Tweag+Nix dev update #58

Hello esteemed Nixers!

The last developer update from Tweag was two years ago, what a shame. Now we’re back.

First off, big people news:

  • @infinisil has taken off his Tweag hat and is moving on to new adventures. :cry:

    Infinite thanks from all the team for your incredible work throughout all these years! Nixpkgs – and Tweag – would not be what it is today without your dedication. It was a great joy building with and alongside you. :heart: We wish you all the best on your journey, may you bring calm and order wherever you go. And hopefully our build graphs will cross paths again.

  • @gilligan and @andir are back at Tweag, after many years. :tada:

    @gilligan is now carrying the torch as Head of Tweag, and his programmatic emphasis on our engineering culture makes us Nixers very happy.

    @andir took over many of @infinisil’s responsibilities, now acting as the resident Nixpkgs guru.

Nix stuff. Apart from our usual work to keep increasing developer productivity for clients and community, in the past year we’ve mainly set our mind to improving Nixpkgs supply chain security.

Other than that we’re preparing for NixCon 2026 and looking forward to meeting each other and many of you in person!

Keep nixing :vulcan_salute:

29 Likes

How does this work compare to what’s in, say, rio-build (archived) or Tribuchet, or whatever nixbuild.net does under the hood?

4 Likes

AFAICT, rio-build, tribuchet and nixbuild.net all distribute building of derivations to a cluster, while the high-availability part of my branch is to ensure that the main nix server, the part answering the nix protocol, is redundant and can fail gracelully to another instance.
nixbuild.net is of course much more robust than bare nix, but it still needs downtime for maintenance. With a cluster of nix nodes, able to work together, one could upgrade one node without shutting down the whole service. No downtime.
You can tell the difference because my implementation requires the client to try another server in the list when the connection fails.
Ideally, the DNS would provide several IPs for the same name, but I did not go that far yet.

1 Like

this is a fantastic change btw, running it for testing purposes before was a real pain

1 Like

What concrete benefits do you receive by making the Nix daemon (/nix/var/nix/daemon-socket/socket) highly available (as opposed to scheduling derivations on HA/distributed remote builders)? You mention

but AFAIK Tribuchet can survive workers going away and joining with no downtime. Hub changes may be different. I see that Tribuchet requires the hub to be local to the machine initiating the build, @Mic92, are there any plans to make it more HA/distributed (or any other thoughts on this and similar work)?

1 Like