Jump to content

Automatic system upgrades: Difference between revisions

From Official NixOS Wiki
m Added filename and syntax highlighting
Noewaeda (talk | contribs)
m Fix broken formatting
(2 intermediate revisions by the same user not shown)
Line 1: Line 1:
Automatic system upgrades can be used to upgrade a system regularly at a specific time. This can help to reduce the time period of applying important security patches to your running software but might also introduce some breakage in case an automatic upgrade fails. For automatic upgrades an automatic [[Garbage Collection|garbage collection]] is important to prevent full <syntaxhighlight inline lang="bash">/boot</syntaxhighlight> and <syntaxhighlight inline lang="bash">/</syntaxhighlight> partitions.
Automatic system upgrades can be used to upgrade a system regularly at a specific time. This can help to reduce the time period of applying important security patches to your running software, but might also introduce some breakage in the case that an automatic upgrade fails. For automatic upgrades, automatic [[Garbage Collection|garbage collection]] is important to prevent full <syntaxhighlight inline lang="bash">/boot</syntaxhighlight> and <syntaxhighlight inline lang="bash">/</syntaxhighlight> partitions.


== Configuration ==
== Configuration ==
Line 5: Line 5:
=== Channel-based systems (default) ===
=== Channel-based systems (default) ===


Most NixOS installations use channels by default. If you're unsure which you're using, check with <syntaxhighlight inline lang="bash">nix-channel --list</syntaxhighlight>. If that returns results, you're using channels.
Most NixOS installations use channels by default. If you're unsure which you're using, check with <syntaxhighlight inline lang="bash">nix-channel --list</syntaxhighlight>. If that returns any results, you're using channels.


For channel-based systems, use this configuration:
For channel-based systems, use this configuration:
Line 22: Line 22:
=== Flake-based systems ===
=== Flake-based systems ===


To enable unattended automatic system updates on a flake-enabled host, add following part to your configuration:
To enable unattended automatic system updates on a flake-enabled host, add following to your configuration:


{{file|auto-upgrade.nix|nix|<nowiki>
{{file|auto-upgrade.nix|nix|<nowiki>
Line 35: Line 35:
   randomizedDelaySec = "45min";
   randomizedDelaySec = "45min";
};
};
</nowiki>}}Previously this page advised to set the flags <code>--update-input nixpkgs</code> to trigger updating a specific input. However that flag will just be handed through to <code>nix build</code> where it was deprecated and removed. Follow [https://github.com/NixOS/nixpkgs/issues/349734 this Bug for details and resolutions].
</nowiki>}}
 
Previously, this page advised to set the flags <syntaxhighlight inline lang="bash">--update-input nixpkgs</syntaxhighlight> to trigger an update of the <code>nixpkgs</code> input. However, that flag will only be passed to <syntaxhighlight inline lang="bash">nixos-rebuild</syntaxhighlight>, where it was deprecated. Follow [https://github.com/NixOS/nixpkgs/issues/349734 this issue] for details and resolutions.


== Monitoring ==
== Monitoring ==


Check that automatic system upgrades run successfully. Force an automatic system upgrade by running
Check that automatic system upgrades run successfully. Force an automatic system upgrade by running:


<syntaxhighlight lang="bash">
<syntaxhighlight lang="bash">
Line 45: Line 47:
</syntaxhighlight>
</syntaxhighlight>


Check the upgrade log with
Check the upgrade log with:


<syntaxhighlight lang="bash">
<syntaxhighlight lang="bash">
Line 51: Line 53:
</syntaxhighlight>
</syntaxhighlight>


Or, to see the full log
Or, to see the full log:


<syntaxhighlight lang="bash">
<syntaxhighlight lang="bash">
Line 57: Line 59:
</syntaxhighlight>
</syntaxhighlight>


To see the status of the upgrade timer run
To see the status of the upgrade timer, run:


<syntaxhighlight lang="bash">
<syntaxhighlight lang="bash">
Line 67: Line 69:
=== Git "repository is not owned by current user" ===
=== Git "repository is not owned by current user" ===


