Privacy and security
What the app changes
The app edits nothing in your configuration except its own generated files.
They are .nix files inside your flake that start with the line
# GENERATED by DrakeFlake - safe to delete.. A file without that line is never overwritten or removed. Besides those, the app writes flake.lock when
you update inputs, and its own settings, logs, backups and caches in your home
folder (see Where things are).
What runs as your user
Almost everything runs as you, without extra rights:
- evaluating your configuration, searching options and packages,
- building the system (
nh os buildornixos-rebuild build), - updating flake inputs (
nix flake update): this deliberately never runs as root, so root never fetches the inputs your flake names into the store, - checking for updates, building images, “Try it”,
- writing the generated files when you may write to the flake folder.
What runs as root
For the few steps that need root, the app uses a small helper,
drakeflake-helper, started through pkexec. It can do exactly three
things, and each has its own polkit action, so the password prompt tells you
what is about to happen:
| Prompt | What the helper does | Password remembered? |
|---|---|---|
| Save system settings: “Authentication is required to save the generated NixOS settings files” | Writes or removes generated .nix files in a flake you may not write to yourself, for example a root-owned /etc/nixos. | Yes, for a short time |
| Activate a NixOS configuration: “Authentication is required to activate this NixOS configuration: …” (with the command) | Activates a system that was already built, by running that system’s own switch-to-configuration (for switch and boot it also becomes the default boot entry). | No, it asks every time |
| Save updated flake inputs: “Authentication is required to save the updated flake.lock” | Replaces flake.lock with the new lock file your update produced. | Yes, for a short time |
The helper checks what it is asked to do before doing anything:
- it only writes
.nixfiles given as absolute paths without.., inside a flake, that are not symlinks, and only replaces or removes files that are empty or carry the generated header; the new content must be a generated module with valid Nix syntax, - it only activates systems in the Nix store that are complete NixOS systems,
- it only installs a lock file that has the shape of a flake lock file, into a
local folder that contains a
flake.nix.
The polkit actions are only known to polkit when the package is installed system-wide (see Installation).
Some tasks are run by nh, which gets root itself when it needs it: Review and
apply, Switch to on the Generations page and Cleanup. Without nh,
Cleanup runs nix-collect-garbage as root, and applying without the helper
lets nh or nixos-rebuild ask for root themselves.
pkexec, run0 and sudo
The app looks for a way to get root in this order:
- a setuid
pkexec(on NixOS,/run/wrappers/bin/pkexec): your desktop’s polkit password dialog, run0(systemd): also polkit, without a setuid program,- a setuid
sudo, only for commands that run in the Console.
When it is not pkexec, the console says which one is used. If run0 or
sudo asks for your password in the console, answer in the password bar above
the output (see Password prompts). The password
goes to that program only and is never shown or logged.
Links
Links in option descriptions, package metadata and flake inputs come from many
sources. The app only opens links that start with http:// or https://;
other links (for example file://) are not opened. Images in option
descriptions are shown as their text, so viewing documentation does not load
anything from the internet.
Network access
The app sends nothing about you or your system anywhere. It only uses the network for:
- fetching your flake inputs and packages, done by Nix itself (evaluating, building, updating, “Try it”, images),
- checking flake inputs for updates (
git ls-remoteand HTTP header requests to the sources named in yourflake.lock), by the app and by the tray, - downloading the nix-index command database from GitHub, only when you click Download on the Packages page,
- opening links in your browser when you click them.