Build It All Yourself (And Prove It): Air-Gapped Nixpkgs with Hydra

How do you guarantee absolute software supply chain security without locking your developers into a restricted environment?

In highly regulated industries, the standard answer is painful: force all development into offline, air-gapped environments. But Nix offers an elegant alternative. Because Nix cleanly separates network-fetching from building, we can decouple developer velocity from compliance. Developers can work in unrestricted environments while releases are rebuilt from scratch behind the air gap to prove (to authorities) that an exact verified set of unchanged sources led to our binaries.

In this talk, we share a concrete blueprint for building all of Nixpkgs entirely offline. We cover:

  • How to develop freely and use air-gapped Hydra builds to produce a 100% trusted, verified binary cache.
  • The practical cost of sovereignty: carrying an audited ~1TB seed (one disk, one hash) across the gap, and rebuilding all of Nixpkgs on standard hardware in a week.
  • How content-addressed seeds and pinned evaluations create a replayable record of your software for decades to come.

Regardless of which critical regulated industry you work in, you will leave with a proven recipe to achieve total digital sovereignty without sacrificing modern developer workflows.

Jacek Galowicz

Jacek Galowicz is a systems architect, Nixpkgs contributor and maintainer of the NixOS Integration Test Driver. He is the founder of Applicative Systems, a software development consulting firm, and Nixcademy, corporate Nix/NixOS training provider. With a background ranging from microhypervisors, CI/CD automation, and writing technical books, Jacek focuses on building resilient, machine-verified software infrastructure that lasts.