[GPLv3+] install nixos over the existing OS in a DigitalOcean droplet (and others with minor modifications)

Clone this repo:
  1. 1fa358e Update default nixpkgs version to 21.11 (#85) by Kid · 1 year ago master
  2. 048ef96 Update README for Debian 11 on Hetzner Cloud (#84) by Xavier Vello · 1 year ago
  3. 343eecd Update README.md for OVHcloud on Debian 11 (#83) by Thomas Jost · 1 year, 1 month ago
  4. 1e2ab19 Add a search path /home/$SUDO_USER/ for ssh keys (#79) by asdfasdf · 1 year, 4 months ago
  5. d4b99a2 Update default nix to latest stable 21.05 (#78) by José Albornoz · 1 year, 6 months ago


What is this?

A script to install NixOS on non-NixOS hosts.

NixOS-Infect is so named because of the high likelihood of rendering a system inoperable. Use with extreme caution and preferably only on newly provisioned systems.

This script has successfully been tested on at least the follow hosting providers and plans:

Should you find that it works on your hoster, feel free to update this README and issue a pull request.


Motivation for this script: nixos-assimilate should supplant this script entirely, if it's ever completed. nixos-in-place was quite broken when I tried it, and also took a pretty janky approach that was substantially more complex than this (although it supported more platforms): it didn't install to root (/nixos instead), left dregs of the old filesystem (almost always unnecessary since starting from a fresh deployment), and most importantly, simply didn't work for me! (old system was being because grub wasnt properly reinstalled)

How do I use it?

  1. Read and understand the the script
  2. Deploy any custom configuration you want on your host
  3. Deploy your host as non-Nix Operating System.
  4. Deploy an SSH key for the root user.

NB: This step is important. The root user will not have a password when nixos-infect runs to completion. To enable root login, you must have an SSH key configured.

  1. run the script with:
  curl https://raw.githubusercontent.com/elitak/nixos-infect/master/nixos-infect | NIX_CHANNEL=nixos-21.11 bash -x

NB: This script wipes out the targeted host's root filesystem when it runs to completion. Any errors halt execution. A failure will leave the system in an inconsistent state, and so it is advised to run with bash -x.

Hoster notes:

Digital Ocean

You may utilize Digital Ocean's "user data" mechanism (found in the Web UI or HTTP API), and supply to it the following example yaml stanzas:


  - curl https://raw.githubusercontent.com/elitak/nixos-infect/master/nixos-infect | PROVIDER=digitalocean NIX_CHANNEL=nixos-21.11 bash 2>&1 | tee /tmp/infect.log

Potential tweaks:

  • /etc/nixos/{,hardware-}configuration.nix: rudimentary mostly static config
  • /etc/nixos/networking.nix: networking settings determined at runtime tweak if no ipv6, different number of adapters, etc.
- path: /etc/nixos/host.nix
  permissions: '0644'
  content: |
    {pkgs, ...}:
      environment.systemPackages = with pkgs; [ vim ];
  - curl https://raw.githubusercontent.com/elitak/nixos-infect/master/nixos-infect | PROVIDER=digitalocean NIXOS_IMPORT=./host.nix NIX_CHANNEL=nixos-21.11 bash 2>&1 | tee /tmp/infect.log

Tested on

DistributionNameStatustest date
CentOS6.9 x32failure2020-03-30
CentOS6.9 x64failure2020-03-30
CentOS7.6 x64failure2020-03-30
CentOS8.1 x64success2020-03-30
CoreOS2345.3.0 (stable)unable2020-03-30
CoreOS2411.1.0 (beta)unable2020-03-30
CoreOS2430.0.0 (alpha)unable2020-03-30
Debian10.3 x64success2020-03-30
Debian9.12 x64success2020-03-30
Fedora30 x64success2020-03-30
Fedora31 x64success2020-03-30
FreeBSD11.3 x64 ufsfailure2020-03-30
FreeBSD11.3 x64 zfsfailure2020-03-30
FreeBSD12.1 x64 ufsfailure2020-03-30
FreeBSD12.1 x64 zfsfailure2020-03-30
Ubuntu16.04.6 (LTS) x32success2020-03-30
Ubuntu16.04.6 (LTS) x64success2020-03-30
Ubuntu18.04.3 (LTS) x64success2020-03-30
Ubuntu19.10 x64success2020-03-30


To set up a NixOS Vultr server, instantiate an Ubuntu box with the following "Startup Script":


curl https://raw.githubusercontent.com/elitak/nixos-infect/master/nixos-infect | NIX_CHANNEL=nixos-21.11 bash

Allow for a few minutes over the usual Ubuntu deployment time for NixOS to download & install itself.

Tested on

DistributionNameStatustest dateSlugID
Ubuntu18.10 x64success(Unknown)(Unknown)(Unknown)

Hetzner cloud

Hetzner cloud works out of the box. When creating a server provide the following script as "User data":


curl https://raw.githubusercontent.com/elitak/nixos-infect/master/nixos-infect | NIX_CHANNEL=nixos-21.11 bash 2>&1 | tee /tmp/infect.log

Tested on

DistributionNameStatustest date
Ubuntu20.04 x64success(Unknown)

InterServer VPS

Tested on

DistributionNameStatustest date

Tencent Cloud Lighthouse

Tencent Cloud Lighthouse Hong Kong Region Works out of the box.

Other Regions in China may not work because of the unreliable connection between China and global Internet or GFW.

Tested on

DistributionNameStatustest date


Before executing the install script, you may need to check your mounts with df -h. By default, OVH adds a relatively short in memory tmpfs mount on the /tmp folder, so the install script runs short in memory and fails. Just execute umount /tmp before launching the install script. Full install process described here

DistributionNameStatustest date
Arch LinuxArch Linux x86-64success2021-03-25

Oracle Cloud Infrastructure

Tested for both VM.Standard.E2.1.Micro (x86) and VM.Standard.A1.Flex (AArch64) instances.

Tested on

DistributionNameStatustest date
Oracle Linux7.9success2021-05-31