NixOS module and runtime package for psibase. NixOS, x86_64-linux only.
This is the operator surface. The contributor nix develop shell stays in the
psibase repo.
packages.psibase—psinode/psibase/psitestplusshare/psibase, patchelf’d from the published Ubuntu 24.04 psidk tarball. Does not build from source.nixosModules.psibase—services.psibase, a hardened systemd unit.
# flake.nix (your NixOS host, e.g. psinix)
{
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
inputs.psibase-nix.url = "github:gofractally/psibase-nix";
inputs.psibase-nix.inputs.nixpkgs.follows = "nixpkgs";
outputs = { nixpkgs, psibase-nix, ... }: {
nixosConfigurations.myhost = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
modules = [
psibase-nix.nixosModules.psibase
{
services.psibase = {
enable = true;
host = "psibase.example.com";
listen = 8090;
producer = "prod"; # omit for a non-producing node
p2p = true;
databaseCacheSize = "2GiB";
};
}
];
};
};
}sudo nixos-rebuild switch --flake .#myhostService runs psinode as user psibase under /var/lib/psibase/db. Boot a new chain once the service is up:
psibase boot -a http://HOST:PORT -p prod-a/--api is a subcommand argument, not a global one. It defaults to
http://psibase.localhost:8080/ and also reads PSINODE_URL.
TLS and reverse proxy are yours. For a full NixOS host that puts Caddy in
front of psinode, see velua/psinix.
psinode listens on 127.0.0.1 by default. If a remote proxy connects
directly to psinode:
services.psibase = {
listenAddress = "0.0.0.0";
openFirewall = true;
};With softHsm.enable = true the module writes a SoftHSM config pointing at a persistent token directory, runs a oneshot that initializes the token once from pinFile, and starts psinode with --pkcs11-module=…/libsofthsm2.so.
pinFile must be a runtime path string (e.g. sops), not a Nix path literal:
({ config, ... }: {
services.psibase.softHsm = {
enable = true;
pinFile = config.sops.secrets.softhsm_pin.path;
};
})After every psinode restart, unlock the HSM in x-admin before the node can sign blocks.
nix build .#psibaseLayout contract: $out/{bin,share/psibase}. Any derivation producing that layout can be substituted via services.psibase.package.
The runtime bits come from flake input psibase (the GitHub release tarball; the asset is named psidk-*.tar.gz). This repo’s lock is only a default. A host flake such as psinix should follow its own pin so a new psibase cut does not require a psibase-nix commit:
{
inputs.psibase-nix.url = "github:gofractally/psibase-nix";
inputs.psibase-nix.inputs.nixpkgs.follows = "nixpkgs";
inputs.psibase = {
url = "https://github.com/gofractally/psibase/releases/download/v0.27.0-pre/psidk-ubuntu-2404.tar.gz";
flake = false;
};
inputs.psibase-nix.inputs.psibase.follows = "psibase";
}nix flake lock records the tarball hash. To move to a new release, change the psibase URL in the host flake and run nix flake update psibase.
nixpkgs.follows is the same idea for nixpkgs: one copy, the host’s pin, no extra lock fight.
nix build .#checks.x86_64-linux.module-eval # module + assertions (seconds)
nix build .#checks.x86_64-linux.overlay-eval # overlay resolves against nixpkgs
nix build .#checks.x86_64-linux.vm # boots a node with SoftHSM (minutes)
nix flake check # all of the abovevm boots SoftHSM + an unsigned ProdDefault chain under the systemd sandbox.
Not covered: signed/production boot, HSM unlock/signing, real p2p peers.
nix fmt