Back to articles
Technology Insight

Unlocking Infrastructure as Code: Deploying NixOS on Cloud VPS for Immutable Server Management

June 1, 2026

The Paradigm Shift in Server Management

In the traditional world of system administration, servers are often treated like pets. We nurture them, manually patch them, and over time, they develop unique configurations—a phenomenon known as 'configuration drift.' This leads to the 'it works on my machine' syndrome and makes disaster recovery a nightmare. Enter NixOS: a Linux distribution that treats servers like cattle. By leveraging a purely functional deployment model, NixOS allows you to define your entire system state in a single file, ensuring that your Cloud VPS is reproducible, immutable, and easily recoverable.

What is NixOS?

NixOS is built on top of the Nix package manager. Unlike traditional distributions like Ubuntu or CentOS, which use imperative package management (e.g., apt-get install), NixOS is declarative. You describe what you want the system to look like in a configuration.nix file, and the system ensures the reality matches your description. If something goes wrong, you can atomically roll back to any previous state, as every change creates a new system generation without overwriting the old one.

The Core Benefits of Immutable Infrastructure

Before diving into the technical implementation, it is essential to understand why business leaders and DevOps engineers are migrating to immutable architectures:

  • Reproducibility: Deploy the exact same configuration across development, staging, and production environments.
  • Atomic Upgrades: Updates either succeed completely or fail without affecting the running system. No more broken dependencies mid-update.
  • Rollback Capabilities: If a new configuration causes a regression, you can switch back to the previous working version in seconds.
  • Version Control: Since your entire server is defined in a text file, you can manage your infrastructure using Git, enabling peer reviews and audit trails.

Step 1: Preparing Your Cloud VPS for NixOS

Most cloud providers (AWS, DigitalOcean, Hetzner, or Vultr) do not offer NixOS as a default image. However, the flexibility of NixOS allows for several installation methods. The most common approach for a Cloud VPS is using the nixos-infect script or a kexec-based installer.

Standard Installation Workflow

  1. Spin up a base image: Start with a minimal Debian or Ubuntu instance.
  2. Network Configuration: Ensure you have SSH access and take note of your public IP and gateway.
  3. Execution: Run the infection script which replaces the existing OS with a NixOS environment during a reboot.
"Infrastructure is no longer a set of manual commands; it is a versioned piece of software."

Step 2: Mastering the configuration.nix File

The heart of your NixOS server is the /etc/nixos/configuration.nix file. This single file controls everything from kernel modules and networking to user accounts and application services.

A Sample Configuration for a Web Server

Imagine setting up a secure Nginx server with SSH access. In a traditional OS, this involves multiple commands and config files. In NixOS, it looks like this:

{ config, pkgs, ... }:
{
  imports = [ ./hardware-configuration.nix ];
  networking.hostName = "cloud-production";
  services.openssh.enable = true;
  services.nginx = {
    enable = true;
    virtualHosts."example.com" = {
      addSSL = true;
      enableACME = true;
      root = "/var/www/html";
    };
  };
  users.users.admin = {
    isNormalUser = true;
    extraGroups = [ "wheel" ];
    openssh.authorizedKeys.keys = [ "ssh-rsa AAAA..." ];
  };
  system.stateVersion = "23.11";
}

By applying this file using nixos-rebuild switch, the system automatically fetches Nginx, configures the firewall, requests an SSL certificate via Let's Encrypt, and creates the admin user. If you delete a line from this file and rebuild, the corresponding service is purged completely, leaving no residual 'junk' files behind.

Step 3: Advanced Deployment with Flakes and NixOps

For professional environments, the standard configuration.nix is often superseded by Nix Flakes. Flakes provide an explicit way to manage dependencies and lock versions, ensuring that your build is 100% bit-for-bit reproducible even months later.

Scaling with NixOps

If you are managing a cluster of VPS instances, NixOps (the NixOS Cloud Deployment tool) allows you to provision resources on AWS, Azure, or GCP directly from your local machine. You define the network topology in Nix code, and NixOps handles the API calls to the cloud provider and the deployment of the configuration to the target nodes.

Security and Maintenance in an Immutable World

Security is significantly enhanced in a NixOS environment. Because the system binaries are stored in a read-only /nix/store, it is much harder for unauthorized scripts to modify system files. Furthermore, keeping the system updated is a matter of updating the Nix channel and running a single command. If a kernel update causes a boot failure, you can simply select the previous generation from the GRUB menu and the server will start as if the update never happened.

Best Practices for Production

  • Externalize Data: Since the OS is immutable, keep your databases (PostgreSQL, MySQL) and user uploads on separate persistent volumes.
  • Automated Backups: Use NixOS modules like services.restic to automate encrypted backups to S3 or backblaze.
  • Monitoring: Integrate Prometheus and Grafana via NixOS services to maintain visibility into your immutable nodes.

Conclusion: Why Your Next Server Should Be NixOS

Deploying NixOS on a Cloud VPS represents a fundamental shift toward Infrastructure as Code (IaC). It eliminates the unpredictability of manual configuration and provides a robust, self-documenting environment that scales with your business needs. While the learning curve for the Nix language exists, the long-term benefits of reliability, easy migrations, and instant rollbacks make it an invaluable tool for any modern technical stack.

By adopting an immutable philosophy today, you are future-proofing your infrastructure against the complexities of tomorrow's cloud demands. It is time to stop fixing servers and start building them.

Unlocking Infrastructure as Code: Deploying NixOS on Cloud VPS for Immutable Server Management | DPTCloud