Automatic system upgrades: Difference between revisions
m Fix broken formatting |
mNo edit summary |
||
| (4 intermediate revisions by 2 users not shown) | |||
| Line 37: | Line 37: | ||
</nowiki>}} | </nowiki>}} | ||
Previously, this page advised to set the flags <syntaxhighlight inline lang="bash">--update-input nixpkgs</syntaxhighlight> to trigger an update of the | Previously, this page advised to set the flags <syntaxhighlight inline lang="bash">--update-input nixpkgs</syntaxhighlight> to trigger an update of the nixpkgs input. However, that flag will only be passed to nixos-rebuild, where it was deprecated. Follow [https://github.com/NixOS/nixpkgs/issues/349734 this issue] for details and resolutions. | ||
==== Home Manager ==== | |||
To enable unattended automatic updates for [[Home Manager]] packages on a flake-enabled host, use {{home manager|services.home-manager.autoUpgrade}} option: | |||
{{file|~/.config/home-manager/home.nix|nix|<nowiki> | |||
services.home-manager.autoUpgrade = { | |||
enable = true; | |||
useFlake = true; | |||
flakeDir = "/path/to/flake"; | |||
frequency = "03:00"; | |||
preSwitchCommands = [ "nix flake update" ]; | |||
}; | |||
</nowiki>}} | |||
{{Note|The update service should be immediately triggered if it missed the last start time (for example due to the system being powered off), since <code>Persistent</code> is set to <code>true</code> both in <code>nixos-upgrade.timer</code> and <code>home-manager-auto-upgrade.timer</code>. (See https://wiki.archlinux.org/title/Systemd/Timers#Realtime_timer for more details on <code>Persistent</code> option.)}} | |||
== Monitoring == | == Monitoring == | ||
| Line 43: | Line 59: | ||
Check that automatic system upgrades run successfully. Force an automatic system upgrade by running: | Check that automatic system upgrades run successfully. Force an automatic system upgrade by running: | ||
<syntaxhighlight lang=" | <syntaxhighlight lang="console"> | ||
# systemctl start nixos-upgrade | # systemctl start nixos-upgrade | ||
</syntaxhighlight> | </syntaxhighlight> | ||
| Line 49: | Line 65: | ||
Check the upgrade log with: | Check the upgrade log with: | ||
<syntaxhighlight lang=" | <syntaxhighlight lang="console"> | ||
# systemctl status nixos-upgrade.service | # systemctl status nixos-upgrade.service | ||
</syntaxhighlight> | </syntaxhighlight> | ||
Or, to see the | Or, to see the log: | ||
<syntaxhighlight lang=" | <syntaxhighlight lang="console"> | ||
# journalctl -u nixos-upgrade.service | # journalctl -u nixos-upgrade.service | ||
</syntaxhighlight> | </syntaxhighlight> | ||
| Line 61: | Line 77: | ||
To see the status of the upgrade timer, run: | To see the status of the upgrade timer, run: | ||
<syntaxhighlight lang=" | <syntaxhighlight lang="console"> | ||
# systemctl status nixos-upgrade.timer | # systemctl status nixos-upgrade.timer | ||
</syntaxhighlight> | |||
=== Home Manager === | |||
Force upgrade by running: | |||
<syntaxhighlight lang="console"> | |||
# systemctl --user start home-manager-auto-upgrade.service | |||
</syntaxhighlight> | |||
To see the full log: | |||
<syntaxhighlight lang="console"> | |||
# journalctl --user -u home-manager-auto-upgrade.service -f | |||
</syntaxhighlight> | |||
To see the status of the upgrade timer, run: | |||
<syntaxhighlight lang="console"> | |||
# systemctl --user status home-manager-auto-upgrade.timer | |||
</syntaxhighlight> | </syntaxhighlight> | ||
| Line 69: | Line 105: | ||
=== Git "repository is not owned by current user" === | === Git "repository is not owned by current user" === | ||
The flake repository directory is not owned by | The flake repository directory is not owned by root, which nixos-upgrade runs as. To fix this, add the following to <syntaxhighlight inline lang="bash">/root/.gitconfig</syntaxhighlight>: | ||
{{file|/root/.gitconfig|gitconfig|<nowiki> | {{file|/root/.gitconfig|gitconfig|<nowiki> | ||
| Line 77: | Line 113: | ||
=== Git "fatal: unable to auto-detect email address" === | === Git "fatal: unable to auto-detect email address" === | ||
The root user doesn't have specified the user and email in the git configuration. To fix this, you can extend the | The root user doesn't have specified the user and email in the git configuration. To fix this, you can extend the nixos-upgrade service with: | ||
{{file|auto-upgrade.nix|nix|<nowiki> | {{file|auto-upgrade.nix|nix|<nowiki> | ||
systemd.services.nixos-upgrade.environment = { | systemd.services.nixos-upgrade.environment = { | ||
Latest revision as of 14:00, 28 September 2026
Automatic system upgrades can be used to upgrade a system regularly at a specific time. This can help to reduce the time period of applying important security patches to your running software, but might also introduce some breakage in the case that an automatic upgrade fails. For automatic upgrades, automatic garbage collection is important to prevent full /boot and / partitions.
