Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Privacy and security

What the app changes

The app edits nothing in your configuration except its own generated files. They are .nix files inside your flake that start with the line # GENERATED by DrakeFlake - safe to delete.. A file without that line is never overwritten or removed. Besides those, the app writes flake.lock when you update inputs, and its own settings, logs, backups and caches in your home folder (see Where things are).

What runs as your user

Almost everything runs as you, without extra rights:

  • evaluating your configuration, searching options and packages,
  • building the system (nh os build or nixos-rebuild build),
  • updating flake inputs (nix flake update): this deliberately never runs as root, so root never fetches the inputs your flake names into the store,
  • checking for updates, building images, “Try it”,
  • writing the generated files when you may write to the flake folder.

What runs as root

For the few steps that need root, the app uses a small helper, drakeflake-helper, started through pkexec. It can do exactly three things, and each has its own polkit action, so the password prompt tells you what is about to happen:

PromptWhat the helper doesPassword remembered?
Save system settings: “Authentication is required to save the generated NixOS settings files”Writes or removes generated .nix files in a flake you may not write to yourself, for example a root-owned /etc/nixos.Yes, for a short time
Activate a NixOS configuration: “Authentication is required to activate this NixOS configuration: …” (with the command)Activates a system that was already built, by running that system’s own switch-to-configuration (for switch and boot it also becomes the default boot entry).No, it asks every time
Save updated flake inputs: “Authentication is required to save the updated flake.lock”Replaces flake.lock with the new lock file your update produced.Yes, for a short time

The helper checks what it is asked to do before doing anything:

  • it only writes .nix files given as absolute paths without .., inside a flake, that are not symlinks, and only replaces or removes files that are empty or carry the generated header; the new content must be a generated module with valid Nix syntax,
  • it only activates systems in the Nix store that are complete NixOS systems,
  • it only installs a lock file that has the shape of a flake lock file, into a local folder that contains a flake.nix.

The polkit actions are only known to polkit when the package is installed system-wide (see Installation).

Some tasks are run by nh, which gets root itself when it needs it: Review and apply, Switch to on the Generations page and Cleanup. Without nh, Cleanup runs nix-collect-garbage as root, and applying without the helper lets nh or nixos-rebuild ask for root themselves.

pkexec, run0 and sudo

The app looks for a way to get root in this order:

  1. a setuid pkexec (on NixOS, /run/wrappers/bin/pkexec): your desktop’s polkit password dialog,
  2. run0 (systemd): also polkit, without a setuid program,
  3. a setuid sudo, only for commands that run in the Console.

When it is not pkexec, the console says which one is used. If run0 or sudo asks for your password in the console, answer in the password bar above the output (see Password prompts). The password goes to that program only and is never shown or logged.

Links in option descriptions, package metadata and flake inputs come from many sources. The app only opens links that start with http:// or https://; other links (for example file://) are not opened. Images in option descriptions are shown as their text, so viewing documentation does not load anything from the internet.

Network access

The app sends nothing about you or your system anywhere. It only uses the network for:

  • fetching your flake inputs and packages, done by Nix itself (evaluating, building, updating, “Try it”, images),
  • checking flake inputs for updates (git ls-remote and HTTP header requests to the sources named in your flake.lock), by the app and by the tray,
  • downloading the nix-index command database from GitHub, only when you click Download on the Packages page,
  • opening links in your browser when you click them.