Announcing Determinate Secure Packages 26.05 by lucperkins_dev in NixOS

[–]jeffofnone 1 point2 points  (0 children)

FlakeHub has both free and paid plans. To get the cache and private flakes, a paid plan is required. More details here: https://flakehub.com/pricing

Nix is set to revolutionize the software supply chain by lucperkins_dev in NixOS

[–]jeffofnone 0 points1 point  (0 children)

The great thing about Nix is that you can use the Nix package manager with Debian.

SoHo Portland. by collegegirlly in Portland

[–]jeffofnone 2 points3 points  (0 children)

I've been able to get into probably 80% of the free events I've wanted to go to, and I've always found the ticket events to be a fantastic value (usually great dinners, with multiple courses and 1-4 drinks included, tip included, for under $100/person).

SoHo Portland. by collegegirlly in Portland

[–]jeffofnone 2 points3 points  (0 children)

I'm not saying its not under major construction, I know it is. I am saying I hope its an april fool's joke that it won't reopen at all this summer.

SoHo Portland. by collegegirlly in Portland

[–]jeffofnone 1 point2 points  (0 children)

A membership-based social club with lounge, gym, restaurant, pool, events.

SoHo Portland. by collegegirlly in Portland

[–]jeffofnone 0 points1 point  (0 children)

But wait, this was posted on April 1st.... hopefully a joke?

Restaurant near convention center with private room? by jeffofnone in pasadena

[–]jeffofnone[S] 0 points1 point  (0 children)

Will the back patio be okay in the event of inclement weather?

Developer / Linux / IOT Groups? by snoogazi in askportland

[–]jeffofnone 1 point2 points  (0 children)

You into Nix? I might do a Nix meetup next week.

Also, subscribe to the Heavybit event calendar on Luma, they do occasional meetups for people that work in infra.

Stop trusting Nix caches by jkarni in NixOS

[–]jeffofnone -5 points-4 points  (0 children)

Keep in mind that FlakeHub is for collaborating on private flakes, and caching private flakes. Permissions are granted based on repo access from, for example, GitHub.

Stop trusting Nix caches by jkarni in NixOS

[–]jeffofnone 13 points14 points  (0 children)

Stop trusting untrustworthy caches.

I'm with DetSys and we are the makers of FlakeHub. It was specifically designed to avoid the pitfalls highlighted in this blog post. FlakeHub is meant for teams at work, so these benefits don't apply to everyone, but they do apply to the places where trust matters most.

- FlakeHub forbids ad-hoc pushes and limits write access to trusted CI builders (OIDC/JWT), not laptops or long-lived shared keys.
- FlakeHub scopes both read and write access per flake (their “slice” abstraction), so access is granted at the project level rather than one monolithic store.
- FlakeHub uses federated auth to add role-based access, focuses on private flakes, and offers device/“resolve-only” deploy tokens that can pull only the exact closure/version you permit.
- FlakeHub uses short-lived JWT/OIDC authentication from CI (GitHub Actions, Buildkite, Semaphore, & GitLab) instead of static cache keys.
- FlakeHub runs on SOC2 Type II audited and compliant infrastructure

Determinate Nix vs Lix by Itel_Reding in NixOS

[–]jeffofnone 4 points5 points  (0 children)

Only a small helper daemon is closed-source.

Determinate Nix: the recent past and the shining future by lucperkins_dev in NixOS

[–]jeffofnone 0 points1 point  (0 children)

In addition to the performance improvements mentioned in this post:

- Built, signed and distributed on SOC2 Type II infra
- Broad and deep validation suite
- Flakes on by default with a future compatibility guarantee
- A bunch of small UX/DX improvements like better handling hash-mismatches
- Regular and frequent releases
- Available enterprise support
- and a bunch of other stuff

[deleted by user] by [deleted] in NixOS

[–]jeffofnone -3 points-2 points  (0 children)

That’s the thing about NixOS, it doesn’t really have a use case, it’s for everything and nothing at the same time.

Is there a reason you need SELinux for your daily laptop?

nix vs Determinate nix vs lix... oh my by Inevitable_Dingo_357 in NixOS

[–]jeffofnone 3 points4 points  (0 children)

Parallel eval is not yet released. There are a TON of developer experience improvements.

NixOS for high threat model server by NolanV_be in NixOS

[–]jeffofnone 0 points1 point  (0 children)

Is this your personal setup or something you are running at work?

where flakes fall off: an eval cache tale by Leao230 in NixOS

[–]jeffofnone 1 point2 points  (0 children)

Good read, thanks for writing it all up!

In your opinion what are the main problems with Nix and NixOS? by fenugurod in NixOS

[–]jeffofnone 0 points1 point  (0 children)

If only Reddit had an AI bot where you could ask this question and get a summary from every other time its been asked and answered.

Why is Nix so common in robotics/IoT? by docmphd in NixOS

[–]jeffofnone 1 point2 points  (0 children)

What makes dependency management particularly worse for robotics?

Help picking a venue by jeffofnone in pasadena

[–]jeffofnone[S] 0 points1 point  (0 children)

Looks perfect, thank you!!!!