Name
nix-store --serve - serve local Nix store over SSH
Synopsis
nix-store --serve [--write]
Description
The operation --serve provides access to the Nix store over stdin and
stdout, and is intended to be used as a means of providing Nix store
access to a restricted ssh user.
The following flags are available:
- 
--writeAllow the connected client to request the realization of derivations. In effect, this can be used to make the host act as a remote builder. 
Options
The following options are allowed for all nix-store operations, but may not always have an effect.
- 
--add-rootpathCauses the result of a realisation ( --realiseand--force-realise) to be registered as a root of the garbage collector. path will be created as a symlink to the resulting store path. In addition, a uniquely named symlink to path will be created in/nix/var/nix/gcroots/auto/. For instance,$ nix-store --add-root /home/eelco/bla/result --realise ... $ ls -l /nix/var/nix/gcroots/auto lrwxrwxrwx 1 ... 2005-03-13 21:10 dn54lcypm8f8... -> /home/eelco/bla/result $ ls -l /home/eelco/bla/result lrwxrwxrwx 1 ... 2005-03-13 21:10 /home/eelco/bla/result -> /nix/store/1r11343n6qd4...-f-spot-0.0.10Thus, when /home/eelco/bla/resultis removed, the GC root in theautodirectory becomes a dangling symlink and will be ignored by the collector.Warning Note that it is not possible to move or rename GC roots, since the symlink in the autodirectory will still point to the old location.If there are multiple results, then multiple symlinks will be created by sequentially numbering symlinks beyond the first one (e.g., foo,foo-2,foo-3, and so on).
Common Options
Most Nix commands accept the following command-line options:
- 
Prints out a summary of the command syntax and exits. 
- 
Prints out the Nix version number on standard output and exits. 
- 
--verbose/-vIncreases the level of verbosity of diagnostic messages printed on standard error. For each Nix operation, the information printed on standard output is well-defined; any diagnostic information is printed on standard error, never on standard output. This option may be specified repeatedly. Currently, the following verbosity levels exist: - 
0“Errors only”Only print messages explaining why the Nix invocation failed. 
- 
1“Informational”Print useful messages about what Nix is doing. This is the default. 
- 
2“Talkative”Print more informational messages. 
- 
3“Chatty”Print even more informational messages. 
- 
4“Debug”Print debug information. 
- 
5“Vomit”Print vast amounts of debug information. 
 
- 
- 
Decreases the level of verbosity of diagnostic messages printed on standard error. This is the inverse option to -v/--verbose.This option may be specified repeatedly. See the previous verbosity levels list. 
- 
--log-formatformatThis option can be used to change the output of the log format, with format being one of: - 
rawThis is the raw format, as outputted by nix-build. 
- 
internal-jsonOutputs the logs in a structured manner. Warning While the schema itself is relatively stable, the format of the error-messages (namely of the msg-field) can change between releases.
- 
barOnly display a progress bar during the builds. 
- 
bar-with-logsDisplay the raw logs, with the progress bar at the bottom. 
 
- 
- 
--no-build-output/-QBy default, output written by builders to standard output and standard error is echoed to the Nix command's standard error. This option suppresses this behaviour. Note that the builder's standard output and error are always written to a log file in prefix/nix/var/log/nix.
- 
--max-jobs/-jnumberSets the maximum number of build jobs that Nix will perform in parallel to the specified number. Specify autoto use the number of CPUs in the system. The default is specified by themax-jobsconfiguration setting, which itself defaults to1. A higher value is useful on SMP systems or to exploit I/O latency.Setting it to 0disallows building on the local machine, which is useful when you want builds to happen only on remote builders.
- 
Sets the value of the NIX_BUILD_CORESenvironment variable in the invocation of builders. Builders can use this variable at their discretion to control the maximum amount of parallelism. For instance, in Nixpkgs, if the derivation attributeenableParallelBuildingis set totrue, the builder passes the-jNflag to GNU Make. It defaults to the value of thecoresconfiguration setting, if set, or1otherwise. The value0means that the builder should use all available CPU cores in the system.
