NixOS: Declarative Linux for Reproducible Sovereign Infrastructure Training Course
NixOS is a Linux distribution built on the Nix package manager, offering fully declarative and reproducible system configuration. By describing entire operating systems as pure functions, NixOS eliminates configuration drift and enables atomic rollbacks, making it ideal for sovereign infrastructure that must be auditable and exactly reproducible.
This instructor-led, live training (online or onsite) is aimed at advanced Linux administrators and infrastructure engineers who wish to use NixOS to replace traditional configuration management with a purely functional, declarative operating system.
By the end of this training, participants will be able to:
- Install NixOS and manage system state with configuration.nix.
- Build reproducible development environments with nix-shell and flakes.
- Deploy NixOS machines remotely with NixOps or Colmena.
- Manage packages, services, and users declaratively.
- Rollback systems atomically after failed updates.
Format of the Course
- Interactive lecture and discussion.
- Lots of exercises and practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Course Outline
Declarative System Sovereignty
- Why imperative configuration management leads to drift and audit failure.
- Nix store, derivations, and pure functions for system building.
- NixOS vs traditional distros: immutability and atomic upgrades.
Installation and Basics
- Installing NixOS from ISO with manual and automated partitioning.
- The Nix language: sets, functions, and imports.
- configuration.nix structure and module system.
- Searching packages and options with nix search and man pages.
Package and Service Management
- Installing packages system-wide vs per-user with nix-env.
- Enabling systemd services declaratively.
- Custom package overrides and overlays.
- Garbage collection and store optimization.
Reproducible Environments
- nix-shell and shell.nix for ad-hoc development.
- Nix Flakes for lockfile-based reproducibility.
- devenv and devshell for team onboarding.
- Direnv integration for automatic environment switching.
Remote Deployment
- NixOps and Colmena for fleet management.
- Remote building and binary cache configuration.
- Secrets management with agenix and sops-nix.
- Deployment testing with NixOS VMs and containers.
System Updates and Rollbacks
- nixos-rebuild switch, test, and boot modes.
- Atomic rollback to previous generations.
- Channel management and pinning for reproducible updates.
- Emergency recovery and bootloader configuration.
Advanced Topics
- NixOS containers and lightweight virtualization.
- Cross-compilation and ARM builds.
- Custom ISO and netboot image generation.
- Hydra continuous integration for Nix packages.
Requirements
- Advanced Linux system administration and shell scripting experience.
- Fundamental understanding of functional programming concepts.
- Familiarity with Git and version-controlled configuration workflows.
Audience
- Infrastructure engineers seeking reproducible, declarative systems.
- DevOps teams looking to replace Ansible, Puppet, or Chef with Nix.
- Organizations requiring bit-for-bit reproducible deployments.
Need help picking the right course?
southafrica@nobleprog.co.za or +27 (0)10 005 5793
NixOS: Declarative Linux for Reproducible Sovereign Infrastructure Training Course - Enquiry
Related Courses
Gitea: Self-Hosted Git Forge Replacing GitHub and GitLab
14 HoursGitea is a lightweight, open-source, self-hosted Git service offering repository management, code review, issue tracking, and CI/CD integration. It serves as an increasingly popular alternative to GitHub and GitLab.com for teams needing full control over their source code without third-party terms of service or export restrictions.
GitLab Self-Managed: Complete DevSecOps Platform Without SaaS
21 HoursGitLab Self-Managed is the on-premises deployment of GitLab's complete DevSecOps platform, including source code management, CI/CD, container registry, security scanning, and monitoring. It is the gold standard for organizations that want the full GitLab feature set without SaaS dependency or data leaving their network.
Container Sovereignty: Kubernetes Without Cloud Dependencies
21 HoursThis instructor-led, live training in Nigeria (online or onsite) is aimed at intermediate to advanced DevOps engineers and system administrators who wish to deploy and manage self-hosted Kubernetes clusters without cloud dependencies.
By the end of this training, participants will be able to: deploy production-ready Kubernetes clusters using kubeadm on bare-metal or virtual machines; configure high-availability control planes and etcd clusters; implement container networking and storage for self-managed environments; set up monitoring and observability using self-hosted solutions.
Multi-Cloud Sovereignty: Avoiding Single-Vendor Lock-in
14 HoursThis instructor-led training, offered online or onsite, targets cloud professionals aiming to design and implement multi-cloud architectures that prevent vendor lock-in and guarantee data sovereignty.
By the end of the course, attendees will be capable of identifying vendor lock-in risks, designing portable architectures, implementing data sovereignty controls, and making effective use of cloud-agnostic tools.
Open Network Operating Systems: SONiC and ONL
14 HoursThis instructor-led, live training in Nigeria (online or onsite) is aimed at network engineers and infrastructure professionals who wish to use SONiC and ONL to deploy and manage open network infrastructure on white-box switches.
By the end of this training, participants will be able to: understand SONiC and ONL architecture, deploy open-source NOS on white-box hardware, configure networking features, and implement monitoring and automation.