Configuration
Channel-based systems (default)
Most NixOS installations use channels by default. If you're unsure which you're using, check with nix-channel --list. If that returns any results, you're using channels.
For channel-based systems, use this configuration:
system.autoUpgrade = {
enable = true;
dates = "02:00";
randomizedDelaySec = "45min";
allowReboot = false; # Set to true if you want automatic reboots
};
Important: Do not use flake-specific flags with channel-based systems, as they will cause the upgrade to fail silently.
Flake-based systems
To enable unattended automatic system updates on a flake-enabled host, add following to your configuration:
system.autoUpgrade = {
enable = true;
flake = "/path/to/flake";
flags = [
"--print-build-logs"
"--commit-lock-file" # If you want to automatically commit the updated flake.lock
];
dates = "02:00";
randomizedDelaySec = "45min";
};
Previously, this page advised to set the flags --update-input nixpkgs to trigger an update of the nixpkgs input. However, that flag will only be passed to nixos-rebuild, where it was deprecated. Follow this issue for details and resolutions.
Home Manager
To enable unattended automatic updates for Home Manager packages on a flake-enabled host, use services.home-manager.autoUpgrade option:
services.home-manager.autoUpgrade = {
enable = true;
useFlake = true;
flakeDir = "/path/to/flake";
frequency = "03:00";
preSwitchCommands = [ "nix flake update" ];
};
Persistent is set to true both in nixos-upgrade.timer and home-manager-auto-upgrade.timer. (See https://wiki.archlinux.org/title/Systemd/Timers#Realtime_timer for more details on Persistent option.)Monitoring
Check that automatic system upgrades run successfully. Force an automatic system upgrade by running:
# systemctl start nixos-upgrade
Check the upgrade log with:
# systemctl status nixos-upgrade.service
Or, to see the log:
# journalctl -u nixos-upgrade.service
To see the status of the upgrade timer, run:
# systemctl status nixos-upgrade.timer
Home Manager
Force upgrade by running:
# systemctl --user start home-manager-auto-upgrade.service
To see the full log:
# journalctl --user -u home-manager-auto-upgrade.service -f
To see the status of the upgrade timer, run:
# systemctl --user status home-manager-auto-upgrade.timer
Troubleshooting
Git "repository is not owned by current user"
The flake repository directory is not owned by root, which nixos-upgrade runs as. To fix this, add the following to /root/.gitconfig:
[safe]
directory = /path/to/flakeGit "fatal: unable to auto-detect email address"
The root user doesn't have specified the user and email in the git configuration. To fix this, you can extend the nixos-upgrade service with:
systemd.services.nixos-upgrade.environment = {
GIT_AUTHOR_NAME = "NixOS Auto-upgrade";
GIT_AUTHOR_EMAIL = "root@{your hostname}";
GIT_COMMITTER_NAME = "NixOS Auto-upgrade";
GIT_COMMITTER_EMAIL = "root@{your hostname}";
};