Best practices for auto-upgrades of flake-enabled NixOS systems?

I made some comments about how I use this here…

Basically (and as you were asking for) unlike the previous channel-based case, I don’t want the autoUpdate updating its own lock file; I now want it to pull the lock file with the rest of the config.