Private Cloud Infrastructure: OpenStack for Enterprises
21 HoursThis instructor-led, live training (available online or on-site) is tailored for system administrators and infrastructure engineers seeking to design, deploy, and manage private OpenStack cloud infrastructures for enterprise settings.
By the end of the course, participants will understand OpenStack architecture, deploy private cloud infrastructure, manage compute and storage resources, implement security via Keystone, and apply enterprise-grade best practices.
Software-Defined Networking with Open Source Tools
35 HoursThis instructor-led live training in Nigeria (online or onsite) is aimed at intermediate-level network engineers and infrastructure administrators who wish to implement software-defined networks using open source tools and technologies.
By the end of this training, participants will be able to design SDN architectures, implement Open vSwitch, configure FRRouting, deploy SDN controllers, and automate network management.
Building a Self-Managed Enterprise Network with Open-Source Routers, Switching, and Wi-Fi
21 HoursThis instructor-led live training in Nigeria (online or onsite) is designed for intermediate-level network and infrastructure professionals who wish to use open-source routing, switching, Wi-Fi, and management tools to design, deploy, and operate a self-managed enterprise network.
By the end of this training, participants will be able to: design an open-source enterprise network architecture, configure routing, switching, and wireless services, enhance security and observability, and develop an operational plan for ongoing support.
Terraform: Self-Hosted Infrastructure as Code Without Cloud Lock-in
14 HoursTerraform is an open-source infrastructure-as-code tool that empowers teams to define and provision data center infrastructure using a declarative configuration language. When paired with self-hosted backends and on-premise providers, Terraform becomes a potent instrument for sovereign infrastructure management, effectively eliminating cloud vendor lock-in.
This instructor-led, live training (available online or onsite) is designed for intermediate infrastructure engineers seeking to leverage Terraform to manage self-hosted environments, including Proxmox, VMware, libvirt, and bare-metal provisioning.
By the end of this training, participants will be able to:
- Write robust Terraform configurations for on-premise and hybrid resources.
- Securely manage state using self-hosted backends such as PostgreSQL, S3-compatible storage, and Gitea.
- Utilize provisioners and custom providers to manage the entire bare-metal lifecycle.
- Implement efficient workspaces, modular architectures, and variable hierarchies.
- Integrate Terraform into CI/CD pipelines for automated infrastructure delivery.
Format of the Course
- Interactive lectures and guided discussions.
- Extensive exercises and practical labs.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training track for this course, please contact us to arrange specific requirements.
Uptime Kuma: Self-Hosted Monitoring Replacing Datadog and Pingdom
7 HoursUptime Kuma is an easy-to-use, self-hosted monitoring tool that tracks the availability of websites, services, and infrastructure. It replaces Pingdom, Datadog Synthetics, and UptimeRobot for teams that want monitoring data under their own control. This instructor-led, live training (online or onsite) is aimed at beginner-to-intermediate SREs and DevOps engineers who wish to use Uptime Kuma to replace cloud uptime monitoring with a self-hosted, sovereign status tracking platform.
Enterprise VPN: Self-Hosted WireGuard and OpenVPN
21 HoursThis instructor-led, live training in Nigeria (online or onsite) is aimed at security engineers and system administrators who wish to deploy and manage enterprise-grade self-hosted VPN solutions using WireGuard and OpenVPN.
By the end of this training, participants will be able to deploy WireGuard and OpenVPN, design scalable architectures, integrate with identity systems, and monitor/secure VPN infrastructure.
OpenVPN and WireGuard: Self-Hosted VPN Replacing ExpressVPN and NordLayer
14 HoursOpenVPN and WireGuard are the two leading open-source VPN protocols. By hosting your own VPN server, you guarantee that no third-party provider can log traffic metadata, inject advertisements, or comply with foreign data requests. This training covers both protocols to address various threat models and performance requirements.
Wazuh: Open-Source Security Monitoring Replacing Splunk and Sentinel
21 HoursWazuh is an open-source security platform delivering unified XDR and SIEM capabilities for threat detection, integrity monitoring, incident response, and compliance. It aggregates endpoint telemetry into a self-managed analysis engine, serving as a credible alternative to Splunk Enterprise Security, Microsoft Sentinel, and other cloud-native SIEMs.
Woodpecker CI: Lightweight Self-Hosted Pipelines for Gitea and Forgejo
14 HoursWoodpecker CI is a straightforward yet robust continuous integration engine built specifically for self-hosted Git platforms like Gitea and Forgejo. It offers a lightweight, Docker-native CI/CD experience, sparing users the complexity and licensing costs typically associated with enterprise CI solutions.
Zero Trust Architecture with Open Source Components
35 HoursThis instructor-led, live training in Nigeria (online or onsite) is aimed at intermediate-level to advanced-level security professionals who wish to implement Zero Trust Architecture using open-source tools and sovereign infrastructure.
By the end of this training, participants will be able to design Zero Trust architectures, deploy identity-aware proxies, implement dynamic authentication, secure microservices with service mesh, and monitor zero trust policies.