Build It All Yourself (And Prove It): Air-Gapped Nixpkgs with Hydra
How do you guarantee absolute software supply chain security without locking your developers into a restricted environment?
In highly regulated industries, the standard answer is painful: force all development into offline, air-gapped environments. But Nix offers an elegant alternative. Because Nix cleanly separates network-fetching from building, we can decouple developer velocity from compliance. Developers can work in unrestricted environments while releases are rebuilt from scratch behind the air gap to prove (to authorities) that an exact verified set of unchanged sources led to our binaries.
In this talk, we share a concrete blueprint for building all of Nixpkgs entirely offline. We cover:
- How to develop freely and use air-gapped Hydra builds to produce a 100% trusted, verified binary cache.
- The practical cost of sovereignty: carrying an audited ~1TB seed (one disk, one hash) across the gap, and rebuilding all of Nixpkgs on standard hardware in a week.
- How content-addressed seeds and pinned evaluations create a replayable record of your software for decades to come.
Regardless of which critical regulated industry you work in, you will leave with a proven recipe to achieve total digital sovereignty without sacrificing modern developer workflows.
Kierán Meinhardt fell down the Nix rabbit hole in 2018 by way of Haskell. Today, he is a NixOS consultant at Applicative Systems and a long-time regular at the weekly Berlin NixOS meetup. Upstream he is best known for introducing systemd-nspawn container tests to nixpkgs.