Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Flake inputs

The Inputs page lists the inputs of your system flake from flake.lock: where each comes from, which revision it is locked to and when that revision was made, and whether upstream has something newer.

Checking for updates

Opening the page asks each source for its newest revision; Check for updates asks again. The check uses git ls-remote for git and GitHub sources and the HTTP headers of tarball sources. It takes a few seconds and needs the network.

Each input gets a tag:

  • update available: upstream has a newer revision. The row shows “Newest upstream: …” and, where the source supports it, a see all changes link to the comparison.
  • up to date
  • pinned: the input is locked to a fixed revision in flake.nix; there is nothing to update.
  • check failed: the source could not be asked, with the reason. Private repositories fail the check rather than ask for a password.

An input that follows another one (“Follows the input …”) is locked together with that input.

Inputs of inputs

Click a row with “… inputs of its own” to see the inputs that input brings along:

  • follows your …: it uses your input of that name,
  • same as your …: it shares the locked copy of one of your inputs,
  • follows …: it follows another input,
  • separate copy: it brings a second copy of a repository you already have as an input,
  • own copy: it brings its own copy of something you do not have.

For a separate copy, the app suggests the follows line that avoids the second copy, for example inputs.home-manager.inputs.nixpkgs.follows = "nixpkgs";.

Updating

  • To update one input, click Update in its row.
  • To update everything, click Update all at the top. It shows how many inputs can be updated, for example Update all (2).

The update runs nix flake update as your user, with the output in the Console. Cancel stops it, for example when a download hangs.

If your user may not write flake.lock (for example in a root-owned /etc/nixos), the new lock file is written to a temporary file first and then put in place by the helper, which asks for your password (“Save updated flake inputs”). The update itself never runs as root.

When the update succeeds, the page says “flake.lock was updated. Rebuild to start using the new versions.” with two buttons: Rebuild and switch and Build only. A rebuild from here uses your configuration as it is; it does not write the generated files.

Why updates use the newest known revision

A plain nix flake update asks GitHub’s API for the newest revision of a branch. When that API’s rate limit is reached, Nix prints “using cached version”, keeps the old revision and still reports success.

To avoid this, the app locks every input whose newer revision the check already found directly to that revision (with --override-input, which keeps the original reference such as github:NixOS/nixpkgs/nixos-unstable in flake.lock). Only the inputs without a known newer revision are left to nix flake update.

After the update the app compares flake.lock with what it expected. If an input did not reach the new revision, the console says “Not updated: … Nix kept its cached version”.

GitHub API rate limit

GitHub allows only a small number of anonymous API requests per hour. If your updates keep hitting the limit, give Nix a GitHub access token in nix.conf. A token without extra permissions is enough for public repositories:

access-tokens = github.com=ghp_yourtokenhere

Put it in a file only you can read, for example ~/.config/nix/nix.conf, rather than in your system configuration, which ends up in the world-readable Nix store.

Update notifications in the tray

drakeflake-tray is a small tray icon (not the whole app) that checks your flake inputs for updates: two minutes after it starts and then every six hours. When updates are available it changes its icon and shows a desktop notification (“Flake updates available”) naming the inputs. It notifies again only when the list of updatable inputs changes.

Its menu has Open DrakeFlake, Check for updates now and Quit. Only one tray runs per session.

To start it with your session, open Settings → Update notifications and turn on Start at login. This writes an autostart entry (~/.config/autostart/drakeflake-tray.desktop); turning it off removes it. Start it now starts the tray right away.

The tray checks the same flake as the app (from the app’s settings) and only works for a flake in a local folder. To test the check from a terminal, run drakeflake-tray --check-once; it prints the inputs that can be updated and exits.