Comment by dml2135
8 hours ago
Use NixOS, only give your model access to the config in a git repo, zero access to the actual host machine.
8 hours ago
Use NixOS, only give your model access to the config in a git repo, zero access to the actual host machine.
That is also what I do now (both with NixOs and Guix Os), both for personal computers and for servers.
- I inspect the agent's changes, and only apply them - at once - if they are OK. So I have no half applied bad changes to my system, and I can catch critical mistakes before they are applied.
- I can roll back the changes by just doing a `git revert` and reapplying
- The agent cannot read secrets or unrelated data, just config.
- The agent gets the full configuration of all systems at once, without having to maintain parallel documentation (which can get out of sync) or rediscover each time from scratch (access my running systems, for example with `ssh root@server`).
- It's harder for the agent to miss some aspect of the configuration, because it's all in my dotfiles. If it's not there, it's nowhere