From September 25 to 28, 2026, the Nix community meets in Kraków, Poland, for NixCon 2026. HeBeKo will be there to meet the people working on the ecosystem.
The program covers sandboxing, regulatory compliance, declarative networking, production experience reports, and physical hardware. Nix now reaches well beyond package management on a developer workstation.
Nix, in one sentence
Nix is a package manager and a set of tools for describing and building software environments declaratively and reproducibly.
On a classic server, you install packages, change the configuration as you go, and stack up scripts. Six months later, it is often hard to tell why the machine is in its current state. With Nix, the desired state of the system is written as code, versionable and shareable. NixOS applies that principle to the entire distribution, which can be rebuilt from its configuration.
From reproducibility to sovereignty
In the French context, DINUM (France's interministerial digital directorate) relies on this ecosystem to build more manageable digital environments. Sécurix, published on GitHub by the cloud-gouv team, is one example: a workstation hardened according to ANSSI recommendations, whose configuration can be known, controlled, and reproduced. We covered it in Understanding NixOS.
Using Linux or open source does not make a system "sovereign" by magic. The question is control: who controls the installed software, can you see precisely what is running, rebuild an environment identically, audit its components and provenance, and keep it running without depending on a single vendor? Those are the questions public administrations and local authorities ask when trying to reduce their dependence on proprietary solutions (see our digital sovereignty page).
Nix in the workplace
Nicolas Goudry will present “NixOS in the Corporate Trenches: Cuts and Bruises”, an account of running Nix in a company setting. Alexander Foremny will look at “The State NixOS Won't Manage”: state, data, and databases remain outside what declarative configuration can make reproducible.
The declarative model solves configuration drift; it doesn't solve what has to stay mutable by nature.
The Cyber Resilience Act
Since September 11, 2026, software manufacturers have had to report actively exploited vulnerabilities through ENISA's platform, under the Cyber Resilience Act. Obligations around SBOMs, patch management, and "steward" status for open-source projects follow at the end of 2027.
Florian Pester will discuss this in “Nix & the EU Cyber Resilience Act”, comparing the security responses of FreeBSD, Zephyr, and Debian. Artemis Tosini will also cover isolation in “Unprivileged Privileged Nix”, focused on Linux sandboxing mechanisms.
Declaring your network
The program doesn't stop at servers. Kierán Meinhardt will present netbox-nixos, which generates NixOS configurations from a NetBox inventory. Dionysis Grigoropoulos will show how to run a small autonomous system with peering declared in Nix.
What about hardware?
Tristan Ross will cover declarative hardware architectures, liberodark will discuss porting to RISC-V, and Markus Napierkowski will show how to run NixOS integration tests on real hardware instead of VMs. Other sessions cover high-performance computing and embedded systems.
Why HeBeKo will be in Kraków
We care about Nix because infrastructure needs to stay understandable to the people running it. For a small local authority, being able to rebuild a server from a documented configuration and know its dependencies is a practical concern.
We'll be in Kraków to meet the people working on NixOS, Sécurix, and software supply chain security.
HeBeKo provides NixOS migration and managed operations. To talk about it, contact us.
Sources
- NixCon 2026 — full program
- NixOS in the Corporate Trenches: Cuts and Bruises — Nicolas Goudry
- The State NixOS Won't Manage — Alexander Foremny
- Nix & the EU Cyber Resilience Act — Florian Pester
- Unprivileged Privileged Nix — Artemis Tosini
- netbox-nixos — Kierán Meinhardt
- Peering Declaratively — Dionysis Grigoropoulos
- Declarative Hardware Architectures using Nix — Tristan Ross
- Running NixOS Integration Tests on Real Hardware — Markus Napierkowski
- Cyber Resilience Act — reporting obligations (European Commission)
- Sécurix (DINUM / cloud-gouv)