the world hasn’t figured out yet that you can literally just fix everything with a Nix overlay Developer Geoffrey Huntley argues that Nix overlays and NixOS let teams define a single source of truth for toolchains and dependencies across local laptops, CI/CD, and agent sandboxes, eliminating configuration drift. Huntley says he gives agents sudo access during agentic development on NixOS because the OS can roll back changes, and uses the built-in runNixOSTest framework to put the entire operating system under test, including multi-machine clusters. He dismisses mise as a "low-power, low-IQ tool" that does not enable agents to "truly fly. the world hasn’t figured out yet that you can literally just fix everything with a Nix overlay There are many things that are uncertain in our industry right now, but one thing I am certain about, and have been for almost 13 years, is that Nix is a terrible programming language. I remember when I first learned it, it felt like pushing shit uphill. The learning cliff is ferocious, and it took me a couple of years to master it because there was no AI back then, but I stuck with it. There's some magic here, and in this post, I'm going to show you why Nix should be your primary choice for all your software projects. First, I'm going to open with this: many pieces of technology are in our heads as really hard to learn, complex, and maybe that's stopped you from picking one up, but I want to encourage you to falsify those thoughts any time you start thinking along those lines. Now that we have AI, things that used to be advanced power tools, hard to use or designed for masters, are now accessible to everyone. You can just prompt for outcomes. first, some introductory knowledge The term Nix is overloaded. It means many different things; when someone says they use Nix, the first thing you should do is ask, "How do you use Nix?" and "What is Nix to you?" because there are many ways to use it; it's not just a package manager or a build system; it can also be an operating system. In this post, I'll focus on Nix's versatility and utility, and why it's so powerful in the age of AI. There's a reason the labs are using this to build the models you are consuming... agent and developer experience By using tools like https://devenv.sh/ https://devenv.sh/?ref=ghuntley.com , you can define a single source of truth for your compilation toolchain and required third-party dependencies. Humans can use this single source of truth in CI/CD and in ephemeral sandbox development environments used by agents. I keep coming across clients with drift between how a local laptop is configured and how their CI/CD is configured. And now we've got ephemeral sandbox environments; they're heading down a path of triplicating that drift. This is utter madness. It is not needed. Stop it. You might be thinking, "Well, there's mise for this." Trust me, mise isn't good enough. Mise is a low-power, low-IQ tool. It does one thing, and it does it well, but it doesn't enable your agents to truly fly. not just a package manager nix is super composable. That same expression that defines your human developer environment setup, your CI/CD setup, and your ephemeral sandbox setup can also be reused to build performant Docker images. But perhaps... the real reason I love Nix is its power to compose an operating system. With a standard operating system such as Debian or Ubuntu, what happens if an agent is given sudo access to do things on your machine? You'd be pretty scared, right? What if I told you that when I'm doing agentic development, I develop on NixOS and I explicitly prompt my agents to use sudo as part of my loop engineering, and it is safe because NixOS is designed to make it nearly impossible to break a machine, and if it does, you can instantly roll back that change. why the operating system matters When others do loop engineering with their agents, they're likely running loops with building the application, perhaps Postgres, but rarely anything more. The primary difference between how others do loop engineering and how I do is that, when I run loops, I put the entire system under test, and the entire System Under Test IS the operating system . You might think, "Whoa, what the —" Like, how the hell do you do this? ah My sweet summer child. It is really simple. NixOS has a testing framework runNixOSTest , built in, and for anything you could ever want to assert about how an operating system is configured, or even across many machines, you can spin up a cluster. You can use a number of machines in a test, assert the network rules between them are correct, and that the right IP tables are forwarded or dropped. You do machines of machines, and you actually test the interoperability of that environment against your application. Here's an example of what this looks like when you've defined an operating system in NixOS and want to assert the network is configured correctly with your firewall zones, and that network activity works for your application before you deploy it. NixOS VM test: HAProxy in front of a Python hello-world server. Topology two QEMU nodes, separate L2 networks : vlan 1 192.168.1.0/24 frontend haproxy eth1 192.168.1.1/24 HAProxy binds :80 here only vlan 2 192.168.2.0/24 backend haproxy eth2 192.168.2.1/24 allowed source eth2 192.168.2.50/24 extra address, must be rejected web eth2 192.168.2.2/24 Python hello-world on :8080 NixOS test IP scheme is 192.168.