetups and conferences to exchange ideas about technology. In his free time, he runs numerous services of everyday digital life on a home Kubernetes cluster, passionately cooks vegan food, does strength training, and listens to heavy metal.