- 
Sets the maximum number of seconds that a builder can go without producing any data on standard output or standard error. The default is specified by the max-silent-timeconfiguration setting.0means no time-out.
- 
Sets the maximum number of seconds that a builder can run. The default is specified by the timeoutconfiguration setting.0means no timeout.
- 
--keep-going/-kKeep going in case of failed builds, to the greatest extent possible. That is, if building an input of some derivation fails, Nix will still build the other inputs, but not the derivation itself. Without this option, Nix stops if any build fails (except for builds of substitutes), possibly killing builds in progress (in case of parallel or distributed builds). 
- 
--keep-failed/-KSpecifies that in case of a build failure, the temporary directory (usually in /tmp) in which the build takes place should not be deleted. The path of the build directory is printed as an informational message.
- 
Whenever Nix attempts to build a derivation for which substitutes are known for each output path, but realising the output paths through the substitutes fails, fall back on building the derivation. The most common scenario in which this is useful is when we have registered substitutes in order to perform binary distribution from, say, a network repository. If the repository is down, the realisation of the derivation will fail. When this option is specified, Nix will build the derivation instead. Thus, installation from binaries falls back on installation from source. This option is not the default since it is generally not desirable for a transient failure in obtaining the substitutes to lead to a full build from source (with the related consumption of resources). 
- 
When this option is used, no attempt is made to open the Nix database. Most Nix operations do need database access, so those operations will fail. 
- 
--argname valueThis option is accepted by nix-env,nix-instantiate,nix-shellandnix-build. When evaluating Nix expressions, the expression evaluator will automatically try to call functions that it encounters. It can automatically call functions for which every argument has a default value (e.g.,{ argName ? defaultValue }: ...).With --arg, you can also call functions that have arguments without a default value (or override a default value). That is, if the evaluator encounters a function with an argument named name, it will call it with value value.For instance, the top-level default.nixin Nixpkgs is actually a function:{ # The system (e.g., `i686-linux') for which to build the packages. system ? builtins.currentSystem ... }: ...So if you call this Nix expression (e.g., when you do nix-env --install --attr pkgname), the function will be called automatically using the valuebuiltins.currentSystemfor thesystemargument. You can override this using--arg, e.g.,nix-env --install --attr pkgname --arg system \"i686-freebsd\". (Note that since the argument is a Nix string literal, you have to escape the quotes.)
- 
--argstrname valueThis option is like --arg, only the value is not a Nix expression but a string. So instead of--arg system \"i686-linux\"(the outer quotes are to keep the shell happy) you can say--argstr system i686-linux.
- 
--attr/-AattrPathSelect an attribute from the top-level Nix expression being evaluated. ( nix-env,nix-instantiate,nix-buildandnix-shellonly.) The attribute path attrPath is a sequence of attribute names separated by dots. For instance, given a top-level Nix expression e, the attribute pathxorg.xorgserverwould cause the expressione.xorg.xorgserverto be used. Seenix-env --installfor some concrete examples.In addition to attribute names, you can also specify array indices. For instance, the attribute path foo.3.barselects thebarattribute of the fourth element of the array in thefooattribute of the top-level expression.
- 
--expr/-EInterpret the command line arguments as a list of Nix expressions to be parsed and evaluated, rather than as a list of file names of Nix expressions. ( nix-instantiate,nix-buildandnix-shellonly.)For nix-shell, this option is commonly used to give you a shell in which you can build the packages returned by the expression. If you want to get a shell which contain the built packages ready for use, give your expression to thenix-shell --packagesconvenience flag instead.
- 
-I/--includepathAdd an entry to the list of search paths used to resolve lookup paths. This option may be given multiple times. Paths added through -Itake precedence over thenix-pathconfiguration setting and theNIX_PATHenvironment variable.
- 
--optionname valueSet the Nix configuration option name to value. This overrides settings in the Nix configuration file (see nix.conf5). 