The flake repository directory is not owned by <syntaxhighlight inline lang="bash">root</syntaxhighlight> (which <syntaxhighlight inline lang="bash">nixos-upgrade</syntaxhighlight> runs as). To fix this, add the following to <syntaxhighlight inline lang="bash">/root/.gitconfig</syntaxhighlight>:
The flake repository directory is not owned by <syntaxhighlight inline lang="bash">root</syntaxhighlight>, which <syntaxhighlight inline lang="bash">nixos-upgrade</syntaxhighlight> runs as. To fix this, add the following to <syntaxhighlight inline lang="bash">/root/.gitconfig</syntaxhighlight>:


{{file|/root/.gitconfig|gitconfig|<nowiki>
{{file|/root/.gitconfig|gitconfig|<nowiki>
Line 79: Line 81:
systemd.services.nixos-upgrade.environment = {
systemd.services.nixos-upgrade.environment = {
   GIT_AUTHOR_NAME = "NixOS Auto-upgrade";
   GIT_AUTHOR_NAME = "NixOS Auto-upgrade";
   GIT_AUTHOR_EMAIL = "root@<your-hostname>";
   GIT_AUTHOR_EMAIL = "root@{your hostname}";
   GIT_COMMITTER_NAME = "NixOS Auto-upgrade";
   GIT_COMMITTER_NAME = "NixOS Auto-upgrade";
   GIT_COMMITTER_EMAIL = "root@<your-hostname>";
   GIT_COMMITTER_EMAIL = "root@{your hostname}";
};
};
</nowiki>}}
</nowiki>}}


[[Category:NixOS]]
[[Category:NixOS]]

Revision as of 13:15, 23 September 2026

Automatic system upgrades can be used to upgrade a system regularly at a specific time. This can help to reduce the time period of applying important security patches to your running software, but might also introduce some breakage in the case that an automatic upgrade fails. For automatic upgrades, automatic garbage collection is important to prevent full /boot and / partitions.

Configuration

Channel-based systems (default)

Most NixOS installations use channels by default. If you're unsure which you're using, check with nix-channel --list. If that returns any results, you're using channels.

For channel-based systems, use this configuration:

❄︎ auto-upgrade.nix
system.autoUpgrade = {
  enable = true;
  dates = "02:00";
  randomizedDelaySec = "45min";
  allowReboot = false;  # Set to true if you want automatic reboots
};

Important: Do not use flake-specific flags with channel-based systems, as they will cause the upgrade to fail silently.

Flake-based systems

To enable unattended automatic system updates on a flake-enabled host, add following to your configuration:

❄︎ auto-upgrade.nix
system.autoUpgrade = {
  enable = true;
  flake = "/path/to/flake";
  flags = [
    "--print-build-logs"
    "--commit-lock-file"  # If you want to automatically commit the updated flake.lock
  ];
  dates = "02:00";
  randomizedDelaySec = "45min";
};

Previously, this page advised to set the flags --update-input nixpkgs to trigger an update of the nixpkgs input. However, that flag will only be passed to nixos-rebuild, where it was deprecated. Follow this issue for details and resolutions.

Monitoring

Check that automatic system upgrades run successfully. Force an automatic system upgrade by running:

# systemctl start nixos-upgrade

Check the upgrade log with:

# systemctl status nixos-upgrade.service

Or, to see the full log:

# journalctl -u nixos-upgrade.service

To see the status of the upgrade timer, run:

# systemctl status nixos-upgrade.timer

Troubleshooting

Git "repository is not owned by current user"

The flake repository directory is not owned by root, which nixos-upgrade runs as. To fix this, add the following to /root/.gitconfig:

≡︎ /root/.gitconfig
[safe]
  directory = /path/to/flake

Git "fatal: unable to auto-detect email address"

The root user doesn't have specified the user and email in the git configuration. To fix this, you can extend the nixos-upgrade service with:

❄︎ auto-upgrade.nix
systemd.services.nixos-upgrade.environment = {
  GIT_AUTHOR_NAME = "NixOS Auto-upgrade";
  GIT_AUTHOR_EMAIL = "root@{your hostname}";
  GIT_COMMITTER_NAME = "NixOS Auto-upgrade";
  GIT_COMMITTER_EMAIL = "root@{your hostname}";
};