When the Honeymoon Ends: Supporting NixOS based Products for the Next Five Years

You’ve just built a phenomenal product on NixOS. The declarative configuration is beautiful, and the reproducibility is flawless. Then the honeymoon phase ends. Your industrial hardware is deployed into the real world, and suddenly you’re faced with a five-year lifecycle. To make matters more complicated, upcoming regulations like the EU’s Cyber Resilience Act are demanding rigorous CVE tracking and compliance.

Upstream NixOS moves fast and is an incredible foundation, but maintaining those products in production for half a decade is an entirely different beast. Pinning to a release is great, but after community support ends, you hunt down vulnerabilities and backport security fixes to keep auditors happy.

We had to solve this, so we built CTRL-OS.

This talk is a behind-the-scenes story of how we manage a downstream, enterprise-grade NixOS distribution designed to survive the long haul. We will walk you through the lifecycle of our daily operations, including:

  • How we decide which packages to commit to supporting.
  • Our methodology for identifying and patching security vulnerabilities.
  • How we keep customers in the loop, turning raw data into actionable advisories for their security and compliance needs.
  • The pipeline we use to safely ship everything to customers in production.
Martin Messer

Enthusiastic Product Manager for CTRL-OS, working at Cyberus Technology GmbH.
I use Nix and NixOS on multiple devices at home and at work.
In my former role as senior software engineer I worked on virtualisation technology, starting from little self written operating system kernels up to KVM and several Virtual Machine Monitor backends for microkernels and also for Linux KVM.
Now, I'm bridging the gap between engineering and business development to bring NixOS into the commercial sector.