- 
Fix corrupted or missing store paths by redownloading or rebuilding them. Note that this is slow because it requires computing a cryptographic hash of the contents of every path in the closure of the build. Also note the warning under nix-store --repair-path.
Note
See
man nix.conffor overriding configuration settings with command line flags.
Common Environment Variables
Most Nix commands interpret the following environment variables:
- 
Indicator that tells if the current environment was set up by nix-shell. It can have the valuespureorimpure.
- 
A colon-separated list of search path entries used to resolve lookup paths. This environment variable overrides the value of the nix-pathconfiguration setting.It can be extended using the -Ioption.Example $ export NIX_PATH=`/home/eelco/Dev:nixos-config=/etc/nixosIf NIX_PATHis set to an empty string, resolving search paths will always fail.Example $ NIX_PATH= nix-instantiate --eval '<nixpkgs>' error: file 'nixpkgs' was not found in the Nix search path (add it using $NIX_PATH or -I)
- 
Normally, the Nix store directory (typically /nix/store) is not allowed to contain any symlink components. This is to prevent “impure” builds. Builders sometimes “canonicalise” paths by resolving all symlink components. Thus, builds on different machines (with/nix/storeresolving to different locations) could yield different results. This is generally not a problem, except when builds are deployed to machines where/nix/storeresolves differently. If you are sure that you’re not going to do that, you can setNIX_IGNORE_SYMLINK_STOREto1.Note that if you’re symlinking the Nix store so that you can put it on another file system than the root file system, on Linux you’re better off using bindmount points, e.g.,$ mkdir /nix $ mount -o bind /mnt/otherdisk/nix /nixConsult the mount 8 manual page for details. 
- 
Overrides the location of the Nix store (default prefix/store).
- 
Overrides the location of the Nix static data directory (default prefix/share).
- 
Overrides the location of the Nix log directory (default prefix/var/log/nix).
- 
Overrides the location of the Nix state directory (default prefix/var/nix).
- 
Overrides the location of the system Nix configuration directory (default prefix/etc/nix).
- 
Applies settings from Nix configuration from the environment. The content is treated as if it was read from a Nix configuration file. Settings are separated by the newline character. 
- 
Overrides the location of the Nix user configuration files to load from. The default are the locations according to the XDG Base Directory Specification. See the XDG Base Directories sub-section for details. The variable is treated as a list separated by the :token.
- 
Use the specified directory to store temporary files. In particular, this includes temporary build directories; these can take up substantial amounts of disk space. The default is /tmp.
- 
This variable should be set to daemonif you want to use the Nix daemon to execute Nix operations. This is necessary in multi-user Nix installations. If the Nix daemon's Unix socket is at some non-standard path, this variable should be set tounix://path/to/socket. Otherwise, it should be left unset.
- 
If set to 1, Nix will print some evaluation statistics, such as the number of values allocated.
- 
If set to 1, Nix will print how often functions were called during Nix expression evaluation. This is useful for profiling your Nix expressions.
- 
If Nix has been configured to use the Boehm garbage collector, this variable sets the initial size of the heap in bytes. It defaults to 384 MiB. Setting it to a low value reduces memory consumption, but will increase runtime due to the overhead of garbage collection. 
XDG Base Directories
Nix follows the XDG Base Directory Specification.
For backwards compatibility, Nix commands will follow the standard only when use-xdg-base-directories is enabled.
New Nix commands (experimental) conform to the standard by default.
The following environment variables are used to determine locations of various state and configuration files:
- XDG_CONFIG_HOME(default- ~/.config)
- XDG_STATE_HOME(default- ~/.local/state)
- XDG_CACHE_HOME(default- ~/.cache)
Examples
To turn a host into a build server, the authorized_keys file can be
used to provide build access to a given SSH public key:
$ cat <<EOF >>/root/.ssh/authorized_keys
command="nice -n20 nix-store --serve --write" ssh-rsa AAAAB3NzaC1yc2EAAAA...
EOF