Back to articles
Technology Insight

Scaling Infrastructure Instantly: How to Clone 100 Identical VPS Servers in 60 Seconds Using NixOS Flakes

May 30, 2026

The DevOps Nightmare: Configuration Drift at Scale

In modern cloud infrastructure management, scaling rapidly while maintaining absolute consistency is a monumental challenge. Traditional configuration management tools like Ansible, Chef, or Puppet have long been the industry standards. However, they inherently suffer from a fundamental flaw: mutability. Over time, subtle differences creep into servers due to manual interventions, interrupted updates, or non-deterministic package managers—a phenomenon known as configuration drift.

Imagine the scenario: you need to spin up 100 identical Virtual Private Servers (VPS) for a high-availability cluster or a distributed microservices architecture. Using traditional methods, ensuring that every single dependency, system library, and configuration file is perfectly mirrored across all 100 nodes is not only time-consuming but statistically prone to error. This is where NixOS and NixOS Flakes enter the paradigm, transforming infrastructure from an imperative guessing game into a deterministic science.

Understanding the Paradigm Shift: What is NixOS and Flakes?

NixOS is a Linux distribution built on top of the Nix package manager. It utilizes a declarative approach to system configuration. Instead of executing commands to install packages or modify configuration files (e.g., apt-get install or editing /etc/nginx.conf directly), the entire state of the operating system is described in a single, centralized configuration file.

NixOS Flakes, introduced as a feature to improve ecosystem reproducibility, takes this a step further. Flakes provide a standardized way to package code, track dependencies via a lockfile (flake.lock), and ensure that a configuration built today will yield the exact same system byte-for-byte when built five years from now on entirely different hardware. This absolute reproducibility is the secret weapon that allows us to clone 100 identical VPS servers in a matter of seconds.

The Architecture of 60-Second Provisioning

To achieve the feat of deploying 100 identical servers in under a minute, we do not perform a standard, sequential installation on each machine. Instead, we leverage the unique architectural traits of NixOS alongside modern cloud orchestration APIs. The process is broken down into three core mechanics:

  1. Local Evaluation and Compilation: The entire system configuration is evaluated locally or on a continuous integration (CI) runner. Nix compiles the exact system closures into an immutable image or an accessible binary cache.
  2. Parallel Cloud Deployment: Utilizing Terraform or the cloud provider’s native API, 100 VPS instances are initialized simultaneously.
  3. Kexec or Custom Image Injection: The pre-baked, deterministic NixOS closure is pulled down from a central binary cache (such as Cachix) and injected into the running VPS memory space via kexec, instantly swapping the boot OS with your exact NixOS configuration without a traditional slow installation process.
"In the world of NixOS, servers are truly treated as cattle, not pets. Because the configuration is pure and functions like a mathematical equation, the exact state can be replicated instantly anywhere."

Step-by-Step Guide to Configuring NixOS Flakes for Mass Cloning

Step 1: Setting Up the Flake Architecture

To begin, we establish our flake.nix file. This file serves as the single source of truth for our infrastructure. It defines our inputs (such as the specific channel of Nixpkgs) and outputs (the actual server configurations).

{
  description = "Enterprise VPS Cluster Configuration";

  inputs = {
    nixpkgs.url = "github:nixos/nixpkgs/nixos-23.11";
  };

  outputs = { self, nixpkgs, ... }:
    let
      system = "x86_64-linux";
      pkgs = nixpkgs.legacyPackages.${system};
    in {
      nixosConfigurations.vps-node = nixpkgs.lib.nixosSystem {
        inherit system;
        modules = [
          ./configuration.nix
          ./hardware-configuration.nix
        ];
      };
    };
}

Step 2: Defining the Declarative Configuration

Next, we write the configuration.nix file. This file strictly defines everything the server needs: from user accounts and SSH keys to system services like Nginx, Docker, or PostgreSQL. Because this file is immutable, every server initialized with it will possess identical security baselines, kernel parameters, and network configurations.

