r3x: Zero-Trust NixOS with Vaultix, Den, and Hardware Keys

r3x: Zero-Trust NixOS with Vaultix, Den, and Hardware Keys

Managing a multi-machine fleet with NixOS across physical workstations, Incus virtual machines, and development containers usually runs into two persistent architectural dilemmas: Module & Dotfile Sprawl: Monolithic flakes where host hardware, system services, and user dotfiles get tangled together in a fragile import graph. The Secret Deployment Paradox: You want root and user passwords locked behind a physical hardware token (YubiKey Age identity), but you also need headless servers and Incus containers to boot, rebuild, and activate unattended without an administrator’s physical key present. Over the past week, I rebuilt my entire infrastructure repository from scratch to solve these exact problems. The project is called r3x. ...

Tech · October 4, 2026 · 7 min · René Jochum