Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Auto Upgrade

Schedules automatic NixOS upgrades from flake host outputs.

Purpose

Keep hosts current by rebuilding them from the flake on a schedule, with randomized start times to spread load across hosts and resource limits so upgrades do not starve interactive workloads.

Entry Point

Options

core.auto-upgrade.enable

Typeboolean
Defaulttrue
Exampletrue

Whether to enable auto-upgrade.


core.auto-upgrade.hostName

Typestring
Defaultconfig.networking.hostName

The hostName to use for auto-upgrade


Architecture / Services / Scope

When enabled, the module configures system.autoUpgrade to rebuild the host from the configured GitHub flake output for that host, using the --refresh, --accept-flake-config, and --no-update-lock-file flags, and applies CPU and IO resource limits to nixos-upgrade.service.

Operational Notes / Assumptions

  • Auto-upgrade only turns on when the flake has a revision (self.rev), meaning the repository is in a clean, revisioned state. Dirty working trees or non-revisioned evaluations leave system.autoUpgrade.enable = false.
  • Upgrades always target the GitHub flake source, not the local checkout.