Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
da2640b
feat(aws-nixos): add a NixOS on AWS EC2 template
phorcys420 Sep 21, 2026
580f141
docs(AGENTS.md): require /usr/bin/env bash in module scripts
phorcys420 Sep 21, 2026
95dd235
refactor(aws-nixos): move the amazon-init logic into its own module (…
phorcys420 Sep 21, 2026
4ea3ce1
refactor(aws-nixos): make amazon-init know nothing about Nix
phorcys420 Sep 21, 2026
b47eaec
refactor(aws-nixos): split the template into a nix module and a platf…
phorcys420 Sep 21, 2026
080b391
refactor(aws-nixos): drop the curl fallback, name the attributes code…
phorcys420 Sep 21, 2026
a4e281a
refactor(aws-nixos): hand the periodic rebuild to the configuration
phorcys420 Sep 21, 2026
cfd05d4
fix(aws-nixos): make a boot that could not build the flake visible
phorcys420 Sep 23, 2026
a415ef5
fix(aws-nixos): report the failure with the agent instead of keeping one
phorcys420 Sep 23, 2026
bb8cf7e
revert(aws-nixos): stop reporting boot failures through the agent
phorcys420 Sep 24, 2026
8b08525
docs(aws-nixos): the upgrade timer no longer streams to the workspace
phorcys420 Sep 24, 2026
a44efa7
refactor(aws-nixos): apply review feedback
phorcys420 Sep 28, 2026
6d9b3af
docs(aws-nixos): no upgrade timer, and the modules moved out
phorcys420 Sep 28, 2026
6d47f25
fix(aws-nixos): run stdbuf under _sudo, not around it
phorcys420 Sep 28, 2026
ca834aa
docs(aws-nixos): name the attribute in the rebuild-by-hand example
phorcys420 Sep 28, 2026
d50a01c
refactor(aws-nixos): take the region's AZ and the instance catalog fr…
phorcys420 Sep 28, 2026
57ac636
refactor(aws-nixos): offer every size, and name the families
phorcys420 Sep 28, 2026
313777c
refactor(coder-labs/aws-nixos): follow the flake's renamed configurat…
phorcys420 Sep 28, 2026
6dd42e7
fix(coder-labs/aws-nixos): the instance catalog renamed ami to arch
phorcys420 Sep 28, 2026
ac4ba33
refactor(coder-labs/aws-nixos): take aws-ec2-instance-type from the r…
phorcys420 Sep 28, 2026
7d4accf
refactor(coder-labs/aws-nixos): take aws-region from the registry too
phorcys420 Sep 28, 2026
481b071
Harden and simplify AWS NixOS flake lifecycle module
phorcys420 Sep 28, 2026
75017c5
refactor(aws-nixos): streamline bootstrap and template onboarding
phorcys420 Sep 28, 2026
713bdc6
refactor(aws-nixos): simplify bootstrap and loosen optional inputs
phorcys420 Sep 29, 2026
600dfbf
Merge branch 'main' into phorcys/nixos-tests
phorcys420 Sep 29, 2026
48939cc
Merge branch 'main' into phorcys/nixos-tests
phorcys420 Oct 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .icons/nixos-rainbow.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
1 change: 1 addition & 0 deletions .icons/nixos-trans.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
1 change: 1 addition & 0 deletions .icons/nixos.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
1 change: 1 addition & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,7 @@ output "scripts" {
- Use `tf` (not `hcl`) for code blocks in README; use relative icon paths (e.g., `../../../../.icons/`)
- **Never include parameter listings or input/output variable tables in module or template READMEs.** This includes workspace parameters declared with `coder_parameter`. The registry automatically parses the Terraform source and displays parameters in a dedicated tab on `registry.coder.com`; input/output documentation is also generated from the source. Duplicating these listings in the README is redundant and creates maintenance drift.
- Usage examples (e.g., a `module "..." { }` block) and explanations of parameter behavior are encouraged, but not tables or lists enumerating parameters, inputs, or outputs.
- Script shebangs must be `#!/usr/bin/env bash`, never `#!/bin/bash`. NixOS workspaces have only `/bin/sh`, so the kernel fails the exec before anything runs and the agent reports exit 255 with an empty log — which looks like a broken module, not a missing interpreter.