{ config, pkgs, ... }:
{
  imports = [ ./hardware-configuration.nix ];

  # Bootloader settings optimized for cloud VPS
  boot.loader.grub.enable = true;
  boot.loader.grub.device = "/dev/vda";

  networking.hostName = "vps-cluster-node";
  networking.firewall.allowedTCPPorts = [ 80 443 22 ];

  services.openssh = {
    enable = true;
    settings.PermitRootLogin = "prohibit-password";
  };

  users.users.admin = {
    isNormalUser = true;
    extraGroups = [ "wheel" "docker" ];
    openssh.authorizedKeys.keys = [
      "ssh-rsa AAAAB3NzaC1yc2E... enterprise-key"
    ];
  };

  environment.systemPackages = with pkgs; [ htop git curl vim ];
  virtualisation.docker.enable = true;

  system.stateVersion = "23.11";
}

Step 3: Generating and Caching the System Closure

Before triggering the mass deployment, we evaluate the flake and push the resulting binaries to a custom binary cache. This step ensures that the VPS instances do not spend time building packages or compiling configurations upon boot. They simply download pre-compiled, cryptographically signed binaries.

  • Run nix build .#nixosConfigurations.vps-node.config.system.build.toplevel to build the system closure locally.
  • Push the build artifacts to a binary cache using tools like Cachix: nix path-info -r .#nixosConfigurations.vps-node.config.system.build.toplevel | cachix push your-private-cache.

The 60-Second Automation Script

With the system configuration built and securely cached, we can utilize a provisioning script combining Terraform (to spin up 100 VPS bodies concurrently) and nixos-anywhere. nixos-anywhere is a powerful utility that connects to any standard Linux server via SSH, initiates a kexec into a NixOS installer, partitions the drive, and pulls down the pre-built Flake closure directly from your binary cache.

Because cloud providers can provision 100 VPS instances concurrently within 15 to 30 seconds, and nixos-anywhere takes roughly another 30 seconds to stream the pre-compiled binary cache directly into disk, the entire fleet transitions from blank slates to operational, production-ready, identical NixOS systems in approximately 60 seconds.

Business Benefits of NixOS Flakes in Enterprise Infrastructure

Transitioning to NixOS Flakes for large-scale node deployment delivers severe competitive advantages for enterprise operations:

MetricTraditional Infrastructure (Ansible/Ubuntu)NixOS Flakes Infrastructure
Deployment Speed (100 Nodes)15 - 45 Minutes (Sequential/Throttled)Under 60 Seconds (Parallel/Cached)
Configuration Drift GuaranteeNo (Prone to local state alteration)Yes (Absolute cryptographic guarantee)
Rollback TimeComplex playbook reversals (Minutes/Hours)Instantaneous atomic rollback (1 Second)
Testing Environment MirroringApproximated environments100% Exact byte-for-byte replication

1. Elimination of "It Works on My Machine"

Because NixOS Flakes utilize a strict flake.lock file, every single shared library, system package, and configuration toggle is explicitly locked to a specific cryptographic hash. Testing environments mirror production down to the exact bits, reducing deployment regressions to zero.

2. Atomic Updates and Zero-Risk Rollbacks

Should an infrastructure update go wrong across the 100 VPS nodes, NixOS supports atomic rollbacks. If a new configuration fails health checks, the systems can instantly revert to the previous working generation in under a second, as old binaries remain untouched in the Nix store.

Conclusion

The imperative approach to managing cloud infrastructure is rapidly becoming an operational bottleneck. Scaling to 100 identical VPS servers shouldn't involve running massive, time-consuming execution loops that verify state line-by-line. By adopting NixOS Flakes, engineering teams can treat entire server fleets as deterministic expressions of code. The result is a highly resilient, blazingly fast, and completely predictable deployment pipeline that takes infrastructure from initialization to production in 60 seconds flat.

Scaling Infrastructure Instantly: How to Clone 100 Identical VPS Servers in 60 Seconds Using NixOS Flakes | DPTCloud