### Variable and output conventions

Expand Down
61 changes: 61 additions & 0 deletions registry/coder-labs/templates/aws-nixos/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
---
display_name: AWS EC2 (NixOS)
description: Provision NixOS EC2 VMs as Coder workspaces from a flake
icon: ../../../../.icons/nixos.svg
verified: true
tags: [vm, linux, aws, nixos, persistent-vm]
---

# NixOS workspaces on AWS EC2

Boot an EC2 workspace from a Git flake. NixOS rebuilds before the agent starts.

## Before you start

- Give the Coder provisioner AWS credentials through the usual provider credential chain.
See the [EC2 policy example](../../../coder/templates/aws-linux/PREREQUISITES.md); its `RunInstances` and `CreateTags` permissions cover more than tagged resources.
- Keep a default VPC/subnet. Allow provisioner egress to AWS/JetBrains and VM egress to Coder/Git/Nix caches.
- Use a supported Git URL: `https://host/org/repo` or `git+ssh://git@host/org/repo`, with optional `?ref=branch`.
`github:` and `?dir=` are not supported. Commit your flake before starting a workspace.

## Choose a flake

**Start with the [example flake](https://github.com/coder/nixos-example-flake):**

1. Fork it, edit `configuration.nix`, and commit your changes and `flake.lock`.
2. Set `flake_ref` to your fork's Git URL. Keep the default `flake_attr = "coder-workspace-ec2-$ARCH"`.
3. Push the template and create a workspace. Its default instance type is `t3.medium`.

**Bring an existing flake:**

1. Add `github:coder/nixos-modules` as an input. Import `coder-modules.nixosModules.default` in each workspace host.
2. Include EC2 hardware support; the [example hardware module](https://github.com/coder/nixos-example-flake/blob/main/hardware/ec2.nix) imports the boot-critical NixOS Amazon image module.
3. Set each host's `nixpkgs.hostPlatform` and `coder.flakeAttr` to its own `nixosConfigurations` name.
4. Export hosts for the instance types you offer. Use `$ARCH` in `flake_attr` for paired `x86_64`/`aarch64` names, or a fixed name for one architecture.
5. Set `flake_ref` and `flake_attr`, push the template, then create a workspace.

Instance type determines AMI, agent architecture, and `$ARCH`. Small sizes may lack build memory.

## Work with the workspace

Boot syncs `/etc/nixos` and rebuilds. Dirty trees and local commits stay untouched. To rebuild manually:

```console
sudo nixos-rebuild switch --flake /etc/nixos#coder-workspace-ec2-x86_64
```

Use your host's attribute instead of the example name. The root disk and Nix store survive stop/start, **not** instance deletion or replacement. A larger root disk can be selected later; EBS cannot shrink it.

Watch the **NixOS** workspace log or `/var/log/coder-nixos/rebuild-latest.log`. If first boot has no agent, use EC2 console output:

```console
aws ec2 get-console-output --instance-id <instance-id> --output text
```

## Secrets and limitations

Do not put secrets in Nix expressions: the Nix store is readable on the VM. Workspace facts and optional bootstrap files are not secret storage. The agent token is kept out of Nix, but EC2 user-data and Terraform state contain it; restrict access to both. Processes with instance-metadata access can read user-data.

Private repos need Git authentication before first boot and separate credentials for private Nix inputs; this template supplies neither. HTTP credentials in `flake_ref` are allowed but exposed in Terraform state, EC2 user-data, Coder metadata, and `/etc/nixos/.git/config`. Prefer root-managed credentials. NixOS scripts need `#!/usr/bin/env bash`; downloaded IDE binaries need `programs.nix-ld`.

Existing templates may retain a stored legacy `flake_attr`; update that variable explicitly before rebuilding against renamed example-flake hosts.
Loading
Loading